Where
-Infinity
0

MongoDB MongoDB ServerImproper Authorization in MongoDB Queryable Encryption Maintenance Operations Allows Unauthorized Modification of Other Collections

Risk 60
Severity
7.2
First published (updated )

MongoDB MongoDB ServerUse-After-Free in MongoDB Query Execution Engine Leads to Denial of Service and Potential Memory Disclosure

Risk 49
Severity
7.1
First published (updated )

MongoDB MongoDB ServerMissing Authorization in MongoDB Sharded Transaction Commit/Abort Handling Leads to Cross-Shard Data Inconsistency

Risk 49
Severity
5.9
First published (updated )

MongoDB MongoDB ServerImproper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections via the validate Command

Risk 34
Severity
5.3
First published (updated )

MongoDB MongoDB ServerImproper Authorization in MongoDB Server Allows Unauthorized Actions on System Collections

Risk 60
Severity
7.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDB ServerImproper Input Validation in MongoDB Query Planner Leads to Denial of Service

Risk 38
Severity
6
First published (updated )

MongoDB MongoDB ServerImproper Authentication in MongoDB Intra-Cluster Connections Allows Credential Exposure

Risk 76
Severity
9
First published (updated )

MongoDB MongoDB ServerImproper Authorization in MongoDB profile Command Allows Unauthorized Modification of Server-Wide Diagnostic Settings

Risk 39
Severity
5.3
First published (updated )

MongoDB MongoDB ServerOut-of-Bounds Read in MongoDB Geospatial Query Processing Leads to Denial of Service and Potential Memory Disclosure

Risk 49
Severity
7.1
First published (updated )

MongoDB MongoDB ServerImproper Neutralization of Input in MongoDB Server's JavaScript Scripting Engine Leads to Unauthorized Code Execution Within Query Scopes

Risk 39
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDB ServerImproper Authorization in MongoDB applyOps Command Handling Allows Unauthorized DDL Operations on Collections

Risk 52
Severity
7
First published (updated )

MongoDB MongoDB ServerUse-After-Free in MongoDB Geospatial Validation Leads to Denial of Service

Risk 38
Severity
6
First published (updated )

MongoDB MongoDB ServerType Confusion in MongoDB Query Subsystem Leads to Denial of Service

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDB ServerOut-of-Bounds Read/Write in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Memory Disclosure

Risk 58
Severity
7.2
First published (updated )

MongoDB MongoDB ServerImproper Authorization in MongoDB Aggregation Framework Allows Read-Only User to Perform Unauthorized Write Operations

Risk 40
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDB ServerUse-After-Free in MongoDB Timeseries Bucket Handling Leads to Denial of Service and Potential Remote Code Execution

Risk 79
Severity
7.7
First published (updated )

MongoDB MongoDB ServerOut-of-Bounds Read in MongoDB Aggregation Framework Leads to Denial of Service and Potential Memory Disclosure

Risk 49
Severity
7.1
First published (updated )

MongoDB MongoDB ServerImproper Input Validation in MongoDB Timeseries Query Processing Leads to Denial of Service

Risk 40
Severity
7.1
First published (updated )

MongoDB MongoDB ServerImproper Validation in MongoDB Queryable Encryption Maintenance Operation Leads to Denial of Service and Index Corruption

Risk 49
Severity
7.1
First published (updated )

MongoDB MongoDB ServerUse-After-Free in MongoDB $graphLookup Aggregation Stage Leads to Denial of Service and Potential Remote Code Execution

Risk 63
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDB ServerImproper Input Validation in MongoDB Aggregation Command Handling Leads to Denial of Service

Risk 26
Severity
5.3
First published (updated )

MongoDB MongoDB ServerImproper Enforcement of Authentication Mechanism Restrictions in MongoDB Server Allows Use of Disabled Authentication Method

Risk 29
Severity
2.3
First published (updated )

MongoDB MongoDBImproper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination

Risk 35
Severity
6
First published (updated )

MongoDB MongoDB ServerLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader

Risk 44
Severity
6.3
First published (updated )

MongoDB MongoDBPost-authentication use-after-free in server-side JavaScript BSON-to-array conversion

Risk 79
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MongoDB MongoDBUnbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow

Risk 33
Severity
8.7
EPSS
0.34%
First published (updated )

MongoDB MongoDB ServerKeyfile contents are in MongoDB Server logs

Risk 27
Severity
6.8
EPSS
0.12%
First published (updated )

MongoDB MongoDBStack memory disclosure in filemd5 command

Risk 29
Severity
7.1
EPSS
0.22%
First published (updated )

MongoDB MongoDBServer crash via malformed binary diff passed to $_internalApplyOplogUpdate.

Risk 43
Severity
7.2
EPSS
0.30%
First published (updated )

MongoDB MongoDBGeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation

Risk 29
Severity
7.1
EPSS
0.27%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203