Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MongoDB Server — Vulnerabilities & Security Advisories 171

All 171 CVE vulnerabilities found in MongoDB Server, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for MongoDB Server, a NoSQL database system developed by MongoDB Inc. It collects critical flaws categorized by weakness type, such as remote code execution, privilege escalation, and denial-of-service issues, covering advisories published over the last several years. Readers can use this resource to track the vendor’s security advisories, understand specific weakness classes like injection or buffer overflow, and review the historical vulnerability landscape for this product. The data is organized to support security analysts, developers, and IT managers who need to assess risk exposure and monitor remediation trends without navigating through disparate sources.

Vendor: MongoDB Inc.

CVE ID Title CVSS Severity Published
CVE-2021-20333 Server log entry spoofing via newline injection CWE-117 5.3 Medium 2021-07-23
CVE-2021-20326 Specially crafted query may result in a denial of service of mongod CWE-20 6.5 Medium 2021-04-30
CVE-2018-25004 Invariant failure when explaining a find with a UUID CWE-20 4.9 Medium 2021-03-01
CVE-2020-7929 Specially crafted regex query can cause DoS CWE-185 6.5 Medium 2021-03-01
CVE-2019-20925 Denial of service via malformed network packet CWE-839 7.5 High 2020-11-24
CVE-2018-20803 Infinite loop in aggregation expression CWE-835 6.5 Medium 2020-11-23
CVE-2020-7928 Improper neutralization of null byte leads to read overrun CWE-158 6.5 Medium 2020-11-23
CVE-2019-2393 Crash while joining collections with $lookup CWE-416 6.5 Medium 2020-11-23
CVE-2019-20923 Crash while handling internal Javascript exception types CWE-749 6.5 Medium 2020-11-23
CVE-2019-20924 Invariant in IndexBoundsBuilder CWE-394 6.5 Medium 2020-11-23
CVE-2019-2392 $mod can result in undefined behavior CWE-190 6.5 Medium 2020-11-23
CVE-2018-20805 Invariant with $elemMatch CWE-834 6.5 Medium 2020-11-23
CVE-2018-20802 Post-auth queries on compound index may crash mongod CWE-394 6.5 Medium 2020-11-23
CVE-2018-20804 Invariant failure in applyOps CWE-20 6.5 Medium 2020-11-23
CVE-2020-7926 Specific query can cause a DoS against MongoDB Server CWE-755 6.5 Medium 2020-11-23
CVE-2020-7925 Denial of Service when processing malformed Role names CWE-475 7.5 High 2020-11-23
CVE-2020-7923 Specific GeoQuery can cause DoS against MongoDB Server CWE-755 6.5 Medium 2020-08-21
CVE-2020-7921 Administrative action may disable enforcement of per-user IP whitelisting CWE-182 4.6 Medium 2020-05-06
CVE-2019-2389 Process termination via PID file manipulation CWE-732 5.3 Medium 2019-08-30
CVE-2019-2390 Code execution on Windows via OpenSSL engine injection CWE-94 8.2 High 2019-08-30
CVE-2019-2386 Authorization session conflation CWE-285 7.1 High 2019-08-06

All 171 known CVE vulnerabilities affecting MongoDB Server with full Chinese analysis, references, and POCs where available.