Compass
8 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Compass, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Compass CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 8 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High6
- Medium2
Latest CVEs
The 8 most recently published vulnerabilities affecting Compass.
- CVE-2026-96750Shell script injection via server-supplied database name in Open MongoDB shell7.1
- CVE-2026-9101Prototype pollution in csv parsing4.3
- CVE-2025-0280HCL Compass is affected by a security vulnerability7.5
- CVE-2025-1755MongoDB Compass may be susceptible to local privilege escalation in Windows7.5
- CVE-2024-6376ejson shell parser in MongoDB Compass maybe bypassed7.0
- CVE-2024-3371Insufficient validation of external input in Compass may enable MITM attacks7.1
- CVE-2021-20334Local privilege escalation in MongoDB Compass for Windows4.8
- CVE-2018-10604SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulti...8.8
Product grouping is registry-driven, with AI assist and human review. How it works