Vulnerabilidades em MONGODB

162 resultados
Análise Vexday

MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.

CVE-2026-88026HIGHRegular expression injection via unescaped characters in LINQ query translation in MongoDB C# DriverEPSS 0.4%CVE-2026-13066HIGHServer-Side JavaScript DBPointer BSON Serialization Memory DisclosureEPSS 0.4%CVE-2026-13073MEDIUMMongoDB Aggregation Command Invariant Assertion Failure Leading to Process TerminationEPSS 0.4%CVE-2026-82063MEDIUMUse-After-Free in MongoDB Server Cursor Management Component Leads to Denial of ServiceEPSS 0.4%CVE-2026-82059MEDIUMImproper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of ServiceEPSS 0.4%CVE-2026-81533MEDIUMMongoDB BI Connector ODBC Driver Memory-Safety Issue When Parsing Oversized LIMIT ValuesEPSS 0.4%CVE-2026-96746HIGHHeap buffer overflow via mid-scan command list growth in client topology monitoringEPSS 0.4%CVE-2026-18705HIGHImproper Authorization in MongoDB Atlas Vector Search Allows Unauthorized Access to Protected View DataEPSS 0.4%CVE-2026-18690HIGHImproper Authorization in MongoDB Server Allows Unauthorized Actions on System CollectionsEPSS 0.4%CVE-2026-18691CRITICALImproper Authentication in MongoDB Intra-Cluster Connections Allows Credential ExposureEPSS 0.4%CVE-2026-76797MEDIUMMongoSQL Transition Readiness Tool Improper Neutralization of Formula Elements in Generated ReportsEPSS 0.4%CVE-2026-81526HIGHCross-database write redirection via unvalidated dotted database name in bulk write namespacesEPSS 0.3%CVE-2026-81521HIGHCross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go DriverEPSS 0.3%CVE-2026-13057MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_METAEPSS 0.3%CVE-2026-18693HIGHOut-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory DisclosureEPSS 0.3%CVE-2026-13078MEDIUMLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module LoaderEPSS 0.3%CVE-2026-5170MEDIUMUsers could trigger a crash of mongod primaries during promotion to shardedEPSS 0.3%CVE-2026-82056MEDIUMRace Condition in MongoDB Server Text Index Query Parsing Leads to Heap Use-After-Free and Denial of ServiceEPSS 0.3%CVE-2026-84968MEDIUMHeap out-of-bounds read via corrupt nested BSON in field path error messageEPSS 0.3%CVE-2026-82073HIGHImproper Validation in MongoDB Server Aggregation Framework Allows Authorization Bypass and Unauthorized Collection Access with Atlas SearchEPSS 0.3%