Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.8
CVE-2021-20328
Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM…
Java Driver
1.13.3 / 3.11.3+
HIGH 7.5
CVE-2019-20925
An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to …
MongoDB
3.4.24 / 3.6.15+
MEDIUM 6.5
CVE-2020-7927
Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. T…
Ops Manager
after 4.4.2
MEDIUM 6.5
CVE-2018-20803
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which loop indefinitely in mathemat…
MongoDB
3.4.19 / 3.6.10+
MEDIUM 6.5
CVE-2020-7928
A user authorized to perform database queries may trigger a read overrun and access arbitrary memory by issuing specially crafted queries. This issue…
MongoDB
3.6.20 / 4.0.20+
MEDIUM 6.5
CVE-2019-2393
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use $lookup and collations. T…
MongoDB
3.6.15 / 4.0.13+
MEDIUM 6.5
CVE-2018-20802
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting Quer…
MongoDB
3.6.9 / 4.0.3+
MEDIUM 6.5
CVE-2018-20804
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations. This issue affects Mon…
MongoDB
3.6.13 / 4.0.10+
MEDIUM 6.5
CVE-2018-20805
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch . This …
MongoDB
3.6.10 / 4.0.5+
MEDIUM 6.5
CVE-2019-20923
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript ex…
MongoDB
4.0.7+
MEDIUM 6.5
CVE-2019-20924
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries which trigger an invariant in the In…
MongoDB
4.2.2+
MEDIUM 6.5
CVE-2019-2392
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which use the $mod operator to over…
MongoDB
3.6.20 / 4.0.20+
HIGH 7.5
CVE-2020-7925
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a spec…
MongoDB
4.2.9+
MEDIUM 6.5
CVE-2020-7926
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the ser…
MongoDB
4.4.1+
MEDIUM 6.5
CVE-2020-7923
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the que…
MongoDB
4.0.19 / 4.2.8+
MEDIUM 5.3
CVE-2019-2388
In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops …
Ops Manager
Mitigation only
MEDIUM 5.3
CVE-2020-7921
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credent…
MongoDB
3.6.18 / 4.0.15+
MEDIUM 5.5
CVE-2020-12135
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() par…
C Driver
0.8+
MEDIUM 6.5
CVE-2020-7922
X.509 certificates generated by the MongoDB Enterprise Kubernetes Operator may allow an attacker with access to the Kubernetes cluster improper acces…
Mongodb Enterprise Kubernetes Operator
after 1.4.4
MEDIUM 5.4
CVE-2019-2391
Incorrect parsing of certain JSON input may result in js-bson not correctly serializing BSON. This may cause unexpected application behaviour includi…
Js Bson
1.1.4+
CRITICAL 9.8
CVE-2020-7610
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsot…
Bson
1.1.4+
HIGH 7.5
CVE-2015-4411EPSS 6%
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of servic…
Bson
3.0.4+
HIGH 7.8
CVE-2019-2390
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs ship…
MongoDB
3.4.22 / 3.6.14+
HIGH 7.1
CVE-2019-2386
After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and becom…
MongoDB
3.4.22 / 3.6.13+
HIGH 8.1
CVE-2015-7882
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.
MongoDB
after 3.0.6
HIGH 8.1
CVE-2018-16790
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read vi…
Libbson
Patch available
HIGH 7.5
CVE-2018-13863
The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Servi…
Js Bson
1.0.5+
HIGH 7.0
CVE-2017-2665
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file…
MongoDB
Mitigation only
CRITICAL 9.1
CVE-2017-15535
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol com…
MongoDB
3.4.10+
HIGH 7.5
CVE-2017-14227
In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at…
MongoDB
Mitigation only