Mongodb
Mongodb Mongoid: vulnerabilidades y CVE
Mongodb Mongoid tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses9
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-93764 | Alta (7.1) | 0.15% | — | 18 sept 2026 | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be… |
| CVE-2026-93763 | Alta (7.1) | 0.15% | — | 18 sept 2026 | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in… |
| CVE-2026-93762 | Crítica (9.2) | 0.57% | — | 18 sept 2026 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated… |
| CVE-2026-93761 | Alta (8.7) | 0.46% | — | 18 sept 2026 | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application… |
| CVE-2026-93760 | Alta (8.3) | 0.47% | — | 18 sept 2026 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter… |
| CVE-2026-93759 | Alta (8.8) | 0.40% | — | 18 sept 2026 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the… |
| CVE-2026-93765 | Alta (8.3) | 0.51% | — | 18 sept 2026 | Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can… |
| CVE-2026-93758 | Alta (8.6) | 0.36% | — | 18 sept 2026 | An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own.… |
| CVE-2026-2302 | Media (6.9) | 0.21% | — | 10 feb 2026 | Under specific conditions when processing a maliciously crafted value of type Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary Ruby code. |