CVE Vulnerability Database

Search and browse 375,847 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-18712HIGH8.1An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg...
CVE-2026-18711HIGH7.1An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to ...
CVE-2026-18709MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit ...
CVE-2026-18708MEDIUM6.4An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus...
CVE-2026-18707MEDIUM5.3An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se...
CVE-2026-18706HIGH7.5An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation ...
CVE-2026-18705HIGH7.1An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view ...
CVE-2026-18704HIGH7.1An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor...
CVE-2026-18703MEDIUM4.2An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authe...
CVE-2026-18702MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost...
CVE-2026-18701HIGH7.1An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server ...
CVE-2026-18700MEDIUM6.5An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i...
CVE-2026-18699MEDIUM6.5An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser...
CVE-2026-18698MEDIUM5.4An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag...
CVE-2026-18697HIGH8.7An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce...
CVE-2026-18696HIGH7An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to ...
CVE-2026-18695HIGH7.1An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could...
CVE-2026-18694HIGH7.1An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus...
CVE-2026-18693HIGH7.6An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges ...
CVE-2026-18692HIGH8.8An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil...
CVE-2026-18691CRITICAL9An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc...
CVE-2026-18690HIGH8.1An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag...
CVE-2026-18688HIGH7.1An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory ...
CVE-2026-18687HIGH7.1MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para...
CVE-2026-15426HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...