15 Total CVEs
13 AI Analyzed
0 CISA KEV
3 Critical
All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-8053
Analyzed
8.8
MongoDB Server

An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bo...

2026-05-14
CVE-2026-45717
Analyzed
8.8
MongoDB datasource to

Budibase is an open-source low-code platform

2026-05-28
CVE-2026-40352
8.8
MongoDB query operators

FastGPT is an AI Agent building platform

2026-04-18
CVE-2026-40351
Analyzed
9.8
MongoDB query operator

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runt...

2026-04-18
CVE-2026-3431
Analyzed
9.8
MongoDB tool endpoints

SimStudio's MongoDB tool endpoints allow unauthenticated attackers to connect to arbitrary MongoDB instances and perform unauthorized data operations...

2026-03-03
CVE-2026-32730
8.1
MongoDB query that

ApostropheCMS is an open-source content management framework

2026-03-19
CVE-2026-19001
Analyzed
9.8
MongoDB BI Connector ODBC Driver

The MongoDB BI Connector ODBC Driver is susceptible to a buffer overflow during metadata retrieval, which may lead to process termination or arbitrary...

2026-08-13
CVE-2026-18692
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal refe...

2026-08-12
CVE-2026-18691
Analyzed
8.8
MongoDB MongoDB Server

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechani...

2026-08-12
CVE-2026-14881
Analyzed
7.8
MongoDB MongoDB Compass

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form

2026-07-24
CVE-2026-13078
Analyzed
7.7
MongoDB MongoDB Server

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that en...

2026-07-24
CVE-2026-13072
Analyzed
8.1
MongoDB MongoDB Server

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline proc...

2026-07-24
CVE-2026-13059
Analyzed
8.1
MongoDB MongoDB Server

An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access cont...

2026-07-24
CVE-2026-11933
Analyzed
8.8
MongoDB Server

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays

2026-06-12
CVE-2025-6713
Analyzed
7.7
MongoDB Multiple Products

An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the...

2025-07-07