CVE Vulnerability Database

Search and browse 389,015 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2025-44090HIGH8.8An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted...
CVE-2025-44089HIGH8.8An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr...
CVE-2026-9737HIGH7.1During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m...
CVE-2026-64829CRITICAL9.1Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta...
CVE-2026-14899HIGH7.5The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) ha...
CVE-2026-14881HIGH8.4When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha...
CVE-2026-13078HIGH7.7A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered...
CVE-2026-13077HIGH7.1A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read...
CVE-2026-13076MEDIUM6.5An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p...
CVE-2026-13075MEDIUM6.5An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th...
CVE-2026-13074MEDIUM5.3An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati...
CVE-2026-13073MEDIUM4.3An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte...
CVE-2026-13072HIGH8.1When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du...
CVE-2026-13071MEDIUM6.5An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express...
CVE-2026-13070MEDIUM6A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons...
CVE-2026-13069HIGH7.1An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c...
CVE-2026-13068MEDIUM4.3An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac...
CVE-2026-13067HIGH7.2When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v...
CVE-2026-13066HIGH7.1Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i...
CVE-2026-13065HIGH7.1A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator...
CVE-2026-13064HIGH7.1Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in ...
CVE-2026-13063MEDIUM5.3An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem...
CVE-2026-13062HIGH7.1An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal ...
CVE-2026-13061MEDIUM5.3An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi...
CVE-2026-13060HIGH7.1An authenticated user with limited read privileges may be able to access documents from collections they are not authori...