📦

mongodb

Vendor: mongodb

Actively Exploited 1 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 3 Remote Access
Total CVEs 254 Total Indexed
Avg. EPSS 1.89% Exploit Prob.
Latest CVE CVE-2026-11933 Jun 12

Security Vulnerability Index

Page 12 / 26
4.3 CVSS

bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

EPSS: 2.63%
6.5 CVSS

MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of __system in an arbitrary database.

EPSS: 1.65%