MongoDB records
299 published records for vendor mongodb.
Researcher profile
- Entered KEV
- 1 · 0.3%
- Weaponized
- 3 · 1%
- Pre-auth RCE
- 7
- With a fix record
- 62.2%
- Median publish → KEV
- 10 days
Recurring classes
- CWE-617 Reachable Assertion24
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic18
- CWE-416 Use After Free15
- CWE-20 Improper Input Validation15
- CWE-863 Incorrect Authorization14
- CWE-770 Allocation of Resources Without Limits or Throttling11
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
299 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
89Now | CVE-2025-14847Weaponized | Zlib compressed protocol header length confusion may allow memory readmongodb · mongodb · CWE-130 | High8.7 | KEV | 83.2% | Dec 19, 2025 |
40Plan | CVE-2020-7610No exploit | All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data.mongodb · bson · CWE-502 | Critical9.8 | — | 2.3% | Mar 30, 2020 |
39Monitor | CVE-2024-1351No exploit | MongoDB Server may allow successful untrusted connectionmongodb · mongodb · CWE-295 | Critical9.8 | — | 0.5% | Mar 7, 2024 |
39Monitor | CVE-2024-6376No exploit | ejson shell parser in MongoDB Compass maybe bypassedmongodb · compass · CWE-20 | Critical9.8 | — | 0.5% | Jul 1, 2024 |
39Monitor | CVE-2024-8654No exploit | MongoDB Server may access non-initialized region of memory leading to unexpected behaviourmongodb · mongodb · CWE-908 | Critical9.8 | — | 0.4% | Sep 10, 2024 |
39Monitor | CVE-2025-3085No exploit | MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revokedmongodb · mongodb · CWE-299 | Critical9.8 | — | 0.3% | Apr 1, 2025 |
38Monitor | CVE-2026-19001No exploit | MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object namesmongodb · bi connector odbc driver · CWE-190 | Critical9.5 | — | 0.5% | Aug 12, 2026 |
37Monitor | CVE-2013-1892Weaponized | MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows rmongodb · mongodb · CWE-20 | Medium6.0 | — | 44.5% | Oct 1, 2013 |
37Monitor | CVE-2026-8431No exploit | Ops Manager RCE via webhook bodymongodb · ops manager · CWE-77 | Critical9.4 | — | 0.7% | May 12, 2026 |
36Monitor | CVE-2017-15535No exploit | MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire promongodb · mongodb | Critical9.1 | — | 1.6% | Oct 31, 2017 |
36Monitor | CVE-2026-93762No exploit | Data deletion and attribute disclosure via field-name method injection in in-memory queriesmongodb · mongoid · CWE-470 | Critical9.2 | — | 0.6% | Sep 18, 2026 |
36Monitor | CVE-2026-82067No exploit | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startupmongodb · mongodb · CWE-178 | Critical9.2 | — | 0.5% | Sep 8, 2026 |
36Monitor | CVE-2026-93393No exploit | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel streammongodb · c driver · CWE-787 | Critical9.2 | — | 0.5% | Sep 17, 2026 |
36Monitor | CVE-2026-13072No exploit | MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruptionmongodb · mongodb · CWE-122 | Critical9.2 | — | 0.4% | Jul 22, 2026 |
36Monitor | CVE-2026-18691No exploit | Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposuremongodb · mongodb · CWE-757 | Critical9.0 | — | 0.4% | Aug 11, 2026 |
35Monitor | CVE-2026-19004No exploit | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parametersmongodb · bi connector odbc driver · CWE-122 | High8.8 | — | 0.5% | Aug 12, 2026 |
35Monitor | CVE-2026-19002No exploit | Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Drivermongodb · bi connector odbc driver · CWE-120 | High8.8 | — | 0.4% | Aug 12, 2026 |
35Monitor | CVE-2026-93759No exploit | Server-side JavaScript injection via string query criteria bypassing the strict operator allowlistmongodb · mongoid · CWE-94 | High8.8 | — | 0.4% | Sep 18, 2026 |
35Monitor | CVE-2025-1692No exploit | MongoDB Shell may be susceptible to control character injection via pastingmongodb · mongosh · CWE-150 | High8.8 | — | 0.3% | Feb 27, 2025 |
35Monitor | CVE-2025-6706No exploit | Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Servermongodb · mongodb · CWE-416 | High8.8 | — | 0.3% | Jun 26, 2025 |
34Monitor | CVE-2026-8053Proof of concept | FlatBSON Duplicate Field Index Driftmongodb · mongodb · CWE-787 | High8.7 | — | 0.7% | May 13, 2026 |
34Monitor | CVE-2026-4148No exploit | ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operatorsmongodb · mongodb · CWE-416 | High8.7 | — | 0.6% | Mar 17, 2026 |
34Monitor | CVE-2026-9740No exploit | Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowmongodb · mongodb · CWE-674 | High8.7 | — | 0.5% | Jun 9, 2026 |
34Monitor | CVE-2026-82075No exploit | Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Servicemongodb · mongodb · CWE-770 | High8.7 | — | 0.5% | Sep 8, 2026 |
34Monitor | CVE-2026-82064No exploit | Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Membersmongodb · mongodb · CWE-617 | High8.7 | — | 0.5% | Sep 8, 2026 |
- CVE-2025-1484789Now
Zlib compressed protocol header length confusion may allow memory read
HighCVSS 8.7KEVWeaponizedEPSS 83%mongodb · mongodbDec 19, 2025
- CVE-2020-761040Plan
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data.
CriticalCVSS 9.8No exploitEPSS 2%mongodb · bsonMar 30, 2020
- CVE-2024-135139Monitor
MongoDB Server may allow successful untrusted connection
CriticalCVSS 9.8No exploitEPSS 1%mongodb · mongodbMar 7, 2024
- CVE-2024-637639Monitor
ejson shell parser in MongoDB Compass maybe bypassed
CriticalCVSS 9.8No exploitEPSS 0%mongodb · compassJul 1, 2024
- CVE-2024-865439Monitor
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour
CriticalCVSS 9.8No exploitEPSS 0%mongodb · mongodbSep 10, 2024
- CVE-2025-308539Monitor
MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked
CriticalCVSS 9.8No exploitEPSS 0%mongodb · mongodbApr 1, 2025
- CVE-2026-1900138Monitor
MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names
CriticalCVSS 9.5No exploitEPSS 1%mongodb · bi connector odbc driverAug 12, 2026
- CVE-2013-189237Monitor
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows r
MediumCVSS 6.0WeaponizedEPSS 45%mongodb · mongodbOct 1, 2013
- CVE-2026-843137Monitor
Ops Manager RCE via webhook body
CriticalCVSS 9.4No exploitEPSS 1%mongodb · ops managerMay 12, 2026
- CVE-2017-1553536Monitor
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire pro
CriticalCVSS 9.1No exploitEPSS 2%mongodb · mongodbOct 31, 2017
- CVE-2026-9376236Monitor
Data deletion and attribute disclosure via field-name method injection in in-memory queries
CriticalCVSS 9.2No exploitEPSS 1%mongodb · mongoidSep 18, 2026
- CVE-2026-8206736Monitor
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
CriticalCVSS 9.2No exploitEPSS 1%mongodb · mongodbSep 8, 2026
- CVE-2026-9339336Monitor
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream
CriticalCVSS 9.2No exploitEPSS 0%mongodb · c driverSep 17, 2026
- CVE-2026-1307236Monitor
MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption
CriticalCVSS 9.2No exploitEPSS 0%mongodb · mongodbJul 22, 2026
- CVE-2026-1869136Monitor
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
CriticalCVSS 9.0No exploitEPSS 0%mongodb · mongodbAug 11, 2026
- CVE-2026-1900435Monitor
MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters
HighCVSS 8.8No exploitEPSS 1%mongodb · bi connector odbc driverAug 12, 2026
- CVE-2026-1900235Monitor
Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver
HighCVSS 8.8No exploitEPSS 0%mongodb · bi connector odbc driverAug 12, 2026
- CVE-2026-9375935Monitor
Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist
HighCVSS 8.8No exploitEPSS 0%mongodb · mongoidSep 18, 2026
- CVE-2025-169235Monitor
MongoDB Shell may be susceptible to control character injection via pasting
HighCVSS 8.8No exploitEPSS 0%mongodb · mongoshFeb 27, 2025
- CVE-2025-670635Monitor
Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server
HighCVSS 8.8No exploitEPSS 0%mongodb · mongodbJun 26, 2025
- CVE-2026-805334Monitor
FlatBSON Duplicate Field Index Drift
HighCVSS 8.7Proof of conceptEPSS 1%mongodb · mongodbMay 13, 2026
- CVE-2026-414834Monitor
ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators
HighCVSS 8.7No exploitEPSS 1%mongodb · mongodbMar 17, 2026
- CVE-2026-974034Monitor
Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow
HighCVSS 8.7No exploitEPSS 1%mongodb · mongodbJun 9, 2026
- CVE-2026-8207534Monitor
Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service
HighCVSS 8.7No exploitEPSS 1%mongodb · mongodbSep 8, 2026
- CVE-2026-8206434Monitor
Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members
HighCVSS 8.7No exploitEPSS 1%mongodb · mongodbSep 8, 2026