Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3038▲ 464 respecto a la semana anterior
Críticas / altas1416▲ 190 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)387▲ 170 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)0.30%—Mongodb PHP DriverAI24/9/202624/9/2026
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database…
AnalizadaMedia (6.9)0.33%—Mongodb PHP Driver3/9/202610/9/2026
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an error message that is returned to application code. This may result in unintended disclosure of limited…
AnalizadaAlta (8.6)0.49%—Mongodb PHP DriverMongodb PHP Library27/8/202629/9/2026
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An application that incorporates untrusted text into these identifiers may have operations silently directed at a…
AnalizadaMedia (6)0.37%—Mongodb PHP Driver14/5/202624/9/2026
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
ModificadaMedia (6.9)0.20%—Mongodb C DriverMongodb PHP Driver18/11/202517/6/2026
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
AnalizadaAlta (7.8)0.26%—MongodbMongodb C DriverMongodb PHP Driver7/8/202417/6/2026
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour determined by the contents of untrusted files. This issue affects MongoDB Server v5.0 versions…
ModificadaAlta (7.5)0.65%—Mongodb C++Mongodb C DriverMongodb Node.jsMongodb PHP Driver+129/8/202317/6/2026
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed. Without due care, an application may inadvertently expose…