Mongodb-inc
30 CVEs tracked since 2024. Since Jul 2024, none of them reached CISA KEV.
Mongodb-inc CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-07 | 5 | 0 |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | 5 | 0 |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | 5 | 0 |
| 2025-08 | null or fewer | |
| 2025-09 | 4 | 0 |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | 11 | 0 |
Products
The products that kept showing up in Mongodb-inc's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Mongodb-inc.
- CVE-2026-93759Server-side JavaScript injection via string query criteria bypassing the strict operator allowlist8.6
- CVE-2026-93760NoSQL injection of JavaScript-executing query operators via unsafe-by-default operator guard8.2
- CVE-2026-93761Denial of service via unbounded regex matching in Mongoid's in-memory query matcher7.5
- CVE-2026-93762Data deletion and attribute disclosure via field-name method injection in in-memory queries9.8
- CVE-2026-93763Silent plaintext persistence via unresolved callable database name in encryption schema map6.5
- CVE-2026-93764Plaintext storage of encrypted fields via skipped embedded models in encryption schema generation6.5
- CVE-2026-93765Document deletion and process crash via unvalidated method-name dispatch in atomic pop operation9.1
- CVE-2026-93758Cross-principal document update, theft, and deletion via unvalidated id in nested attributes8.1
- CVE-2026-93395Integer Underflow → Heap Out-of-Bounds Read in `bson_new_from_buffer()5.3
- CVE-2026-93394libmongoc SCRAM client nonce-validation bypass3.7
- CVE-2026-93393Heap overflow via oversized decrypted TLS record sequence in Windows Secure Channel stream8.1
- CVE-2026-92757Malformed connection string may disable field level encryption5.5
- CVE-2026-92758Logs may collect sensitive information5.5
- CVE-2026-92756Combining encryption settings may disable encryption5.5
- CVE-2026-9101Prototype pollution in csv parsing4.3
The record
- Peak rank
- #84 in Feb 2026
- Busiest month shown
- Feb 2026, 11 CVEs
- Months with a KEV entry
- 0 since Jul 2024
- Monthly snapshots
- 5 since 2024