Vulnerabilities > Mongodb

DATE CVE VULNERABILITY TITLE RISK
2020-11-23 CVE-2019-20923 Unspecified vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which throw unhandled Javascript exceptions containing types intended to be scoped to the Javascript engine's internals.
network
low complexity
mongodb
6.5
2020-11-23 CVE-2018-20805 Excessive Iteration vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries, which perform an $elemMatch .
network
low complexity
mongodb CWE-834
6.5
2020-11-23 CVE-2018-20804 Improper Input Validation vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted applyOps invocations.
network
low complexity
mongodb CWE-20
6.5
2020-11-23 CVE-2018-20802 Unspecified vulnerability in Mongodb
A user authorized to perform database queries may trigger denial of service by issuing specially crafted queries with compound indexes affecting QueryPlanner.
network
low complexity
mongodb
6.5
2020-11-23 CVE-2020-7926 Improper Handling of Exceptional Conditions vulnerability in Mongodb 4.4.0
A user authorized to perform database queries may cause denial of service by issuing a specially crafted query which violates an invariant in the server selection subsystem.
network
low complexity
mongodb CWE-755
6.5
2020-11-23 CVE-2020-7925 Improper Input Validation vulnerability in Mongodb
Incorrect validation of user input in the role name parser may lead to use of uninitialized memory allowing an unauthenticated attacker to use a specially crafted request to cause a denial of service.
network
low complexity
mongodb CWE-20
7.5
2020-08-21 CVE-2020-7923 Improper Handling of Exceptional Conditions vulnerability in Mongodb
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear.
network
low complexity
mongodb CWE-755
6.5
2020-05-13 CVE-2019-2388 Forced Browsing vulnerability in Mongodb OPS Manager 4.0.10/4.0.9/4.1.5
In affected Ops Manager versions there is an exposed http route was that may allow attackers to view a specific access log of a publicly exposed Ops Manager instance.
network
low complexity
mongodb CWE-425
5.3
2020-05-06 CVE-2020-7921 Incorrect Authorization vulnerability in Mongodb
Improper serialization of internal state in the authorization subsystem in MongoDB Server's authorization subsystem permits a user with valid credentials to bypass IP whitelisting protection mechanisms following administrative action.
network
high complexity
mongodb CWE-863
5.3
2020-04-24 CVE-2020-12135 Integer Overflow or Wraparound vulnerability in multiple products
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values.
local
low complexity
whoopsie-project mongodb CWE-190
5.5