Vulnerabilidades em MONGODB
162 resultadosAnálise Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2026-82074HIGHIncorrect Authorization in MongoDB Server Aggregation Framework Allows Unauthorized Read Access to Collection DataEPSS 0.3%CVE-2026-82070HIGHInsufficiently Protected Credentials in MongoDB Server Diagnostic Reporting InterfaceEPSS 0.3%CVE-2025-14911HIGHInteger Overflow in GridFS chunkSize Leading to Heap Allocation FailureEPSS 0.3%CVE-2026-82060LOWInsufficient Validation of Shard Key Values in MongoDB Server Leads to Query Operator Injection in Change Stream Post-Image LookupsEPSS 0.3%CVE-2026-18888HIGHMongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character dataEPSS 0.3%CVE-2026-89099HIGHRace Condition in MongoDB Server Document Value Layer Leads to Memory CorruptionEPSS 0.3%CVE-2026-84963MEDIUMSilent field truncation via unchecked int cast of huge JSON string values in JSON-to-BSON parserEPSS 0.3%CVE-2026-81527MEDIUMNoSQL injection via unquoted constant GroupBy keys in LINQ pipeline translationEPSS 0.3%CVE-2026-77184MEDIUMMongoDB Connector for BI Incomplete Escaping of Stored Metadata in Generated SHOW CREATE OutputEPSS 0.3%CVE-2026-96745MEDIUMPHP object injection via unsuppressible __pclass class inference in command monitoring eventsEPSS 0.3%CVE-2026-76798MEDIUMMongoSQL Transition Readiness Tool Improper Output Encoding in Generated HTML ReportsEPSS 0.3%CVE-2026-13069HIGHQueryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource ExhaustionEPSS 0.3%CVE-2026-96744HIGHUnauthorized cache lock takeover via expression injection in lock owner values in MongoDB integration for LaravelEPSS 0.3%CVE-2026-6915MEDIUMFlaw in the updateUser Command May Allow Unauthorized Configuration ChangeEPSS 0.3%CVE-2026-75159HIGHMongoDB BI Connector Improper Memory Handling During Failed Kerberos Authentication May Cause Process TerminationEPSS 0.3%CVE-2026-81529HIGHConnection-option injection via unescaped settings in the canonical MongoDB URL builderEPSS 0.3%CVE-2026-13061MEDIUMImproper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation StageEPSS 0.3%CVE-2026-18702MEDIUMImproper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic SettingsEPSS 0.3%CVE-2026-81528MEDIUMNoSQL injection via array replacement bypassing update shape validation in driver write pathEPSS 0.3%CVE-2026-84969MEDIUMHeap overflow via truncated base64 encoding of binary fields in length-limited JSON outputEPSS 0.3%