SecAlerts
MongoDB logo

MongoDB

Security Risk Profile

43
/100
medium

Security Risk Score

Comprehensive risk assessment based on 231 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from June 1, 2013 to present

231
Total CVEs
120
Critical+High
7
Exploited
97
Unpatched

Threat Assessment

Avg CVSS
6.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
97
Critical/High
Risk Level
43/100
medium
⚠️ 7 Active Exploits 2 Zero-Days🆕 28Fresh (<7d)📈 51 in Last 30 Days

Severity Distribution

Critical
12
High
108
Medium
92
Low
8

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
64

Age Distribution

Common Weaknesses (CWE)

1
Input Validation
17
2
Use After Free
12
3
Null Pointer Dereference
7
4
Integer Overflow
6
5
Code Injection
4

Most Affected Products

1. MongoDB MongoDB486
2. MongoDB MongoDB Server122
3. MongoDB Server24
4. MongoDB C Driver Mongodb10
5. MongoDB Ops Manager8

Recent Vulnerabilities

See more →
CVE-2026-19004
CVSS 8.8high

MongoDB BI Connector ODBC Driver Memory-Safety Issue When Handling Stored Procedure Output Parameters

8/12/2026🔧 No Patch
CVE-2026-18888
CVSS 7.1high

MongoDB BI Connector ODBC driver may write outside an allocated buffer when retrieving large floating point values as character data

8/12/2026🔧 No Patch
CVE-2026-19001
CVSS 9.5critical

MongoDB BI Connector ODBC driver may write outside an allocated buffer when handling oversized catalog object names

8/12/2026🔧 No Patch
CVE-2026-19502
CVSS 6.8medium

Insufficient redaction of sensitive configuration values in diagnostic output of MongoDB SQL Schema Builder CLI

8/12/2026🔧 No Patch
CVE-2026-18712
CVSS 7.2high

Improper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections

8/11/2026🔧 No Patch
CVE-2026-18711
CVSS 7.1high

Use-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure

8/11/2026🔧 No Patch
CVE-2026-18709
CVSS 5.9medium

Missing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency

8/11/2026🔧 No Patch
CVE-2026-18698
CVSS 5.3medium

Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command

8/11/2026🔧 No Patch
CVE-2026-18690
CVSS 7.2high

Improper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections

8/11/2026🔧 No Patch
CVE-2026-18699
CVSS 6.0medium

Improper Input Validation in MongoDB Query Planner Leads to Denial of Service

8/11/2026🔧 No Patch

Monitor MongoDB in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.