CVE Vulnerability Database

Search and browse 395,880 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-9753HIGH8.1The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed ...
CVE-2026-9752HIGH7.1An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSO...
CVE-2026-9751MEDIUM6.8The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon...
CVE-2026-9750HIGH7.1An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe...
CVE-2026-9749HIGH7.1This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran...
CVE-2026-9748HIGH7.1The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st...
CVE-2026-9747HIGH7.1Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
CVE-2026-9746HIGH7.1When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which...
CVE-2026-9743HIGH7.1In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines...
CVE-2026-9742MEDIUM5.9When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th...
CVE-2026-9741HIGH7.1A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F...
CVE-2026-9740HIGH8.7A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ...
CVE-2026-9735MEDIUM6.8MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W...
CVE-2026-46433MEDIUM6.5lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ...
CVE-2026-46374HIGH7.5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers...
CVE-2026-46373HIGH7.5SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers...
CVE-2026-44963CRITICAL9.4A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
CVE-2026-10238Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-47905MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47904MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-47903MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-47902MEDIUM6.2CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34713HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu...
CVE-2026-34712HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v...
CVE-2026-34711HIGH7.5CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparo...