Vulnerabilidades em MongoDB Inc

61 resultados
Análise Vexday

Com 61 CVEs catalogadas e nenhuma em exploração ativa no catálogo KEV da CISA, o MongoDB Inc apresenta uma taxa de exploração abaixo da média geral do catálogo, o que sugere superfície de risco operacional relativamente contida no momento. A ausência de falhas críticas, de provas de conceito públicas e de vulnerabilidades surgidas nos últimos 90 dias reforça um perfil de ameaça imediata baixo. O tipo de falha mais frequente é CWE-20 (validação inadequada de entrada), padrão que historicamente favorece encadeamentos com outras vulnerabilidades e merece atenção contínua em revisões de código e configuração. A CVE mais relevante no momento, CVE-2023-0437, possui EPSS de 0,011, indicando baixa probabilidade estimada de exploração em curto prazo, embora seu monitoramento continue recomendado para equipes que mantêm ambientes MongoDB em produção.

CVE-2023-0437MEDIUMMongoDB client C Driver may infinitely loop when validating certain BSON input dataEPSS 1.1%CVE-2022-48282MEDIUMDeserializing compromised object with MongoDB .NET/C# Driver may cause remote code executionEPSS 1.0%CVE-2026-25611HIGHPre-Authentication Memory Exhaustion Denial of Service in MongoDB ServerEPSS 0.8%CVE-2025-0755HIGHMongoDB C Driver bson library may be susceptible to buffer overflowEPSS 0.7%CVE-2024-5629MEDIUMOut-of-bounds read in bson module of PyMongoEPSS 0.7%CVE-2024-6383MEDIUMMongoDB C Driver bson_string_append may be vulnerable to a buffer overflowEPSS 0.6%CVE-2023-0436MEDIUMSecret logging may occur in debug mode of Atlas Operator EPSS 0.6%CVE-2021-32050MEDIUMSome MongoDB Drivers may publish events containing authentication-related data to a command listener configured by an applicationEPSS 0.6%CVE-2024-8305MEDIUMMongoDB Server secondaries may crash due to forced index constraintsEPSS 0.6%CVE-2024-3372HIGHMongoDB Server may have unexpected application behaviour due to invalid BSONEPSS 0.5%CVE-2024-10921MEDIUMImproper neutralization of null bytes may lead to buffer over-reads in MongoDB ServerEPSS 0.5%CVE-2024-1351HIGHMongoDB Server may allow successful untrusted connectionEPSS 0.5%CVE-2025-6709HIGHPre-Authentication Denial of Service Vulnerability in MongoDB Server's OIDC AuthenticationEPSS 0.5%CVE-2024-3374MEDIUMMongoDB Server (mongod) may crash when generating ftdcEPSS 0.5%CVE-2024-6384MEDIUMBackup files may be downloaded by underprivileged users in MongoDB Enterprise ServerEPSS 0.4%CVE-2024-6376HIGHejson shell parser in MongoDB Compass maybe bypassedEPSS 0.4%CVE-2025-3083HIGHMalformed MongoDB wire protocol messages may cause mongos to crashEPSS 0.4%CVE-2025-3084MEDIUMMongoDB Server may crash due to improper validation of explain commandEPSS 0.4%CVE-2024-6381MEDIUMMongoDB C Driver bson_strfreev may be susceptible to integer overflowEPSS 0.4%CVE-2024-6375MEDIUMMissing authorization check may lead to shard key refinementEPSS 0.4%