33 Total CVEs
33 AI Analyzed
1 CISA KEV
1 Critical

Profile

3% ended up actively exploited 1 of 33 added to CISA KEV
3% rated critical (CVSS 9.0+) 1 critical, 32 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

31 CVEs in the last 12 months

Products

  • MongoDB Server10
  • BI Connector5
  • BI Connector ODBC Driver3
  • C++ Driver2
  • Rust Driver2
  • C Driver1
  • Java Driver1
  • Ruby Driver1

16 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-33 of 33 CVEs
CVE-2026-88036
Analyzed
8.3
MongoDB C Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured...

2026-09-11
Full analysis →
CVE-2026-88034
Analyzed
8.3
MongoDB C++ Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structur...

2026-09-11
Full analysis →
CVE-2026-88033
Analyzed
8.3
MongoDB Java Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structu...

2026-09-11
Full analysis →
CVE-2026-88030
Analyzed
8.3
MongoDB Ruby Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structu...

2026-09-11
Full analysis →
CVE-2026-88029
Analyzed
8.3
MongoDB Python Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied struc...

2026-09-11
Full analysis →
CVE-2026-88025
Analyzed
8.3
MongoDB C# Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structure...

2026-09-11
Full analysis →
CVE-2026-88024
Analyzed
8.3
MongoDB Rust Driver

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structu...

2026-09-11
Full analysis →
CVE-2026-88023
Analyzed
8.3
MongoDB MongoDB PHP Library

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structu...

2026-09-11
Full analysis →
CVE-2026-81532
Analyzed
8.8
MongoDB BI Connector ODBC Driver

A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor...

2026-08-29
Full analysis →
CVE-2026-81525
Analyzed
8.1
MongoDB PHP Library

The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to...

2026-08-28
Full analysis →
CVE-2026-81522
Analyzed
8.1
MongoDB C++ Driver

A weakness in the MongoDB C++ Driver's handling of caller-supplied namespace identifiers allows special characters embedded in those identifiers. An a...

2026-08-28
Full analysis →
CVE-2026-81520
Analyzed
7.5
MongoDB BI Connector

A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a...

2026-08-30
Full analysis →
CVE-2026-81518
Analyzed
7.5
MongoDB BI Connector

When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does no...

2026-08-30
Full analysis →
CVE-2026-81517
Analyzed
7.5
MongoDB BI Connector

An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity...

2026-08-30
Full analysis →
CVE-2026-81490
Analyzed
7.7
MongoDB BI Connector

A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning b...

2026-08-30
Full analysis →
CVE-2026-8053
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bo...

2026-05-14
Full analysis →
CVE-2026-77586
Analyzed
8
MongoDB BI Connector

In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text re...

2026-08-30
Full analysis →
CVE-2026-6691
Analyzed
7.8
MongoDB MongoDB C Driver

The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before...

2026-05-07
Full analysis →
CVE-2026-4148
Analyzed
8.8
MongoDB MongoDB Server

A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup...

2026-03-18
Full analysis →
CVE-2026-19001
Analyzed
9.8
MongoDB BI Connector ODBC Driver

The MongoDB BI Connector ODBC Driver is susceptible to a buffer overflow during metadata retrieval, which may lead to process termination or arbitrary...

2026-08-13
Full analysis →
CVE-2026-18692
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal refe...

2026-08-12
Full analysis →
CVE-2026-18691
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechani...

2026-08-12
Full analysis →
CVE-2026-14881
Analyzed
7.8
MongoDB MongoDB Compass

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form

2026-07-24
Full analysis →
CVE-2026-13078
Analyzed
7.7
MongoDB MongoDB Server

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that en...

2026-07-24
Full analysis →
CVE-2026-13072
Analyzed
8.1
MongoDB MongoDB Server

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline proc...

2026-07-24
Full analysis →
CVE-2026-13059
Analyzed
8.1
MongoDB MongoDB Server

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access cont...

2026-07-24
Full analysis →
CVE-2026-11933
Analyzed
8.8
MongoDB MongoDB

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays

2026-06-12
Full analysis →
CVE-2025-6713
Analyzed
7.7
MongoDB MongoDB Server

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the...

2025-07-07
Full analysis →
CVE-2025-14847
KEV Analyzed
7.5
MongoDB MongoDB Server

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client

2025-12-20
Full analysis →
CVE-2025-12100
Analyzed
7.8
MongoDB BI Connector ODBC Driver

Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation

2025-10-23
Full analysis →
CVE-2025-11695
Analyzed
8
MongoDB Rust Driver

When tlsInsecure=False appears in a connection string, certificate validation is disabled

2025-10-13
Full analysis →
CVE-2025-11575
Analyzed
7.8
MongoDB Atlas SQL ODBC driver

Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation

2025-10-23
Full analysis →
CVE-2025-10491
Analyzed
7.8
MongoDB MongoDB Server

The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to...

2025-09-15
Full analysis →