Записи MongoDB
299 опубликованных записей вендора mongodb.
Профиль для исследователя
- Попали в KEV
- 1 · 0,3 %
- С эксплойтом
- 3 · 1 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 62,2 %
- Медиана: публикация → KEV
- 10 дн.
Повторяющиеся классы
- CWE-617 Reachable Assertion24
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic18
- CWE-416 Use After Free15
- CWE-20 Improper Input Validation15
- CWE-863 Incorrect Authorization14
- CWE-770 Allocation of Resources Without Limits or Throttling11
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
299 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
89Срочно | CVE-2025-14847Готовый эксплойт | Zlib compressed protocol header length confusion may allow memory readmongodb · mongodb · CWE-130 | Высокая8,7 | KEV | 83,2 % | 19 дек. 2025 г. |
40В плане | CVE-2020-7610Эксплойта нет | All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data.mongodb · bson · CWE-502 | Критическая9,8 | — | 2,3 % | 30 мар. 2020 г. |
39Наблюдать | CVE-2024-1351Эксплойта нет | MongoDB Server may allow successful untrusted connectionmongodb · mongodb · CWE-295 | Критическая9,8 | — | 0,5 % | 7 мар. 2024 г. |
39Наблюдать | CVE-2024-6376Эксплойта нет | ejson shell parser in MongoDB Compass maybe bypassedmongodb · compass · CWE-20 | Критическая9,8 | — | 0,5 % | 1 июл. 2024 г. |
39Наблюдать | CVE-2024-8654Эксплойта нет | MongoDB Server may access non-initialized region of memory leading to unexpected behaviourmongodb · mongodb · CWE-908 | Критическая9,8 | — | 0,4 % | 10 сент. 2024 г. |
39Наблюдать | CVE-2025-3085Эксплойта нет | MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revokedmongodb · mongodb · CWE-299 | Критическая9,8 | — | 0,3 % | 1 апр. 2025 г. |
38Наблюдать | CVE-2026-19001Эксплойта нет | MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object namesmongodb · bi connector odbc driver · CWE-190 | Критическая9,5 | — | 0,5 % | 12 авг. 2026 г. |
37Наблюдать | CVE-2013-1892Готовый эксплойт | MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows rmongodb · mongodb · CWE-20 | Средняя6,0 | — | 44,5 % | 1 окт. 2013 г. |
37Наблюдать | CVE-2026-8431Эксплойта нет | Ops Manager RCE via webhook bodymongodb · ops manager · CWE-77 | Критическая9,4 | — | 0,7 % | 12 мая 2026 г. |
36Наблюдать | CVE-2017-15535Эксплойта нет | MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire promongodb · mongodb | Критическая9,1 | — | 1,6 % | 31 окт. 2017 г. |
36Наблюдать | CVE-2026-93762Эксплойта нет | Data deletion and attribute disclosure via field-name method injection in in-memory queriesmongodb · mongoid · CWE-470 | Критическая9,2 | — | 0,6 % | 18 сент. 2026 г. |
36Наблюдать | CVE-2026-82067Эксплойта нет | Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startupmongodb · mongodb · CWE-178 | Критическая9,2 | — | 0,5 % | 8 сент. 2026 г. |
36Наблюдать | CVE-2026-93393Эксплойта нет | Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel streammongodb · c driver · CWE-787 | Критическая9,2 | — | 0,5 % | 17 сент. 2026 г. |
36Наблюдать | CVE-2026-13072Эксплойта нет | MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruptionmongodb · mongodb · CWE-122 | Критическая9,2 | — | 0,4 % | 22 июл. 2026 г. |
36Наблюдать | CVE-2026-18691Эксплойта нет | Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposuremongodb · mongodb · CWE-757 | Критическая9,0 | — | 0,4 % | 11 авг. 2026 г. |
35Наблюдать | CVE-2026-19004Эксплойта нет | MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parametersmongodb · bi connector odbc driver · CWE-122 | Высокая8,8 | — | 0,5 % | 12 авг. 2026 г. |
35Наблюдать | CVE-2026-19002Эксплойта нет | Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Drivermongodb · bi connector odbc driver · CWE-120 | Высокая8,8 | — | 0,4 % | 12 авг. 2026 г. |
35Наблюдать | CVE-2026-93759Эксплойта нет | Server-side JavaScript injection via string query criteria bypassing the strict operator allowlistmongodb · mongoid · CWE-94 | Высокая8,8 | — | 0,4 % | 18 сент. 2026 г. |
35Наблюдать | CVE-2025-1692Эксплойта нет | MongoDB Shell may be susceptible to control character injection via pastingmongodb · mongosh · CWE-150 | Высокая8,8 | — | 0,3 % | 27 февр. 2025 г. |
35Наблюдать | CVE-2025-6706Эксплойта нет | Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Servermongodb · mongodb · CWE-416 | Высокая8,8 | — | 0,3 % | 26 июн. 2025 г. |
34Наблюдать | CVE-2026-8053Proof of concept | FlatBSON Duplicate Field Index Driftmongodb · mongodb · CWE-787 | Высокая8,7 | — | 0,7 % | 13 мая 2026 г. |
34Наблюдать | CVE-2026-4148Эксплойта нет | ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operatorsmongodb · mongodb · CWE-416 | Высокая8,7 | — | 0,6 % | 17 мар. 2026 г. |
34Наблюдать | CVE-2026-9740Эксплойта нет | Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflowmongodb · mongodb · CWE-674 | Высокая8,7 | — | 0,5 % | 9 июн. 2026 г. |
34Наблюдать | CVE-2026-82075Эксплойта нет | Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Servicemongodb · mongodb · CWE-770 | Высокая8,7 | — | 0,5 % | 8 сент. 2026 г. |
34Наблюдать | CVE-2026-82064Эксплойта нет | Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Membersmongodb · mongodb · CWE-617 | Высокая8,7 | — | 0,5 % | 8 сент. 2026 г. |
- CVE-2025-1484789Срочно
Zlib compressed protocol header length confusion may allow memory read
ВысокаяCVSS 8,7KEVГотовый эксплойтEPSS 83 %mongodb · mongodb19 дек. 2025 г.
- CVE-2020-761040В плане
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mongodb · bson30 мар. 2020 г.
- CVE-2024-135139Наблюдать
MongoDB Server may allow successful untrusted connection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mongodb · mongodb7 мар. 2024 г.
- CVE-2024-637639Наблюдать
ejson shell parser in MongoDB Compass maybe bypassed
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mongodb · compass1 июл. 2024 г.
- CVE-2024-865439Наблюдать
MongoDB Server may access non-initialized region of memory leading to unexpected behaviour
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mongodb · mongodb10 сент. 2024 г.
- CVE-2025-308539Наблюдать
MongoDB Server running on Linux may allow unexpected connections where intermediate certificates are revoked
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %mongodb · mongodb1 апр. 2025 г.
- CVE-2026-1900138Наблюдать
MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %mongodb · bi connector odbc driver12 авг. 2026 г.
- CVE-2013-189237Наблюдать
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows r
СредняяCVSS 6,0Готовый эксплойтEPSS 45 %mongodb · mongodb1 окт. 2013 г.
- CVE-2026-843137Наблюдать
Ops Manager RCE via webhook body
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %mongodb · ops manager12 мая 2026 г.
- CVE-2017-1553536Наблюдать
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire pro
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %mongodb · mongodb31 окт. 2017 г.
- CVE-2026-9376236Наблюдать
Data deletion and attribute disclosure via field-name method injection in in-memory queries
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %mongodb · mongoid18 сент. 2026 г.
- CVE-2026-8206736Наблюдать
Improper Case Sensitivity Handling in MongoDB Server Configuration Validation May Cause Authorization to Remain Disabled at Startup
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %mongodb · mongodb8 сент. 2026 г.
- CVE-2026-9339336Наблюдать
Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %mongodb · c driver17 сент. 2026 г.
- CVE-2026-1307236Наблюдать
MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption
КритическаяCVSS 9,2Эксплойта нетEPSS 0 %mongodb · mongodb22 июл. 2026 г.
- CVE-2026-1869136Наблюдать
Improper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %mongodb · mongodb11 авг. 2026 г.
- CVE-2026-1900435Наблюдать
MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mongodb · bi connector odbc driver12 авг. 2026 г.
- CVE-2026-1900235Наблюдать
Crafted database metadata may cause memory corruption in MongoDB BI Connector ODBC Driver
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mongodb · bi connector odbc driver12 авг. 2026 г.
- CVE-2026-9375935Наблюдать
Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mongodb · mongoid18 сент. 2026 г.
- CVE-2025-169235Наблюдать
MongoDB Shell may be susceptible to control character injection via pasting
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mongodb · mongosh27 февр. 2025 г.
- CVE-2025-670635Наблюдать
Running certain aggregation operations with the SBE engine may lead to unexpected behavior on MongoDB Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mongodb · mongodb26 июн. 2025 г.
- CVE-2026-805334Наблюдать
FlatBSON Duplicate Field Index Drift
ВысокаяCVSS 8,7Proof of conceptEPSS 1 %mongodb · mongodb13 мая 2026 г.
- CVE-2026-414834Наблюдать
ExpressionContext use-after-free in classic engine $lookup and $graphLookup aggregation operators
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mongodb · mongodb17 мар. 2026 г.
- CVE-2026-974034Наблюдать
Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mongodb · mongodb9 июн. 2026 г.
- CVE-2026-8207534Наблюдать
Uncontrolled Resource Consumption in MongoDB Sharded Cluster Router Allows Unauthenticated Denial of Service
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mongodb · mongodb8 сент. 2026 г.
- CVE-2026-8206434Наблюдать
Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mongodb · mongodb8 сент. 2026 г.