Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Mongo Express
MEDIUM 6.1
CVE-2023-52555
In mongo-express 1.0.2, /admin allows CSRF, as demonstrated by deletion of a Collection.
No fix yet
Fix from $1,600
2024-03-01
Mongo Express
MEDIUM 6.1
CVE-2021-21422
mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-expre…
Fix: after 0.54.0
Fix from $1,600
2021-06-21
Mongo Express
HIGH 7.5
CVE-2021-23372
All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled except…
Mitigation only
Fix from $1,950
2021-04-13
Mongo Express
CRITICAL 9.8
CVE-2020-24391EPSS 75%
mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.
Fix: after 0.54.0
Fix from $2,300
2021-03-30
Mongo Express
CRITICAL 9.9
CVE-2019-10758 KEVEPSS 85%
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to pe…
Fix: 0.54.0+
Fix from $2,300
2019-12-24