Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3090▲ 500 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

23.740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.19%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit or abort an in-progress prepared transaction, bypassing the intended transaction coordination process. This could result in cross-shard data inconsistency, cluster clock corruption, and violation of…
AnalizadaMedia (5.3)0.38%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value processed during an internal maintenance cycle. This could result in corruption of…
AnalizadaMedia (5.3)0.26%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the server process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service.
AnalizadaAlta (7.5)0.47%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or, potentially, execution of unintended code.
AnalizadaAlta (7.1)0.36%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied fields when constructing an internal request…
AnalizadaAlta (7.1)0.20%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization…
AnalizadaBaja (2.3)0.14%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms. This could allow authentication through a…
AnalizadaMedia (5.3)0.27%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide, potentially obscuring unauthorized activity,…
AnalizadaAlta (7.1)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.
AnalizadaMedia (6)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator. This could result in a server crash,…
AnalizadaMedia (6)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service, affecting connected clients and…
AnalizadaMedia (5.3)0.24%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain deployment configurations, unauthorized…
AnalizadaAlta (8.7)0.44%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections routed through the affected mongos instance.
AnalizadaAlta (7)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is due to an inconsistency in how the target…
AnalizadaAlta (7.1)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.
AnalizadaAlta (7.1)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the server accessing memory outside its…
AnalizadaAlta (7.2)0.34%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result in the server accessing memory outside…
AnalizadaAlta (7.7)0.57%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or, potentially, execution of unintended code.
AnalizadaCrítica (9)0.36%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared internal credential to be transmitted in a…
AnalizadaAlta (7.2)0.41%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and recreated without proper authorization.
AnalizadaAlta (7.1)0.40%—Mongodb11/8/202616/9/2026
An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may potentially expose a limited amount of…
AnalizadaAlta (7.1)0.23%—Mongodb11/8/202616/9/2026
MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed request that leads to a server crash or…
AnalizadaMedia (4)0.10%—Intel Xeon Bronze 3408u FirmwareIntel Xeon Gold 5403n FirmwareIntel Xeon Gold 5411n FirmwareIntel Xeon Gold 5412u Firmware+13711/8/202628/8/2026
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are…
AplazadaAlta (7.2)0.46%—Uoregon TAUAI11/8/202624/9/2026
Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any authenticated user to read or permanently delete another tenant's project by supplying an arbitrary project ID to the GET and DELETE /projects/{id} endpoints. The GitHubTokenHTTPAuth middleware only…
AnalizadaAlta (8.5)0.12%—Intel Xeon 6315p FirmwareIntel Xeon 6325p FirmwareIntel Xeon 6333p FirmwareIntel Xeon 6337p Firmware+17111/8/202631/8/2026
Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur…