Vulnerabilidades em MONGODB
162 resultadosAnálise Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2026-18697HIGHImproper Input Validation in MongoDB Aggregation Framework Allows Unauthenticated Denial of Service on mongosEPSS 0.4%CVE-2026-88022HIGHUnauthorized document disclosure and deletion via query-operator injection in explicit equality filters in MongoDB integration for LaravelEPSS 0.4%CVE-2026-13077HIGHOut-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn DataEPSS 0.4%CVE-2026-82057HIGHType Confusion in MongoDB Server WiredTiger Storage Engine via Custom Collection Configuration Leads to Persistent Denial of ServiceEPSS 0.4%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.4%CVE-2026-13075HIGH$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion GenerationEPSS 0.4%CVE-2026-13071HIGHServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationEPSS 0.4%CVE-2026-81520HIGHMongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection ExhaustionEPSS 0.4%CVE-2026-77586HIGHMongoDB Connector for BI Unescaped Object Names in Generated SHOW CREATE OutputEPSS 0.4%CVE-2026-82076HIGHInteger Overflow in Query Planner Leads to Unbounded Memory Allocation and Denial of Service in MongoDB ServerEPSS 0.4%CVE-2026-82053HIGHImproper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role AssignmentEPSS 0.4%CVE-2026-88028HIGHUnauthorized document disclosure via query-operator injection in polymorphic relation identifiers in MongoDB integration for LaravelEPSS 0.4%CVE-2026-9737HIGHFind command with $meta sort can lead to crashEPSS 0.4%CVE-2026-81490HIGHMongoDB Connector for BI Improper Error Handling During Schema Sampling May Cause Loss of SQL ServiceEPSS 0.4%CVE-2026-82069MEDIUMImproper Redaction of Query Literals in MongoDB Server Query Statistics Serialization on Sharded Cluster RouterEPSS 0.4%CVE-2026-13072CRITICALMongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory CorruptionEPSS 0.4%CVE-2026-19002HIGHCrafted database metadata may cause memory corruption in MongoDB BI Connector ODBC DriverEPSS 0.4%CVE-2026-13056HIGHA user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAMEPSS 0.4%CVE-2026-82065HIGHInsufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted MetadataEPSS 0.4%CVE-2026-18699MEDIUMImproper Input Validation in MongoDB Query Planner Leads to Denial of ServiceEPSS 0.4%