Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MongoDB Inc. — Vulnerabilities & Security Advisories 67

Browse all 67 CVE security advisories affecting MongoDB Inc.. AI-powered Chinese analysis, POCs, and references for each vulnerability.

MongoDB Inc. develops a popular document-oriented NoSQL database designed for high-volume data storage and flexible schema management. With fifty recorded Common Vulnerabilities and Exposures (CVEs), the platform has historically faced issues ranging from remote code execution and cross-site scripting to privilege escalation flaws. These vulnerabilities often stem from improper input validation, authentication bypasses, or insecure default configurations in earlier releases. Notable incidents include critical flaws allowing unauthenticated access to administrative interfaces, highlighting risks associated with default settings in production environments. The company actively addresses these concerns through regular security patches and updates, emphasizing the importance of proper configuration and timely maintenance. While the software remains widely adopted for its scalability, the frequency of CVEs underscores the necessity for rigorous security hygiene and continuous monitoring to mitigate potential exploitation vectors in enterprise deployments.

CVE ID Title CVSS Severity Published
CVE-2021-32036 Denial of Service and Data Integrity vulnerability in features command — MongoDB Server CWE-770 5.4 Medium 2022-02-04
CVE-2021-32039 MongoDB Extension for VS Code may unexpectedly store credentials locally in clear text — MongoDB for VS Code CWE-522 5.5 Medium 2022-01-20
CVE-2021-20330 Specific replication command with malformed oplog entries can crash secondaries — MongoDB Server CWE-20 6.5 Medium 2021-12-15
CVE-2021-32037 User may trigger invariant when allowed to send commands directly to shards — MongoDB Server CWE-617 6.5 Medium 2021-11-24
CVE-2021-20332 MongoDB Rust Driver may publish events containing authentication-related data to a connection pool event listener configured by an application — MongoDB Rust Driver CWE-200 4.2 Medium 2021-08-02
CVE-2021-20333 Server log entry spoofing via newline injection — MongoDB Server CWE-117 5.3 Medium 2021-07-23
CVE-2021-20329 Specific cstrings input may not be properly validated in the Go Driver — MongoDB Go Driver CWE-1287 6.8 Medium 2021-06-10
CVE-2021-20331 MongoDB C# Driver may publish events containing authentication-related data to a command listener configured by an application — MongoDB C# Driver CWE-200 4.2 Medium 2021-05-13
CVE-2021-20326 Specially crafted query may result in a denial of service of mongod — MongoDB Server CWE-20 6.5 Medium 2021-04-30
CVE-2020-7924 Specific command line parameter might result in accepting invalid certificate — MongoDB Database Tools CWE-295 4.2 Medium 2021-04-12
CVE-2021-20334 Local privilege escalation in MongoDB Compass for Windows — MongoDB Compass CWE-269 4.8 Medium 2021-04-06
CVE-2018-25004 Invariant failure when explaining a find with a UUID — MongoDB Server CWE-20 4.9 Medium 2021-03-01
CVE-2020-7929 Specially crafted regex query can cause DoS — MongoDB Server CWE-185 6.5 Medium 2021-03-01
CVE-2021-20328 MongoDB Java driver client-side field level encryption not verifying KMS host name — mongo-java-driver CWE-295 6.4 Medium 2021-02-25
CVE-2021-20327 MongoDB Node.js client side field level encryption library may not be validating KMS certificate — MongoDB Node.js Driver mongodb-client-encryption module CWE-295 6.4 Medium 2021-02-25
CVE-2021-20335 SSL may be unexpectedly disabled during upgrade of multiple-server MongoDB Ops Manager — MongoDB Ops Manager CWE-319 6.7 Medium 2021-02-11
CVE-2019-20925 Denial of service via malformed network packet — MongoDB Server CWE-839 7.5 High 2020-11-24
CVE-2020-7927 Potential privilege escalation in Ops Manager API — MongoDB Ops Manager CWE-648 8.1 High 2020-11-23
CVE-2018-20803 Infinite loop in aggregation expression — MongoDB Server CWE-835 6.5 Medium 2020-11-23
CVE-2020-7928 Improper neutralization of null byte leads to read overrun — MongoDB Server CWE-158 6.5 Medium 2020-11-23
CVE-2019-2393 Crash while joining collections with $lookup — MongoDB Server CWE-416 6.5 Medium 2020-11-23
CVE-2019-20923 Crash while handling internal Javascript exception types — MongoDB Server CWE-749 6.5 Medium 2020-11-23
CVE-2019-20924 Invariant in IndexBoundsBuilder — MongoDB Server CWE-394 6.5 Medium 2020-11-23
CVE-2019-2392 $mod can result in undefined behavior — MongoDB Server CWE-190 6.5 Medium 2020-11-23
CVE-2018-20805 Invariant with $elemMatch — MongoDB Server CWE-834 6.5 Medium 2020-11-23
CVE-2018-20802 Post-auth queries on compound index may crash mongod — MongoDB Server CWE-394 6.5 Medium 2020-11-23
CVE-2018-20804 Invariant failure in applyOps — MongoDB Server CWE-20 6.5 Medium 2020-11-23
CVE-2020-7926 Specific query can cause a DoS against MongoDB Server — MongoDB Server CWE-755 6.5 Medium 2020-11-23
CVE-2020-7925 Denial of Service when processing malformed Role names — MongoDB Server CWE-475 7.5 High 2020-11-23
CVE-2020-7923 Specific GeoQuery can cause DoS against MongoDB Server — MongoDB Server CWE-755 6.5 Medium 2020-08-21

This page lists every published CVE security advisory associated with MongoDB Inc.. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.