Vulnerabilidades en MONGODB
162 resultadosAnálisis Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2026-9752HIGHGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generationEPSS 0.5%CVE-2026-9746HIGHServer crashes in case of the use of exchangeEPSS 0.5%CVE-2026-9749HIGHUsing MaxKey() may crash the serverEPSS 0.5%CVE-2026-9747HIGHCrafted cross-shard merge aggregation crashes MongoDB ServerEPSS 0.5%CVE-2026-9743HIGHAggregation sub-pipeline null dereference may allow DoS via crafted getMoreEPSS 0.5%CVE-2026-88031MEDIUMGridFS data deletion via query-operator injection in file IDs in the MongoDB Go DriverEPSS 0.5%CVE-2026-18706HIGHUse-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code ExecutionEPSS 0.5%CVE-2026-88025MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C# DriverEPSS 0.5%CVE-2026-88024MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Rust DriverEPSS 0.5%CVE-2026-88023MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB PHP LibraryEPSS 0.5%CVE-2026-88029MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Python DriverEPSS 0.5%CVE-2026-88030MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Ruby DriverEPSS 0.5%CVE-2026-81517HIGHMongoDB Connector for BI Improper Error Handling of Log Write Failures May Cause Loss of SQL ServiceEPSS 0.5%CVE-2026-88034MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB C++ DriverEPSS 0.5%CVE-2026-88033MEDIUMGridFS data disclosure and deletion via query-operator injection in file IDs in the MongoDB Java DriverEPSS 0.5%CVE-2026-82062HIGHImproper Authorization in MongoDB Server applyOps Command Allows Writes to Arbitrary Internal Storage Tables via Feature Gate BypassEPSS 0.5%CVE-2026-81522HIGHCross-tenant database retargeting via dot/NUL injection in namespace strings in the C++ DriverEPSS 0.5%CVE-2026-13064HIGHMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of ServiceEPSS 0.5%CVE-2026-6914HIGHMD5 checksum creation may cause availability lossEPSS 0.4%CVE-2026-13074MEDIUMAwaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of ServiceEPSS 0.4%