Mongodb
62 known vulnerabilities
Top Products
A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during
A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a cr
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted is
An authorized user may disable the MongoDB server by issuing a query against a collection that contains an invalid compo
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
Incorrect validation of the profile command may result in the determination that a request altering the 'filter' is read
Complex queries can cause excessive memory usage in MongoDB Query Planner resulting in an Out-Of-Memory Crash.
MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents
Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes i
Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the o
Frequently Asked Questions
How many CVEs affect Mongodb?
Mongodb has 62 CVE records in our database, including 0 critical and 13 high severity vulnerabilities.
What are the most severe Mongodb vulnerabilities?
Mongodb has 0 critical severity (CVSS 9.0+) and 13 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Mongodb vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Mongodb products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Mongodb Vulnerabilities
CyberStrike scans your infrastructure for Mongodb vulnerabilities and provides real-time remediation guidance.
Get Started