Skip to main content

Vendor archive

mongodb CVEs

Beta · best-effort

167 CVEs tagged to vendor mongodb2 Critical, 69 High, 87 Medium, 9 Low, 0 Unrated.

CVE-2025-6706

Published Jun 26, 2025

An authenticated user may trigger a use after free that may result in MongoDB Server crash and other unexpected behavior, even if the user does not have authorization to shut down…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3085

Published Apr 1, 2025

A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certifica…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3084

Published Apr 1, 2025

When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB S…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3083

Published Apr 1, 2025

Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-3082

Published Apr 1, 2025

A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects Mo…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-0755

Published Mar 18, 2025

The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which…

CVSS 8.4 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2025-1755

Published Feb 27, 2025

MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, wh…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2025-1693

Published Feb 27, 2025

The MongoDB Shell may be susceptible to control character injection where an attacker with control over the database cluster contents can inject control characters into the shell…

CVSS 3.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1692

Published Feb 27, 2025

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the user’s clipboard could manipulate them to paste text into mongosh that ev…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1691

Published Feb 27, 2025

The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input…

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-10921

Published Nov 14, 2024

An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted requests that construct malformed BSON in the Mon…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8305

Published Oct 21, 2024

prepareUnique index may cause secondaries to crash due to incorrect enforcement of index constraints on secondaries, where in extreme cases may cause multiple secondaries crashing…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8654

Published Sep 10, 2024

MongoDB Server may access non-initialized region of memory leading to unexpected behaviour when zero arguments are called in internal aggregation stage. This issue affected MongoD…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8207

Published Aug 27, 2024

In certain highly specific configurations of the host system and MongoDB server binary installation on Linux Operating Systems, it may be possible for a unintended actor with host…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6384

Published Aug 13, 2024

"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a unique backup identifier. This issue affects MongoDB Enterprise Server v6.0 versi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6382

Published Jul 2, 2024

Incorrect handling of certain string inputs may result in MongoDB Rust driver constructing unintended server commands. This may cause unexpected application behavior including dat…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6381

Published Jul 2, 2024

The bson_strfreev function in the MongoDB C driver library may be susceptible to an integer overflow where the function will try to free memory at a negative offset. This may resu…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6376

Published Jul 1, 2024

MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This iss…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6375

Published Jul 1, 2024

A command for refining a collection shard key is missing an authorization check. This may cause the command to run directly on a shard, leading to either degradation of query perf…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5629

Published Jun 5, 2024

An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitr…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3374

Published May 14, 2024

An unauthenticated user can trigger a fatal assertion in the server while generating ftdc diagnostic metrics due to attempting to build a BSON object that exceeds certain memory s…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3372

Published May 14, 2024

Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected applicatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 76-100 of 167 CVEsPage 4 of 7