All vulnerabilities
209 / 209
Sort
8.7
CVE-2025-14847DEB KEV
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized …
2025-01-01KEV
EPSS83.0%
pct 99
6.8
CVE-2013-1892DEB
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHe…
2013-01-01
EPSS44.5%
pct 98
6.5
CVE-2013-3969DEB
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authen…
2013-01-01
EPSS10.1%
pct 95
7.5
CVE-2015-4411DEB
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-mop…
2015-01-01Pre-auth
EPSS6.4%
pct 92
5.8
CVE-2012-6619DEB
The default configuration for MongoDB before 2.3.2 does not validate objects, which allows remo…
2012-01-01
EPSS3.9%
pct 89
5.0
CVE-2015-1609DEB
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of servi…
2015-01-01
EPSS2.8%
pct 84
3.3
CVE-2017-14227DEB
In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson…
2017-01-01
EPSS2.8%
pct 84
5.0
CVE-2013-2132DEB
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB,…
2013-01-01
EPSS2.6%
pct 83
7.5
CVE-2016-3104DEB
mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a de…
2016-01-01Pre-auth
EPSS2.5%
pct 82
9.8
CVE-2020-7610DEB
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The pack…
2020-01-01Pre-auth
EPSS2.2%
pct 79
6.3
CVE-2018-16790DEB
_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver an…
2018-01-01
EPSS2.1%
pct 79
3.7
CVE-2018-13863DEB
The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5…
2018-01-01Pre-auth
EPSS1.9%
pct 77
7.5
CVE-2021-32040DEB
It may be possible to have an extremely long aggregation pipeline in conjunction with a specifi…
2021-01-01Pre-auth
EPSS1.9%
pct 76
9.1
CVE-2015-7882DEB
Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an un…
2015-01-01Pre-auth
EPSS1.8%
pct 75
7.5
CVE-2020-7925DEB
Incorrect validation of user input in the role name parser may lead to use of uninitialized mem…
2020-01-01Pre-auth
EPSS1.7%
pct 73
7.5
CVE-2019-20925DEB
An unauthenticated client can trigger denial of service by issuing specially crafted wire proto…
2019-01-01Pre-auth
EPSS1.7%
pct 73
6.5
CVE-2013-4650DEB
MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain i…
2013-01-01
EPSS1.7%
pct 73
5.7
CVE-2017-15535DEB
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration set…
2017-01-01
EPSS1.6%
pct 72
6.5
CVE-2018-20802DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2018-01-01
EPSS1.5%
pct 70
5.0
CVE-2014-3971DEB
The CmdAuthenticate::_authenticateX509 function in db/commands/authentication_commands.cpp in m…
2014-01-01
EPSS1.5%
pct 70
6.5
CVE-2020-7928DEB
A user authorized to perform database queries may trigger a read overrun and access arbitrary m…
2020-01-01
EPSS1.4%
pct 69
6.5
CVE-2020-7926DEB
A user authorized to perform database queries may cause denial of service by issuing a speciall…
2020-01-01
EPSS1.4%
pct 68
6.5
CVE-2020-7929DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2020-01-01
EPSS1.3%
pct 66
6.5
CVE-2019-20924DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2019-01-01
EPSS1.3%
pct 66
6.5
CVE-2020-7923DEB
A user authorized to perform database queries may cause denial of service by issuing specially …
2020-01-01
EPSS1.3%
pct 66
5.3
CVE-2021-20333DEB
Sending specially crafted commands to a MongoDB Server may result in artificial log entries bei…
2021-01-01Pre-auth
EPSS1.3%
pct 66
6.5
CVE-2018-20803DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2018-01-01
EPSS1.3%
pct 65
6.5
CVE-2019-20923DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2019-01-01
EPSS1.3%
pct 65
6.5
CVE-2019-2392DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2019-01-01
EPSS1.2%
pct 65
6.5
CVE-2019-2393DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2019-01-01
EPSS1.2%
pct 65
6.5
CVE-2018-20805DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2018-01-01
EPSS1.2%
pct 65
6.5
CVE-2018-20804DEB
A user authorized to perform database queries may trigger denial of service by issuing speciall…
2018-01-01
EPSS1.2%
pct 65
7.1
CVE-2019-2386DEB
After user deletion in MongoDB Server the improper invalidation of authorization sessions allow…
2019-01-01
EPSS1.2%
pct 64
6.5
CVE-2021-32037DEB
An authorized user may trigger an invariant which may result in denial of service or server exi…
2021-01-01
EPSS1.2%
pct 63
5.5
CVE-2020-12135DEB
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and ret…
2020-01-01
EPSS1.2%
pct 63
7.5
CVE-2023-0437AST
When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be rea…
2023-01-01Pre-auth
EPSS1.1%
pct 61
7.2
CVE-2022-48282CVE
Under very specific circumstances (see Required configuration section below), a privileged user…
2022-01-01
EPSS1.0%
pct 59
6.5
CVE-2021-20330DEB
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command…
2021-01-01
EPSS1.0%
pct 59
6.5
CVE-2020-7927CVE
Specially crafted API calls may allow an authenticated user who holds Organization Owner privil…
2020-01-01
EPSS1.0%
pct 59
5.4
CVE-2021-32036DEB
An authenticated user without any specific authorizations may be able to repeatedly invoke the …
2021-01-01
EPSS1.0%
pct 58
Select a vulnerability on the left to open the preview.