Skip to content
Noroxi

MongoDB records

299 published records for vendor mongodb.

Researcher profile

Entered KEV
1 · 0.3%
Weaponized
3 · 1%
Pre-auth RCE
7
With a fix record
62.2%
Median publish → KEV
10 days

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

299 records
  • Zlib compressed protocol header length confusion may allow memory read

    HighCVSS 8.7KEVWeaponizedEPSS 83%

    mongodb · mongodbDec 19, 2025

  • All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data.

    CriticalCVSS 9.8No exploitEPSS 2%

    mongodb · bsonMar 30, 2020

  • CVE-2024-1351
    39Monitor

    MongoDB Server may allow successful untrusted connection

    CriticalCVSS 9.8No exploitEPSS 1%

    mongodb · mongodbMar 7, 2024

  • CVE-2024-6376
    39Monitor

    ejson shell parser in MongoDB Compass maybe bypassed

    CriticalCVSS 9.8No exploitEPSS 0%

    mongodb · compassJul 1, 2024

  • CVE-2024-8654
    39Monitor

    MongoDB Server may access non-initialized region of memory leading to unexpected behaviour

    CriticalCVSS 9.8No exploitEPSS 0%

    mongodb · mongodbSep 10, 2024

  • CVE-2025-3085
    39Monitor

    MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked

    CriticalCVSS 9.8No exploitEPSS 0%

    mongodb · mongodbApr 1, 2025

  • MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names

    CriticalCVSS 9.5No exploitEPSS 1%

    mongodb · bi connector odbc driverAug 12, 2026

  • CVE-2013-1892
    37Monitor

    MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows r

    MediumCVSS 6.0WeaponizedEPSS 45%

    mongodb · mongodbOct 1, 2013

  • CVE-2026-8431
    37Monitor

    Ops Manager RCE via webhook body

    CriticalCVSS 9.4No exploitEPSS 1%

    mongodb · ops managerMay 12, 2026

  • MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire pro

    CriticalCVSS 9.1No exploitEPSS 2%

    mongodb · mongodbOct 31, 2017

  • Data deletion and attribute disclosure via field-name method injection in in-memory queries

    CriticalCVSS 9.2No exploitEPSS 1%

    mongodb · mongoidSep 18, 2026

  • Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup

    CriticalCVSS 9.2No exploitEPSS 1%

    mongodb · mongodbSep 8, 2026

  • Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream

    CriticalCVSS 9.2No exploitEPSS 0%

    mongodb · c driverSep 17, 2026

  • MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption

    CriticalCVSS 9.2No exploitEPSS 0%

    mongodb · mongodbJul 22, 2026

  • Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure

    CriticalCVSS 9.0No exploitEPSS 0%

    mongodb · mongodbAug 11, 2026

  • MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters

    HighCVSS 8.8No exploitEPSS 1%

    mongodb · bi connector odbc driverAug 12, 2026

  • Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver

    HighCVSS 8.8No exploitEPSS 0%

    mongodb · bi connector odbc driverAug 12, 2026

  • Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist

    HighCVSS 8.8No exploitEPSS 0%

    mongodb · mongoidSep 18, 2026

  • CVE-2025-1692
    35Monitor

    MongoDB Shell may be susceptible to control character injection via pasting

    HighCVSS 8.8No exploitEPSS 0%

    mongodb · mongoshFeb 27, 2025

  • CVE-2025-6706
    35Monitor

    Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server

    HighCVSS 8.8No exploitEPSS 0%

    mongodb · mongodbJun 26, 2025

  • CVE-2026-8053
    34Monitor

    FlatBSON Duplicate Field Index Drift

    HighCVSS 8.7Proof of conceptEPSS 1%

    mongodb · mongodbMay 13, 2026

  • CVE-2026-4148
    34Monitor

    ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators

    HighCVSS 8.7No exploitEPSS 1%

    mongodb · mongodbMar 17, 2026

  • CVE-2026-9740
    34Monitor

    Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow

    HighCVSS 8.7No exploitEPSS 1%

    mongodb · mongodbJun 9, 2026

  • Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service

    HighCVSS 8.7No exploitEPSS 1%

    mongodb · mongodbSep 8, 2026

  • Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members

    HighCVSS 8.7No exploitEPSS 1%

    mongodb · mongodbSep 8, 2026