Search
66,694 CVEs
EOL hidden · Show all products
CVEs (66,694, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 66,694 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-13072 | HIGH | 8.1 | 2026-07-22 | When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in m… | |
| CVE-2026-13071 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue … | |
| CVE-2026-13070 | MEDIUM | 5.3 | 2026-07-22 | A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP … | |
| CVE-2026-13069 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing … | |
| CVE-2026-13068 | MEDIUM | 4.2 | 2026-07-22 | An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongo… | |
| CVE-2026-13067 | MEDIUM | 6.3 | 2026-07-22 | When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-li… | |
| CVE-2026-13066 | MEDIUM | 6.5 | 2026-07-22 | Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in… | |
| CVE-2026-13065 | MEDIUM | 6.5 | 2026-07-22 | A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the… | |
| CVE-2026-13064 | MEDIUM | 6.5 | 2026-07-22 | Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to… | |
| CVE-2026-13063 | MEDIUM | 4.3 | 2026-07-22 | An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation comma… | |
| CVE-2026-13062 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be s… | |
| CVE-2026-13061 | MEDIUM | 4.3 | 2026-07-22 | An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally … | |
| CVE-2026-13060 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $gra… | |
| CVE-2026-13059 | HIGH | 8.1 | 2026-07-22 | An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insuffici… | |
| CVE-2026-13058 | NONE | — | 2026-07-22 | An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of re… | |
| CVE-2026-13057 | MEDIUM | 5.3 | 2026-07-22 | An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta agg… | |
| CVE-2026-13056 | MEDIUM | 6.5 | 2026-07-22 | Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error. | |
| CVE-2026-13055 | MEDIUM | 6.5 | 2026-07-22 | The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard i… | |
| CVE-2026-3482 | MEDIUM | 5.3 | 2026-07-22 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 could allow an unauthenticat… | |
| CVE-2026-22049 | NONE | — | 2026-07-22 | ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when su… | |
| CVE-2026-16624 | NONE | — | 2026-07-22 | Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then ste… | |
| CVE-2026-65650 | MEDIUM | Patched | 4.3 | 2026-07-22 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. |
| CVE-2026-64835 | HIGH | 8.8 | 2026-07-22 | FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger … | |
| CVE-2026-64834 | HIGH | 7.5 | 2026-07-22 | FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause deni… | |
| CVE-2026-64833 | HIGH | 7.1 | 2026-07-22 | FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by suppl… |