<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – MongoDB Server (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/mongodb.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/mongodb-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – MongoDB Server (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:32 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-32625 – LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32625</guid>
    <pubDate>Tue, 02 Jun 2026 23:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32625</strong></p>
  <p>LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-c…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45685 – OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45685</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45685</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45685</strong></p>
  <p>OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught panics in the MongoDB TCP parser, allowing a remote unauthenticated attacker to crash the telemetry agent and cause a denial of service. The parser operates on raw attacker-controlled network payloads…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45685">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45717 – Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45717</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45717</guid>
    <pubDate>Wed, 27 May 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45717</strong></p>
  <p>Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoutes group with TABLE/READ permission. This is the same authorization level as the read endpoint (GET /api/datasources/:datasourceId). Every authenticated Budibase app user with the BASIC built-in role o…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45717">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42334 – Mongoose is a MongoDB object modeling tool designed to work in an asynchronous e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42334</guid>
    <pubDate>Thu, 14 May 2026 18:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42334</strong></p>
  <p>Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query sanitization mechanism via the $nor operator. When sanitizeFilter is enabled, Mongoose wraps query operators in $eq to neutralize them. However, prior to the fix, $nor was not included in the set of…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8336 – After invoking $_internalJsEmit, which is not intended to be directly accessible...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8336</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8336</guid>
    <pubDate>Wed, 13 May 2026 04:17:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8336</strong></p>
  <p>After invoking $_internalJsEmit, which is not intended to be directly accessible, or mapreduce command’s map function in a certain way, an authenticated user can subsequently crash mongod when the server-side JavaScript engine (through $where, $function, mapreduce reduce stage, etc.) is used also in a specific way, resulting in a post-authentication denial-of-service.  This issue impacts MongoDB…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8336">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8053 – An issue in MongoDB Server's time-series collection implementation allows an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8053</guid>
    <pubDate>Wed, 13 May 2026 04:17:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8053</strong></p>
  <p>An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issue results from an inconsistency in the internal field-name-to-index mapping within the time-series bucket catalog. Under certain conditions this can result in arbitrary code execution.  This issue imp…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-8431 – An administrative user with access to configure webhooks can execute arbitrary c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-8431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-8431</guid>
    <pubDate>Tue, 12 May 2026 19:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-8431</strong></p>
  <p>An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.     This issue affects all MongoDB Ops Manager 7.0 versions and MongoDB Ops Manager versions 8.0.22 and prior.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-8431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6691 – The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying dur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6691</guid>
    <pubDate>Wed, 06 May 2026 16:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6691</strong></p>
  <p>The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network traffic. This may be triggered by passing untrusted input in the username of a MongoDB URI with authMechanism=GSSAPI.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40352 – FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40352</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40352</strong></p>
  <p>FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change the password of their account (or others if combined with ID manipulation) without…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40351 – FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the pas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40351</guid>
    <pubDate>Fri, 17 Apr 2026 22:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40351</strong></p>
  <p>FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the password check, enabling login as any user including the root administrator. Th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34163 – FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34163</guid>
    <pubDate>Tue, 31 Mar 2026 15:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34163</strong></p>
  <p>FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept a user-supplied URL parameter and make server-side HTTP requests to it without validating whether the URL points to an internal/private network address. Although the application has a dedicated isInt…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33539 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33539</guid>
    <pubDate>Tue, 24 Mar 2026 19:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33539</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.59 and 9.6.0-alpha.53, an attacker with master key access can execute arbitrary SQL statements on the PostgreSQL database by injecting SQL metacharacters into field name parameters of the aggregate $group pipeline stage or the distinct operation. This allows privilege esca…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32730 – ApostropheCMS is an open-source content management framework. Prior to version 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32730</guid>
    <pubDate>Wed, 18 Mar 2026 23:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32730</strong></p>
  <p>ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incorrect MongoDB query that allows incomplete login tokens — where the password was verified but TOTP/MFA requirements were NOT — to be used as fully authenticated bearer tokens. This completely bypasses…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32248 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32248</guid>
    <pubDate>Thu, 12 Mar 2026 20:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32248</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38, an unauthenticated attacker can take over any user account that was created with an authentication provider that does not validate the format of the user identifier (e.g. anonymous authentication). By sending a crafted login request, the attacker can cause th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31872 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31872</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31872</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.6 and 8.6.32, the protectedFields class-level permission (CLP) can be bypassed using dot-notation in query WHERE clauses and sort parameters. An attacker can use dot-notation to query or sort by sub-fields of a protected field, enabling a binary oracle attack to enumerate p…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-31856 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31856</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-31856</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection vulnerability exists in the PostgreSQL storage adapter when processing Increment operations on nested object fields using dot notation (e.g., stats.counter). The amount value is interpolated directly into the SQL query without parameterization or type validation. An attacker who…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31827 – Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31827</guid>
    <pubDate>Tue, 10 Mar 2026 22:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31827</strong></p>
  <p>Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops and recreates the MongoDB TTL index on the entire post collection for every new paste submission. When User B submits a paste with a short TTL (e.g., 30 seconds), the TTL index is recreated with expireAfterSeconds: 30 for all documents in the collection. This causes User A's pas…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-29793 – Feathersjs is a framework for creating web APIs and real-time applications with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29793</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29793</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-29793</strong></p>
  <p>Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript.  From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScript objects as the id argument to any service method (get, patch, update, remove). The transport layer performs no type checking on this argument. When the service uses the MongoDB adapter, these objects pass through ge…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29793">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30941 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30941</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30941</guid>
    <pubDate>Tue, 10 Mar 2026 18:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30941</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the token field in the password reset and email verification resend endpoints. The token value is passed to database queries without type validation and can…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-943</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30941">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25887 – Chartbrew is an open-source web application that can connect directly to databas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25887</guid>
    <pubDate>Fri, 06 Mar 2026 05:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25887</strong></p>
  <p>Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to version 4.8.1, there is a remote code execution vulnerability via the MongoDB dataset Query. This issue has been patched in version 4.8.1.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-3431 – On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3431</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3431</guid>
    <pubDate>Mon, 02 Mar 2026 13:16:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-3431</strong></p>
  <p>On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3431">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25611 – A series of specifically crafted, unauthenticated messages can exhaust available...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25611</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25611</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25611</strong></p>
  <p>A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-405</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25611">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21868 – Flag Forge is a Capture The Flag (CTF) platform. Versions 2.3.2 and below have a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21868</guid>
    <pubDate>Thu, 08 Jan 2026 01:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21868</strong></p>
  <p>Flag Forge is a Capture The Flag (CTF) platform. Versions 2.3.2 and below have a Regular Expression Denial of Service (ReDoS) vulnerability in the user profile API endpoint (/api/user/[username]). The application constructs a regular expression dynamically using unescaped user input (the username parameter). An attacker can exploit this by sending a specially crafted username containing regex met…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14847 – Mismatched length fields in Zlib compressed protocol headers may allow a read of...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14847</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14847</guid>
    <pubDate>Fri, 19 Dec 2025 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14847</strong></p>
  <p>Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Se…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-130</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14847">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10703 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10703</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10703</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10703</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.  The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver l…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10703">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10702 – Improper Control of Generation of Code ('Code Injection') vulnerability in Progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10702</guid>
    <pubDate>Wed, 19 Nov 2025 16:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10702</strong></p>
  <p>Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion.   The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers, DataDirect Hybrid Data Pipeline JDBC driver and the DataDirect OpenAccess JDBC driver…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12100 – Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12100</guid>
    <pubDate>Thu, 23 Oct 2025 21:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12100</strong></p>
  <p>Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11575 – Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11575</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11575</guid>
    <pubDate>Thu, 23 Oct 2025 01:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11575</strong></p>
  <p>Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11575">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61301 – Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61301</guid>
    <pubDate>Mon, 20 Oct 2025 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61301</strong></p>
  <p>Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports by generating deeply nested or oversized behavior data that trigger MongoDB BSON limits or orjson recursion errors when the sample executes in the sandbox.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62419 – DataEase is a data visualization and analytics platform. In DataEase versions th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62419</guid>
    <pubDate>Fri, 17 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62419</strong></p>
  <p>DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams field is empty, the HOSTNAME, PORT, and DATABASE values are directly concatenated into the JDBC URL without filtering illegal parameters. This allows…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11695 – When tlsInsecure=False appears in a connection string, certificate validation is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11695</guid>
    <pubDate>Mon, 13 Oct 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11695</strong></p>
  <p>When tlsInsecure=False appears in a connection string, certificate validation is disabled.  This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11535 – MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on cu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11535</guid>
    <pubDate>Wed, 08 Oct 2025 22:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11535</strong></p>
  <p>MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34227 – Nagios XI &lt; 2026R1 is vulnerable to an authenticated command injection vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34227</guid>
    <pubDate>Thu, 25 Sep 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34227</strong></p>
  <p>Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL Query, MySQL Server, Postgres Server, and Postgres Query wizards. It is possible to inject shell characters into arguments provided to the service and execute arbitrary system commands on the underlying host as the `nagios` user.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10491 – The MongoDB Windows installation MSI may leave ACLs unset on custom installation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10491</guid>
    <pubDate>Mon, 15 Sep 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10491</strong></p>
  <p>The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0 version prior to 8.0.5</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54428 – RevelaCode is an AI-powered faith-tech project that decodes biblical verses, pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54428</guid>
    <pubDate>Mon, 28 Jul 2025 21:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54428</strong></p>
  <p>RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded username and password was accidentally committed to the public repository. This could allow unauthorized access to production or staging databases, potentially leading to data exfiltration, modification…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6714 – MongoDB Server's mongos component can become unresponsive to new connections due...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6714</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6714</strong></p>
  <p>MongoDB Server's mongos component can become unresponsive to new connections due to incorrect handling of incomplete data. This affects MongoDB when configured with load balancer support. This issue affects MongoDB Server v6.0 prior to 6.0.23, MongoDB Server v7.0 prior to 7.0.20 and MongoDB Server v8.0 prior to 8.0.9  Required Configuration:  This affects MongoDB sharded clusters when configured…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6713 – An unauthorized user may leverage a specially crafted aggregation pipeline to ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6713</guid>
    <pubDate>Mon, 07 Jul 2025 15:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6713</strong></p>
  <p>An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization due to improper handling of the $mergeCursors stage in MongoDB Server. This may lead to access to data without further authorisation. This issue affects MongoDB Server MongoDB Server v8.0 versions prior to 8.0.7, MongoDB Server v7.0 versions prior to 7.0.19 and MongoDB Server v6.…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6710 – MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6710</guid>
    <pubDate>Thu, 26 Jun 2025 14:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6710</strong></p>
  <p>MongoDB Server may be susceptible to stack overflow due to JSON parsing mechanism, where specifically crafted JSON inputs may induce unwarranted levels of recursion, resulting in excessive stack space consumption. Such inputs can lead to a stack overflow that causes the server to crash which could occur pre-authorisation. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6709 – The MongoDB Server is susceptible to a denial of service vulnerability due to im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6709</guid>
    <pubDate>Thu, 26 Jun 2025 14:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6709</strong></p>
  <p>The MongoDB Server is susceptible to a denial of service vulnerability due to improper handling of specific date values in JSON input when using OIDC authentication. This can be reproduced using the mongo shell to send a malicious JSON payload leading to an invariant failure and server crash. This issue affects MongoDB Server v7.0 versions prior to 7.0.17 and MongoDB Server v8.0 versions prior to…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-40906 – BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-40906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-40906</guid>
    <pubDate>Fri, 16 May 2025 16:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-40906</strong></p>
  <p>BSON::XS versions 0.8.4 and earlier for Perl includes a bundled libbson 1.1.7, which has several vulnerabilities.  Those include CVE-2017-14227, CVE-2018-16790, CVE-2023-0437, CVE-2024-6381, CVE-2024-6383, and CVE-2025-0755.   BSON-XS was the official Perl XS implementation of MongoDB's BSON serialization, but this distribution has reached its end of life as of August 13, 2020 and is no longer su…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-40906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3085 – A MongoDB server under specific conditions running on Linux with TLS and CRL rev...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3085</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3085</guid>
    <pubDate>Tue, 01 Apr 2025 12:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3085</strong></p>
  <p>A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoD…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-299</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3085">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-3083 – Specifically crafted MongoDB wire protocol messages can cause mongos to crash du...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3083</guid>
    <pubDate>Tue, 01 Apr 2025 12:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-3083</strong></p>
  <p>Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-248</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0755 – The various bson_append functions in the MongoDB C driver library may be suscept...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0755</guid>
    <pubDate>Tue, 18 Mar 2025 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0755</strong></p>
  <p>The various bson_append functions in the MongoDB C driver library may be susceptible to buffer overflow when performing operations that could result in a final BSON document which exceeds the maximum allowable size (INT32_MAX), resulting in a segmentation fault and possible application crash. This issue affected libbson versions prior to 1.27.5, MongoDB Server v8.0 versions prior to 8.0.1 and Mon…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1755 – MongoDB Compass may be susceptible to local privilege escalation under certain c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1755</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1755</guid>
    <pubDate>Thu, 27 Feb 2025 16:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1755</strong></p>
  <p>MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\node_modules\. This issue affects MongoDB Compass prior to 1.42.1</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1755">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-1691 – The MongoDB Shell may be susceptible to control character injection where an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-1691</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-1691</guid>
    <pubDate>Thu, 27 Feb 2025 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-1691</strong></p>
  <p>The MongoDB Shell may be susceptible to control character injection where an attacker with control of the mongosh autocomplete feature, can use the autocompletion feature to input and run obfuscated malicious text. This requires user interaction in the form of the user using ‘tab’ to autocomplete text that is a prefix of the attacker’s prepared autocompletion. This issue affects mongosh versions…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-1691">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27097 – GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Fede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27097</guid>
    <pubDate>Thu, 20 Feb 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27097</strong></p>
  <p>GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a user transforms on the root level or single source with transforms, and the client sends the same query with different variables, the initial variables are used in…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20489 – A vulnerability in the storage method of the PON Controller configuration file c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20489</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20489</strong></p>
  <p>A vulnerability in the storage method of the PON Controller configuration file could allow an authenticated, local attacker with low privileges to obtain the MongoDB credentials.  This vulnerability is due to improper storage of the unencrypted database credentials on the device that is running Cisco IOS XR Software. An attacker could exploit this vulnerability by accessing the configuration fi…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-256</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-20483 – Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-20483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-20483</guid>
    <pubDate>Wed, 11 Sep 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-20483</strong></p>
  <p>Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the PON Manager MongoDB instance to perform command injection attacks on the PON Controller container and execute arbitrary…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-20483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-7553 – Incorrect validation of files loaded from a local untrusted directory may allow ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7553</guid>
    <pubDate>Wed, 07 Aug 2024 10:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-7553</strong></p>
  <p>Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions prior to 5.0.27, MongoDB Server v6.0 versions prior to 6.0.16, MongoDB Server v7.0 v…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-6376 – MongoDB Compass may be susceptible to code injection due to insufficient sandbox...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6376</guid>
    <pubDate>Mon, 01 Jul 2024 15:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-6376</strong></p>
  <p>MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3372 – Improper validation of certain metadata input may result in the server not corre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3372</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3372</guid>
    <pubDate>Tue, 14 May 2024 16:17:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3372</strong></p>
  <p>Improper validation of certain metadata input may result in the server not correctly serialising BSON. This can be performed pre-authentication and may cause unexpected application behavior including unavailability of serverStatus responses. This issue affects MongoDB Server v7.0 versions prior to 7.0.6, MongoDB Server v6.0 versions prior to 6.0.14 and MongoDB Server v.5.0 versions prior to 5.0.2…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3372">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-3371 – MongoDB Compass may accept and use insufficiently validated input from an untrus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-3371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-3371</guid>
    <pubDate>Wed, 24 Apr 2024 17:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-3371</strong></p>
  <p>MongoDB Compass may accept and use insufficiently validated input from an untrusted external source. This may cause unintended application behavior, including data disclosure and enabling attackers to impersonate users. This issue affects MongoDB Compass versions 1.35.0 to 1.42.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-360</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-3371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-1351 – Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-1351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-1351</guid>
    <pubDate>Thu, 07 Mar 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-1351</strong></p>
  <p>Under certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server may skip peer certificate validation which may result in untrusted connections to succeed. This may effectively reduce the security guarantees provided by TLS and open connections  that should have been closed due to failing certificate validation. This issue affects MongoDB Server v7.0 versions prior to and including 7.0.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-1351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-25141 – When ssl was enabled for Mongo Hook, default settings included "allow_insecure" ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25141</guid>
    <pubDate>Tue, 20 Feb 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-25141</strong></p>
  <p>When ssl was enabled for Mongo Hook, default settings included "allow_insecure" which caused that certificates were not validated. This was unexpected and undocumented. Users are recommended to upgrade to version 4.0.0, which fixes this issue.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-43651 – JumpServer is an open source bastion host. An authenticated user can exploit a v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-43651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-43651</guid>
    <pubDate>Wed, 27 Sep 2023 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-43651</strong></p>
  <p>JumpServer is an open source bastion host. An authenticated user can exploit a vulnerability in MongoDB sessions to execute arbitrary commands, leading to remote code execution. This vulnerability may further be leveraged to gain root privileges on the system. Through the WEB CLI interface provided by the koko component, a user logs into the authorized mongoDB database and exploits the MongoDB se…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-43651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-4009 – In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-4009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-4009</guid>
    <pubDate>Tue, 08 Aug 2023 09:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-4009</strong></p>
  <p>In MongoDB Ops Manager v5.0 prior to 5.0.22 and v6.0 prior to 6.0.17 it is possible for an authenticated user with project owner or project user admin access to generate an API key with the privileges of org owner resulting in privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-4009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-31997 – UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31997</guid>
    <pubDate>Sat, 01 Jul 2023 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-31997</strong></p>
  <p>UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on a local network to access MongoDB. Applicable Cloud Keys that are both (1) running UniFi OS 3.1 and (2) hosting the UniFi Network application. "Applicable Cloud Keys" include the following: Cloud Key Gen2 and Cloud Key Gen2 Plus.</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-36475 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36475</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36475</guid>
    <pubDate>Wed, 28 Jun 2023 23:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-36475</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36475">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-41331 – A missing authentication for critical function vulnerability [CWE-306] in FortiP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41331</guid>
    <pubDate>Tue, 11 Apr 2023 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-41331</strong></p>
  <p>A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39396 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39396</guid>
    <pubDate>Thu, 10 Nov 2022 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39396</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Versions prior to 4.10.18, and prior to 5.3.1 on the 5.X branch, are vulnerable to Remote Code Execution via prototype pollution. An attacker can use this prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. This issue is patched in version 5.3.1 and in 4…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39267 – Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39267</guid>
    <pubDate>Wed, 19 Oct 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39267</strong></p>
  <p>Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field in the request header. This issue has been patched in 1.8.8-release. There are no…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36076 – NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36076</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36076</guid>
    <pubDate>Fri, 02 Sep 2022 13:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36076</strong></p>
  <p>NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. Due to an unnecessarily strict conditional in the code handling the first step of the SSO process, the pre-existing logic that added (and later checked) a nonce was inadvertently rendered opt-in instead of opt-out. This re-exposed a vulnerability in that a specially crafted Man-in-the-Middle…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36076">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-36045 – NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36045</guid>
    <pubDate>Wed, 31 Aug 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-36045</strong></p>
  <p>NodeBB Forum Software is powered by Node.js and supports either Redis, MongoDB, or a PostgreSQL database. It utilizes web sockets for instant interactions and real-time notifications. `utils.generateUUID`, a helper function available in essentially all versions of NodeBB (as far back as v1.0.1 and potentially earlier) used a cryptographically insecure Pseudo-random number generator (`Math.random(…</p>
  <p><strong>CVSS:</strong> 9.0 · <strong>CWE:</strong> CWE-330</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31551 – The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows ab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31551</guid>
    <pubDate>Mon, 11 Jul 2022 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31551</strong></p>
  <p>The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-22980 – A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Qu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22980</guid>
    <pubDate>Thu, 23 Jun 2022 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-22980</strong></p>
  <p>A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-917</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-24760 – Parse Server is an open source http web server backend. In versions prior to 4.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24760</guid>
    <pubDate>Sat, 12 Mar 2022 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-24760</strong></p>
  <p>Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that leads to RCE is the Prototype Pollution vulnerable code in the file `DatabaseController.js`, so it is likely to affect Postgres and any oth…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-39187 – Parse Server is an open source backend that can be deployed to any infrastructur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-39187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-39187</guid>
    <pubDate>Thu, 02 Sep 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-39187</strong></p>
  <p>Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version 4.10.3, Parse Server crashes when if a query request contains an invalid value for the `explain` option. This is due to a bug in the MongoDB Node.js driver which throws an exception that Parse Server cannot catch. There is a patch for this issue in version 4.10.3. No workaround…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-39187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-21422 – mongo-express is a web-based MongoDB admin interface, written with Node.js and e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21422</guid>
    <pubDate>Mon, 21 Jun 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-21422</strong></p>
  <p>mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https://github.com/mongo-express/mongo-express/issues/577, when the content of a cell grows larger than supported size, clicking on a row will show full document unescaped, however this needs admin interaction on cell. 2: Data cells identified as media will be rendered as media,…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-4669 – IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a docume...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-4669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-4669</guid>
    <pubDate>Mon, 17 May 2021 17:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-4669</strong></p>
  <p>IBM Planning Analytics Local 2.0 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 184600.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-4669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-24391 – mongo-express before 1.0.0 offers support for certain advanced syntax but implem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24391</guid>
    <pubDate>Tue, 30 Mar 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-24391</strong></p>
  <p>mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may overlap CVE-2019-10769.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-35666 – Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-35666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-35666</guid>
    <pubDate>Wed, 23 Dec 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-35666</strong></p>
  <p>Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-35666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-20925 – An unauthenticated client can trigger denial of service by issuing specially cra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20925</guid>
    <pubDate>Tue, 24 Nov 2020 11:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-20925</strong></p>
  <p>An unauthenticated client can trigger denial of service by issuing specially crafted wire protocol messages, which cause the message decompressor to incorrectly allocate memory. This issue affects MongoDB Server v4.2 versions prior to 4.2.1; MongoDB Server v4.0 versions prior to 4.0.13; MongoDB Server v3.6 versions prior to 3.6.15 and MongoDB Server v3.4 versions prior to 3.4.24.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-839</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7927 – Specially crafted API calls may allow an authenticated user who holds Organizati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7927</guid>
    <pubDate>Mon, 23 Nov 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7927</strong></p>
  <p>Specially crafted API calls may allow an authenticated user who holds Organization Owner privilege to obtain an API key with Global Role privilege. This issue affects MongoDB Ops Manager v4.2 versions prior to and including 4.2.17, MongoDB Ops Manager v4.3 versions prior to and including 4.3.9 and MongoDB Ops Manager v4.4 versions prior to and including 4.4.2.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-648</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7925 – Incorrect validation of user input in the role name parser may lead to use of un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7925</guid>
    <pubDate>Mon, 23 Nov 2020 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7925</strong></p>
  <p>Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc12; MongoDB Server v4.2 versions prior to 4.2.9.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-475</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26542 – An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26542</guid>
    <pubDate>Mon, 09 Nov 2020 20:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26542</strong></p>
  <p>An issue was discovered in the MongoDB Simple LDAP plugin through 2020-10-02 for Percona Server when using the SimpleLDAP authentication in conjunction with Microsoft’s Active Directory, Percona has discovered a flaw that would allow authentication to complete when passing a blank value for the account password, leading to access against the service integrated with which Active Directory is deplo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2268 – A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2268</guid>
    <pubDate>Wed, 16 Sep 2020 14:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2268</strong></p>
  <p>A cross-site request forgery (CSRF) vulnerability in Jenkins MongoDB Plugin 1.3 and earlier allows attackers to gain access to some metadata of any arbitrary files on the Jenkins controller.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-4411 – The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-4411</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-4411</guid>
    <pubDate>Thu, 20 Feb 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-4411</strong></p>
  <p>The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue is due to an incomplete fix to CVE-2015-4410.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-4411">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-0234 – The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0234</guid>
    <pubDate>Wed, 12 Feb 2020 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-0234</strong></p>
  <p>The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-1929 – The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1929</guid>
    <pubDate>Wed, 15 Jan 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-1929</strong></p>
  <p>The Apache Beam MongoDB connector in versions 2.10.0 to 2.16.0 has an option to disable SSL trust verification. However this configuration is not respected and the certificate verification disables trust verification in every case. This exclusion also gets registered globally which disables trust checking for any code running in the same JVM.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-10758 – mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10758</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10758</guid>
    <pubDate>Tue, 24 Dec 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-10758</strong></p>
  <p>mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10758">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4374 – An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4374</guid>
    <pubDate>Mon, 04 Nov 2019 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4374</strong></p>
  <p>An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-0165 – cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-0165</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-0165</guid>
    <pubDate>Fri, 01 Nov 2019 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-0165</strong></p>
  <p>cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-0165">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-17426 – Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17426</guid>
    <pubDate>Thu, 10 Oct 2019 02:05:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-17426</strong></p>
  <p>Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2390 – An unprivileged user or program on Microsoft Windows which can create OpenSSL co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2390</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2390</guid>
    <pubDate>Fri, 30 Aug 2019 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2390</strong></p>
  <p>An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14 and MongoDB Server v3.4 prior to 3.4.22.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2390">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2386 – After user deletion in MongoDB Server the improper invalidation of authorization...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2386</guid>
    <pubDate>Tue, 06 Aug 2019 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2386</strong></p>
  <p>After user deletion in MongoDB Server the improper invalidation of authorization sessions allows an authenticated user's session to persist and become conflated with new accounts, if those accounts reuse the names of deleted ones. This issue affects MongoDB Server v4.0 versions prior to 4.0.9; MongoDB Server v3.6 versions prior to 3.6.13 and MongoDB Server v3.4 versions prior to 3.4.22.  Workarou…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-18381 – The installation process in Open edX before 2017-01-10 exposes a MongoDB instanc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-18381</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-18381</guid>
    <pubDate>Tue, 30 Jul 2019 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-18381</strong></p>
  <p>The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-18381">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-7882 – Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7882</guid>
    <pubDate>Fri, 19 Jul 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-7882</strong></p>
  <p>Improper handling of LDAP authentication in MongoDB Server versions 3.0.0 to 3.0.6 allows an unauthenticated client to gain unauthorized access.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1784 – IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1784</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1784</guid>
    <pubDate>Thu, 20 Dec 2018 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1784</strong></p>
  <p>IBM API Connect 5.0.0.0 and 5.0.8.4 is affected by a NoSQL Injection in MongoDB connector for the LoopBack framework. IBM X-Force ID: 148807.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1784">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-16790 – _bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-16790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-16790</guid>
    <pubDate>Mon, 10 Sep 2018 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-16790</strong></p>
  <p>_bson_iter_next_internal in bson-iter.c in libbson 1.12.0, as used in MongoDB mongo-c-driver and other products, has a heap-based buffer over-read via a crafted bson buffer.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-16790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-3783 – A privilege escalation detected in flintcms versions &lt;= 1.1.9 allows account tak...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3783</guid>
    <pubDate>Fri, 17 Aug 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-3783</strong></p>
  <p>A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-13863 – The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-13863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-13863</guid>
    <pubDate>Tue, 10 Jul 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-13863</strong></p>
  <p>The MongoDB bson JavaScript module (also known as js-bson) versions 0.5.0 to 1.0.x before 1.0.5 is vulnerable to a Regular Expression Denial of Service (ReDoS) in lib/bson/decimal128.js. The flaw is triggered when the Decimal128.fromString() function is called to parse a long untrusted string.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-13863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10572 – mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10572</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10572</guid>
    <pubDate>Thu, 31 May 2018 20:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10572</strong></p>
  <p>mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10572">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-9327 – Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-9327</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-9327</guid>
    <pubDate>Sat, 07 Apr 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-9327</strong></p>
  <p>Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-9327">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-8097 – io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8097</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8097</guid>
    <pubDate>Wed, 14 Mar 2018 12:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-8097</strong></p>
  <p>io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8097">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-15535 – MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-15535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-15535</guid>
    <pubDate>Wed, 01 Nov 2017 01:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-15535</strong></p>
  <p>MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify memory.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-15535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-14227 – In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c misca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-14227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-14227</guid>
    <pubDate>Sat, 09 Sep 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-14227</strong></p>
  <p>In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the bson_utf8_validate function in bson-utf8.c), as demonstrated by bson-to-json.c.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-14227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-3104 – mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-3104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-3104</guid>
    <pubDate>Fri, 14 Apr 2017 18:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-3104</strong></p>
  <p>mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-3104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5723 – Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5723</guid>
    <pubDate>Tue, 07 Jun 2016 14:06:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5723</strong></p>
  <p>Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the u…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5723">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
