Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 561 respecto a la semana anterior
Críticas / altas1461▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

342 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.13%—Mongodb PymongoAI24/9/202626/9/2026
An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is performed in a signed 32-bit type, and the guard meant to catch the overflow is…
Pendiente de análisisAlta (8.3)0.26%—Mongodb PymongoAI24/9/202624/9/2026
PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a connection string, that party may cause additional servers of their choosing to be…
Pendiente de análisisMedia (5.3)0.13%—Mongodb Python DriverAI24/9/202624/9/2026
The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encryption key metadata stored in the database can cause an application using the driver…
Pendiente de análisisAlta (7.3)0.19%—Mongodb CompassAI24/9/202625/9/2026
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as…
Pendiente de análisisAlta (8.3)0.37%—Mongodb C DriverAI24/9/202624/9/2026
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate…
Pendiente de análisisMedia (6.3)0.30%—Mongodb PHP DriverAI24/9/202624/9/2026
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database…
AnalizadaAlta (7.1)0.15%—Mongodb Mongoid18/9/202624/9/2026
Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database,…
AnalizadaAlta (7.1)0.15%—Mongodb Mongoid18/9/202624/9/2026
A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read…
AnalizadaCrítica (9.2)0.57%—Mongodb Mongoid18/9/202624/9/2026
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored…
AnalizadaAlta (8.7)0.46%—Mongodb Mongoid18/9/202624/9/2026
An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications that place user-supplied text into a pattern-matching query condition on an…
AnalizadaAlta (8.3)0.47%—Mongodb Mongoid18/9/202624/9/2026
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query.…
AnalizadaAlta (8.8)0.40%—Mongodb Mongoid18/9/202624/9/2026
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by…
AnalizadaAlta (8.3)0.51%—Mongodb Mongoid18/9/202625/9/2026
Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended internal method invocation instead of the intended array field update. This may result…
AnalizadaAlta (8.6)0.36%—Mongodb Mongoid18/9/202625/9/2026
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping…
AnalizadaMedia (6.9)0.40%—Mongodb C Driver17/9/202625/9/2026
A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but does not verify that the value is at least 5 (the minimum valid BSON document size)…
AnalizadaMedia (6.3)0.32%—Mongodb C Driver17/9/202625/9/2026
A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized party with a man-in-the-middle position could exploit this by injecting a crafted…
AnalizadaCrítica (9.2)0.47%—Mongodb C Driver17/9/202629/9/2026
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outside the bounds of a heap allocation while processing incoming encrypted traffic…
AnalizadaMedia (5.7)0.15%—Mongodb Entity Framework Core Provider17/9/202624/9/2026
If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.
AnalizadaMedia (6.8)0.07%—Mongodb Entity Framework Core Provider17/9/202624/9/2026
Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
AnalizadaMedia (6.8)0.07%—Mongodb Entity Framework Core Provider17/9/202624/9/2026
Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored unencrypted in the database.
AplazadaAlta (7)0.28%—Oracle HelidonAIOracle Helidon-dbclient-mongodbAI15/9/202617/9/2026
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb). Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of…
AplazadaAlta (8.7)0.47%—MongodbAIFlowiseai FlowiseAI15/9/202623/9/2026
Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to other users from the shared collection.
Pendiente de análisisAlta (7.7)0.53%—Langchain Langgraph-checkpoint-mongodbAILangchain Langgraph-store-mongodbAI14/9/202630/9/2026
LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into MongoDB queries without recursively…
AnalizadaAlta (7.7)0.32%—Mongodb11/9/202629/9/2026
A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able to trigger this condition over the…
AnalizadaMedia (6.1)0.27%—Mongodb C Driver10/9/202616/9/2026
Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can influence the identifier passed by an affected…