Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
335 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.29% | — | Mongodb | 10/2/2026 | 17/6/2026 | MongoDB Server may experience an out-of-memory failure while evaluating expressions that produce deeply nested documents. The issue arises in recursive functions because the server does not periodically check the depth of the expression. | |
| Analizada | Alta (8.2) | 0.28% | — | Mongodb | 10/2/2026 | 17/6/2026 | Connections received from the proxy port may not count towards total accepted connections, resulting in server crashes if the total number of connections exceeds available resources. This only applies to connections accepted from the proxy port, pending the proxy protocol header. | |
| Analizada | Alta (7.1) | 0.26% | — | Mongodb | 10/2/2026 | 17/6/2026 | Inserting certain large documents into a replica set could lead to replica set secondaries not being able to fetch the oplog from the primary. This could stall replication inside the replica set leading to server crash. | |
| Aplazada | Alta (7.1) | 0.36% | — | MongodbAI | 10/2/2026 | 17/6/2026 | The internal locking mechanism of the MongoDB server uses an internal encoding of the resources in order to choose what lock to take. Collections may inadvertently collide with one another in this representation causing unavailability between them due to conflicting locks. | |
| Aplazada | Alta (8.7) | 0.65% | — | MongodbAI | 10/2/2026 | 17/6/2026 | A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server. | |
| Aplazada | Alta (7.1) | 0.32% | — | MongodbAI | 27/1/2026 | 17/6/2026 | User-controlled chunkSize metadata from MongoDB lacks appropriate validation allowing malformed GridFS metadata to overflow the bounding container. | |
| Analizada | Alta (8.7) | 83% | ⚠ Explotación activa💥 Exploit | Mongodb | 19/12/2025 | 17/6/2026 | Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0… | |
| Analizada | Baja (2.3) | 0.22% | — | Mongodb | 9/12/2025 | 7/10/2026 | A post-authentication flaw in the network two-phase commit protocol used for cross-shard transactions in MongoDB Server may lead to logical data inconsistencies under specific conditions which are not predictable and exist for a very short period of time. This error can cause the transaction coordination logic to… | |
| Analizada | Alta (7.1) | 0.33% | — | Mongodb | 25/11/2025 | 17/6/2026 | MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size exceeding BSONObjMaxSize. This issue affects MongoDB Server v7.0 versions prior to… | |
| Analizada | Baja (2.3) | 0.22% | — | Mongodb | 25/11/2025 | 17/6/2026 | A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are being executed by other users. This may cause a denial of service by preventing a fraction of queries from successfully completing. This issue affects MongoDB Server v7.0 versions prior to 7.0.26 and… | |
| Analizada | Alta (7.1) | 0.29% | — | Mongodb | 25/11/2025 | 17/6/2026 | Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON documents leading to an assert failing and process termination. This issue impacts MongoDB Server v7.0 versions prior to 7.0.26, v8.0 versions prior to 8.0.16 and MongoDB server v8.2 versions prior to… | |
| Analizada | Baja (2.3) | 0.09% | — | Mongodb | 25/11/2025 | 17/6/2026 | Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not aligning with the documented Extended Key Usage (EKU) requirements. A certificate that specifies extendedKeyUsage but is missing extendedKeyUsage = clientAuth may still be successfully authenticated via… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Aplazada | Alta (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 19/11/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Modificada | Media (6.9) | 0.20% | — | Mongodb C DriverMongodb PHP Driver | 18/11/2025 | 7/10/2026 | A mongoc_bulk_operation_t may read invalid memory if large options are passed. | |
| Analizada | Media (5.9) | 0.39% | — | Mongodb | 3/11/2025 | 17/6/2026 | The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them into invalid objects. Later reads of this object can result in read access violations. | |
| Aplazada | Alta (8.8) | 0.17% | — | Mongodb BI Connector Odbc DriverAI | 23/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in MongoDB BI Connector ODBC driver allows Privilege Escalation.This issue affects BI Connector ODBC driver: from 1.0.0 through 1.4.6. | |
| Aplazada | Alta (8.8) | 0.13% | — | Mongodb Atlas SQL Odbc DriverAI | 23/10/2025 | 17/6/2026 | Incorrect Default Permissions vulnerability in MongoDB Atlas SQL ODBC driver on Windows allows Privilege Escalation.This issue affects MongoDB Atlas SQL ODBC driver: from 1.0.0 through 2.0.0. | |
| Aplazada | Alta (7.5) | 0.36% | 💥 PoC | Capev2AIMongodbAIIJL OrjsonAI | 20/10/2025 | 5/7/2026 | Denial-of-analysis in reporting/mongodb.py and reporting/jsondump.py in CAPEv2 (commit 52e4b43, on 2025-05-17) allows attackers who can submit samples to cause incomplete or missing behavioral analysis reports by generating deeply nested or oversized behavior data that trigger MongoDB BSON limits or orjson recursion… | |
| Analizada | Media (6.5) | 0.27% | — | Mongodb | 20/10/2025 | 17/6/2026 | An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation while queries are being issued, under some conditions. This issue affects MongoDB Server v7.0 versions prior to 7.0.25, MongoDB Server v8.0 versions prior to 8.0.15, and MongoDB Server version 8.2.0. | |
| Analizada | Alta (7.5) | 0.18% | — | Mongodb Rust Driver | 13/10/2025 | 17/6/2026 | When tlsInsecure=False appears in a connection string, certificate validation is disabled. This vulnerability affects MongoDB Rust Driver versions prior to v3.2.5 | |
| Aplazada | Alta (8.8) | 0.12% | — | Mongodb Connector FOR BIAI | 8/10/2025 | 17/6/2026 | MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privilege Escalation.This issue affects MongoDB Connector for BI: from 2.0.0 through 2.14.24. | |
| Aplazada | Alta (7.8) | 0.12% | — | Mongodb ServerAI | 15/9/2025 | 17/6/2026 | The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking. This issue affects MongoDB Server v6.0 version prior to 6.0.25, MongoDB Server v7.0 version prior to 7.0.21 and MongoDB Server v8.0… | |
| Analizada | Media (6.5) | 0.32% | — | Mongodb | 5/9/2025 | 17/6/2026 | An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability is related to the incorrect handling of certain accumulator functions when additional parameters are specified within the $group operation. This vulnerability could lead to denial of service if… | |
| Analizada | Media (6.5) | 0.28% | — | Mongodb | 5/9/2025 | 17/6/2026 | An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when a generic argument (lsid) is provided in a case when it is not applicable. This affects MongoDB Server v6.0 versions prior to 6.0.x, MongoDB Server v7.0 versions prior to 7.0.18 and MongoDB Server… |