mongoosejs kayıtları
mongoosejs üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2022-2564İstismar yok | Prototype Pollution in automattic/mongoosemongoosejs · mongoose · CWE-1321 | Kritik9,8 | — | %32,7 | 28 Tem 2022 |
41Planlayın | CVE-2025-23061Kavram kanıtı | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection.mongoosejs · mongoose · CWE-94 | Kritik9,8 | — | %7,3 | 15 Oca 2025 |
39İzleyin | CVE-2023-3696İstismar yok | Prototype Pollution in automattic/mongoosemongoosejs · mongoose · CWE-1321 | Kritik9,8 | — | %1,2 | 16 Tem 2023 |
37İzleyin | CVE-2024-53900Kavram kanıtı | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.mongoosejs · mongoose · CWE-89 | Kritik9,1 | — | %4,0 | 2 Ara 2024 |
36İzleyin | CVE-2019-17426İstismar yok | Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontypemongoosejs · mongoose | Kritik9,1 | — | %1,7 | 9 Eki 2019 |
30İzleyin | CVE-2026-42334İstismar yok | Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injectionmongoosejs · mongoose · CWE-74 | Yüksek7,5 | — | %0,5 | 14 May 2026 |
- CVE-2022-256449Planlayın
Prototype Pollution in automattic/mongoose
KritikCVSS 9,8İstismar yokEPSS %33mongoosejs · mongoose28 Tem 2022
- CVE-2025-2306141Planlayın
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection.
KritikCVSS 9,8Kavram kanıtıEPSS %7mongoosejs · mongoose15 Oca 2025
- CVE-2023-369639İzleyin
Prototype Pollution in automattic/mongoose
KritikCVSS 9,8İstismar yokEPSS %1mongoosejs · mongoose16 Tem 2023
- CVE-2024-5390037İzleyin
Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.
KritikCVSS 9,1Kavram kanıtıEPSS %4mongoosejs · mongoose2 Ara 2024
- CVE-2019-1742636İzleyin
Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype
KritikCVSS 9,1İstismar yokEPSS %2mongoosejs · mongoose9 Eki 2019
- CVE-2026-4233430İzleyin
Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
YüksekCVSS 7,5İstismar yokEPSS %0mongoosejs · mongoose14 May 2026