Vulnerabilidades en MONGODB
50 resultadosAnálisis Vexday
MongoDB apresenta um perfil de risco mínimo com apenas 1 CVE crítica registrada na base, sem evidência atual de exploração em ataques documentados. A vulnerabilidade não é recente e está associada à fraqueza CWE-1104 (Use of Unmaintained Third Party Components), indicando risco potencial relacionado a dependências obsoletas em vez de falhas diretas do produto.
CVE-2026-13057MEDIUMAuthorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_METAEPSS 0.3%CVE-2026-13071HIGHServer-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process TerminationEPSS 0.2%CVE-2026-13077HIGHOut-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn DataEPSS 0.2%CVE-2026-13060HIGH$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection AccessEPSS 0.2%CVE-2026-13076HIGHAggregation Framework Memory Exhaustion Leading to Process TerminationEPSS 0.2%CVE-2026-9737HIGHFind command with $meta sort can lead to crashEPSS 0.2%CVE-2026-13075HIGH$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion GenerationEPSS 0.2%CVE-2026-13058HIGHTransaction Command Insufficient Input Validation Leading to Process TerminationEPSS 0.2%CVE-2026-13064HIGHMongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of ServiceEPSS 0.2%CVE-2026-13063MEDIUMlibmongocrypt Improper Input Validation Leading to Process TerminationEPSS 0.2%CVE-2026-13066HIGHServer-Side JavaScript DBPointer BSON Serialization Memory DisclosureEPSS 0.2%CVE-2026-9754HIGHStack memory disclosure in filemd5 commandEPSS 0.2%CVE-2026-13073MEDIUMMongoDB Aggregation Command Invariant Assertion Failure Leading to Process TerminationEPSS 0.2%CVE-2026-13078MEDIUMLocal File Disclosure in MongoDB Server via MozJS Scripting Engine Module LoaderEPSS 0.2%CVE-2026-5170MEDIUMUsers could trigger a crash of mongod primaries during promotion to shardedEPSS 0.2%CVE-2025-12119MEDIUMBulk write with options may read invalid memoryEPSS 0.2%CVE-2026-6915MEDIUMFlaw in the updateUser Command May Allow Unauthorized Configuration ChangeEPSS 0.2%CVE-2026-13061MEDIUMImproper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation StageEPSS 0.2%CVE-2025-11695HIGHConfiguration may unexpectedly disable certificate validationEPSS 0.2%CVE-2026-13069HIGHQueryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource ExhaustionEPSS 0.2%