Loading HuntDB...

mongodb

5 Products 11 CVEs

CVE Severity Distribution (All Time)

Critical
0
High
1
Medium
10
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-1351 HIGH 1 year, 3 months ago

Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connect…

CVE-2023-0437 MEDIUM 1 year, 5 months ago

When calling bson_utf8_validate on some inputs a loop with an exit condition that cannot be reached may occur, i.e. an infinite loop. This issue affe…

CVE-2021-32040 MEDIUM 3 years, 2 months ago

It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and cause a stack overflow due to the…

CVE-2021-20330 MEDIUM 3 years, 6 months ago

An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in …

CVE-2021-32037 MEDIUM 3 years, 7 months ago

An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregation request is sent to a shard…

CVE-2021-20332 MEDIUM 3 years, 11 months ago

Specific MongoDB Rust Driver versions can include credentials used by the connection pool to authenticate connections in the monitoring event that is…

CVE-2021-20331 MEDIUM 4 years, 1 month ago

Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a command listener configured by …

CVE-2020-7929 MEDIUM 4 years, 4 months ago

A user authorized to perform database queries may trigger denial of service by issuing specially crafted query contain a type of regex. This issue af…

CVE-2021-20328 MEDIUM 4 years, 4 months ago

Specific versions of the Java driver that support client-side field level encryption (CSFLE) fail to perform correct host name verification on the KM…

CVE-2019-20923 MEDIUM 4 years, 7 months ago

A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript ex…