« Volver al listado

Mongodb

Mongodb PHP Driver: vulnerabilidades y CVE

Mongodb PHP Driver tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses5
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96745Media (6.3)0.30%—24 sept 2026
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an…
CVE-2026-84968Media (6.9)0.33%—3 sept 2026
An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount of adjacent process memory copied into an…
CVE-2026-81525Alta (8.6)0.49%—27 ago 2026
The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before using them to construct the target namespace for database operations. An…
CVE-2026-6811Media (6)0.37%—14 may 2026
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is not MongoDB Server.
CVE-2025-12119Media (6.9)0.20%—18 nov 2025
A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2024-7553Alta (7.8)0.26%—7 ago 2024
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the application executing arbitrary behaviour…
CVE-2021-32050Alta (7.5)0.65%—29 ago 2023
Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript1
  2. T1190 Exploit Public-Facing Application1
  3. T1210 Exploitation of Remote Services1
  4. T1565.002 Transmitted Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Mongodb