Vulnerabilities in MongoDB Inc

61 results
Vexday analysis

Com 61 CVEs catalogadas e nenhuma em exploração ativa no catálogo KEV da CISA, o MongoDB Inc apresenta uma taxa de exploração abaixo da média geral do catálogo, o que sugere superfície de risco operacional relativamente contida no momento. A ausência de falhas críticas, de provas de conceito públicas e de vulnerabilidades surgidas nos últimos 90 dias reforça um perfil de ameaça imediata baixo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que historicamente favorece encadeamentos com outras vulnerabilidades e merece atenção contínua em revisões de código e configuração. A CVE mais relevante no momento, CVE-2023-0437, possui EPSS de 0,011, indicando baixa probabilidade estimada de exploração em curto prazo, embora seu monitoramento continue recomendado para equipes que mantêm ambientes MongoDB em produção.

CVE-2024-6384MEDIUMBackup files may be downloaded by underprivileged users in MongoDB Enterprise ServerEPSS 0.4%CVE-2025-3084MEDIUMMongoDB Server may crash due to improper validation of explain commandEPSS 0.4%CVE-2024-6381MEDIUMMongoDB C Driver bson_strfreev may be susceptible to integer overflowEPSS 0.4%CVE-2024-6375MEDIUMMissing authorization check may lead to shard key refinementEPSS 0.4%CVE-2024-8654MEDIUMMongoDB Server may access non-initialized region of memory leading to unexpected behaviourEPSS 0.4%CVE-2025-10060MEDIUMMongoDB may be susceptible to Invariant Failure in Transactions due Upsert OperationEPSS 0.4%CVE-2026-4147HIGHStack memory disclosure in filemd5 commandEPSS 0.4%CVE-2026-4358MEDIUMMemory safety issues in slot-based execution hash table spillEPSS 0.4%CVE-2025-6713HIGHMongoDB Server may be susceptible to privilege escalation due to $mergeCursors stageEPSS 0.4%CVE-2025-1691HIGHMongoDB Shell may be susceptible to Control Character Injection via autocompleteEPSS 0.4%CVE-2025-6710HIGHPre-authentication Denial of Service Stack Overflow Vulnerability in JSON Parsing via Excessive Recursion in MongoDBEPSS 0.4%CVE-2026-25612HIGHInternal ResourceId collision may affect unrelated collectionsEPSS 0.3%CVE-2025-10061MEDIUMMalformed $group Query May Cause MongoDB Server to CrashEPSS 0.3%CVE-2025-6714HIGHIncorrect Handling of incomplete data may prevent mongoS from Accepting New ConnectionsEPSS 0.3%CVE-2026-25609MEDIUMprofile command may permit unauthorized configurationEPSS 0.3%CVE-2026-1849HIGHMongod can run out of stack memory when expressions create deeply nested documentsEPSS 0.3%CVE-2025-7259MEDIUMCertain Queries with Duplicate _id Fields May Cause MongoDB Server to CrashEPSS 0.3%CVE-2025-6712MEDIUMMongoDB Server may be susceptible to DoS due to Accumulated Memory AllocationEPSS 0.3%CVE-2025-1692MEDIUMMongoDB Shell may be susceptible to control character injection via pastingEPSS 0.3%CVE-2024-6382MEDIUMAdversarial unsanitized input may cause MongoDB Rust Driver to issue unintended commands.EPSS 0.3%