Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Mongoose
HIGH 7.5
CVE-2026-42334
Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerabilit…
Fix: 6.13.9 / 7.8.9+
Fix from $1,950
2026-05-14
Mongoose
CRITICAL 9.8
CVE-2025-23061EPSS 7%
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because…
Fix: 6.13.6 / 7.8.4+
Fix from $2,300
2025-01-15
Mongoose
CRITICAL 9.1
CVE-2024-53900
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
Fix: 6.13.5 / 7.8.3+
Fix from $2,300
2024-12-02
Mongoose
CRITICAL 9.8
CVE-2023-3696
Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.4.
Fix: 5.13.20 / 6.11.3+
Fix from $2,300
2023-07-17
Mongoose
CRITICAL 9.8
CVE-2022-2564EPSS 33%
Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.
Fix: 5.13.15 / 6.4.6+
Fix from $2,300
2022-07-28
Mongoose
CRITICAL 9.1
CVE-2019-17426
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribut…
Fix: after 5.7.4
Fix from $2,300
2019-10-10