« Volver al listado

Mongodb

Mongodb Mongoid: vulnerabilidades y CVE

Mongodb Mongoid tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses9
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-93764Alta (7.1)0.15%—18 sept 2026
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be…
CVE-2026-93763Alta (7.1)0.15%—18 sept 2026
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in…
CVE-2026-93762Crítica (9.2)0.57%—18 sept 2026
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated…
CVE-2026-93761Alta (8.7)0.46%—18 sept 2026
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application…
CVE-2026-93760Alta (8.3)0.47%—18 sept 2026
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter…
CVE-2026-93759Alta (8.8)0.40%—18 sept 2026
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the…
CVE-2026-93765Alta (8.3)0.51%—18 sept 2026
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can…
CVE-2026-93758Alta (8.6)0.36%—18 sept 2026
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own.…
CVE-2026-2302Media (6.9)0.21%—10 feb 2026
Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code.

Otros productos de Mongodb