Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MongoDB server — Vulnerabilities & Security Advisories 146

All 146 CVE vulnerabilities found in MongoDB server, with AI-generated Chinese analysis, references, and POCs.

This page serves as a comprehensive vulnerability aggregation hub for MongoDB Server, focusing on the Common Weakness Enumeration (CWE) classification system to organize and contextualize security flaws. It collects and catalogs reported security weaknesses affecting this specific database management system, covering incidents disclosed from the initial release of the software up to the present day, ensuring a complete historical perspective on its security posture. By aggregating data from multiple reliable sources, this resource allows users to track vendor advisories and official patches issued by MongoDB Inc., providing a clear timeline of remediation efforts and critical updates. Readers can use this page to understand the underlying nature of specific weakness classes, such as injection flaws or improper access controls, and how they manifest in MongoDB’s architecture. Additionally, the tool enables users to look up a product's vulnerability history, offering insights into recurring issues, severity trends, and the overall evolution of security practices within the MongoDB ecosystem. This centralized view simplifies the process of assessing risk for administrators and developers who rely on MongoDB for their data infrastructure, facilitating informed decisions regarding upgrades, mitigation strategies, and compliance requirements without the need to search across disparate security databases.

Vendor: MongoDB Inc.

CVE IDTitleCVSSSeverityPublished
CVE-2022-24272 MongoDB Server (mongod) may crash in response to unexpected requests CWE-617 6.5 Medium2022-04-21
CVE-2021-32040 Large aggregation pipelines with a specific stage can crash mongod under default configuration CWE-121 6.5 Medium2022-04-12
CVE-2021-32036 Denial of Service and Data Integrity vulnerability in features command CWE-770 5.4 Medium2022-02-04
CVE-2021-20330 Specific replication command with malformed oplog entries can crash secondaries CWE-20 6.5 Medium2021-12-15
CVE-2021-32037 User may trigger invariant when allowed to send commands directly to shards CWE-617 6.5 Medium2021-11-24
CVE-2021-20333 Server log entry spoofing via newline injection CWE-117 5.3 Medium2021-07-23
CVE-2021-20326 Specially crafted query may result in a denial of service of mongod CWE-20 6.5 Medium2021-04-30
CVE-2018-25004 Invariant failure when explaining a find with a UUID CWE-20 4.9 Medium2021-03-01
CVE-2020-7929 Specially crafted regex query can cause DoS CWE-185 6.5 Medium2021-03-01
CVE-2019-20925 Denial of service via malformed network packet CWE-839 7.5 High2020-11-24
CVE-2018-20803 Infinite loop in aggregation expression CWE-835 6.5 Medium2020-11-23
CVE-2020-7928 Improper neutralization of null byte leads to read overrun CWE-158 6.5 Medium2020-11-23
CVE-2019-2393 Crash while joining collections with $lookup CWE-416 6.5 Medium2020-11-23
CVE-2019-20923 Crash while handling internal Javascript exception types CWE-749 6.5 Medium2020-11-23
CVE-2019-20924 Invariant in IndexBoundsBuilder CWE-394 6.5 Medium2020-11-23
CVE-2019-2392 $mod can result in undefined behavior CWE-190 6.5 Medium2020-11-23
CVE-2018-20805 Invariant with $elemMatch CWE-834 6.5 Medium2020-11-23
CVE-2018-20802 Post-auth queries on compound index may crash mongod CWE-394 6.5 Medium2020-11-23
CVE-2018-20804 Invariant failure in applyOps CWE-20 6.5 Medium2020-11-23
CVE-2020-7926 Specific query can cause a DoS against MongoDB Server CWE-755 6.5 Medium2020-11-23
CVE-2020-7925 Denial of Service when processing malformed Role names CWE-475 7.5 High2020-11-23
CVE-2020-7923 Specific GeoQuery can cause DoS against MongoDB Server CWE-755 6.5 Medium2020-08-21
CVE-2020-7921 Administrative action may disable enforcement of per-user IP whitelisting CWE-182 4.6 Medium2020-05-06
CVE-2019-2389 Process termination via PID file manipulation CWE-732 5.3 Medium2019-08-30
CVE-2019-2390 Code execution on Windows via OpenSSL engine injection CWE-94 8.2 High2019-08-30
CVE-2019-2386 Authorization session conflation CWE-285 7.1 High2019-08-06

All 146 known CVE vulnerabilities affecting MongoDB server with full Chinese analysis, references, and POCs where available.