Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-13072 HIGH 8.1 2026-07-22 When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in m…
CVE-2026-13071 MEDIUM 6.5 2026-07-22 An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue …
CVE-2026-13070 MEDIUM 5.3 2026-07-22 A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP …
CVE-2026-13069 MEDIUM 6.5 2026-07-22 An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing …
CVE-2026-13068 MEDIUM 4.2 2026-07-22 An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongo…
CVE-2026-13067 MEDIUM 6.3 2026-07-22 When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-li…
CVE-2026-13066 MEDIUM 6.5 2026-07-22 Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in…
CVE-2026-13065 MEDIUM 6.5 2026-07-22 A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the…
CVE-2026-13064 MEDIUM 6.5 2026-07-22 Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to…
CVE-2026-13063 MEDIUM 4.3 2026-07-22 An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation comma…
CVE-2026-13062 MEDIUM 6.5 2026-07-22 An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be s…
CVE-2026-13061 MEDIUM 4.3 2026-07-22 An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally …
CVE-2026-13060 MEDIUM 6.5 2026-07-22 An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $gra…
CVE-2026-13059 HIGH 8.1 2026-07-22 An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insuffici…
CVE-2026-13058 NONE — 2026-07-22 An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of re…
CVE-2026-13057 MEDIUM 5.3 2026-07-22 An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta agg…
CVE-2026-13056 MEDIUM 6.5 2026-07-22 Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.
CVE-2026-13055 MEDIUM 6.5 2026-07-22 The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard i…
CVE-2026-3482 MEDIUM 5.3 2026-07-22 IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticat…
CVE-2026-22049 NONE — 2026-07-22 ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when su…
CVE-2026-16624 NONE — 2026-07-22 Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then ste…
CVE-2026-65650 MEDIUM Patched 4.3 2026-07-22 Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.
CVE-2026-64835 HIGH 8.8 2026-07-22 FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger …
CVE-2026-64834 HIGH 7.5 2026-07-22 FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause deni…
CVE-2026-64833 HIGH 7.1 2026-07-22 FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by suppl…