Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51667
Total
4097
Critical
15338
High
14987
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-50325 | UNKNOWN | — | BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip | Jul 22, 2026 |
| CVE-2025-50324 | UNKNOWN | — | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component. | Jul 22, 2026 |
| CVE-2025-44090 | UNKNOWN | — | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | Jul 22, 2026 |
| CVE-2025-44089 | UNKNOWN | — | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file. | Jul 22, 2026 |
| CVE-2026-9737 | MEDIUM | 6.5 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may … | Jul 22, 2026 |
| CVE-2026-64829 | HIGH | 7.4 | Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password … | Jul 22, 2026 |
| CVE-2026-14899 | UNKNOWN | — | The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, … | Jul 22, 2026 |
| CVE-2026-14881 | HIGH | 7.8 | When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it … | Jul 22, 2026 |
| CVE-2026-13078 | HIGH | 7.7 | A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read … | Jul 22, 2026 |
| CVE-2026-13077 | HIGH | 7.1 | A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The … | Jul 22, 2026 |
| CVE-2026-13076 | MEDIUM | 6.5 | An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion … | Jul 22, 2026 |
| CVE-2026-13075 | MEDIUM | 6.5 | An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. … | Jul 22, 2026 |
| CVE-2026-13074 | MEDIUM | 5.3 | An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command … | Jul 22, 2026 |
| CVE-2026-13073 | MEDIUM | 4.3 | An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service … | Jul 22, 2026 |
| CVE-2026-13072 | HIGH | 8.1 | When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory … | Jul 22, 2026 |
| CVE-2026-13071 | MEDIUM | 6.5 | An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves … | Jul 22, 2026 |
| CVE-2026-13070 | MEDIUM | 5.3 | A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. … | Jul 22, 2026 |
| CVE-2026-13069 | MEDIUM | 6.5 | An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an … | Jul 22, 2026 |
| CVE-2026-13068 | MEDIUM | 4.2 | An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query … | Jul 22, 2026 |
| CVE-2026-13067 | MEDIUM | 6.3 | When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured … | Jul 22, 2026 |
| CVE-2026-13066 | MEDIUM | 6.5 | Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned … | Jul 22, 2026 |
| CVE-2026-13065 | MEDIUM | 6.5 | A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to … | Jul 22, 2026 |
| CVE-2026-13064 | MEDIUM | 6.5 | Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound … | Jul 22, 2026 |
| CVE-2026-13063 | MEDIUM | 4.3 | An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. … | Jul 22, 2026 |
| CVE-2026-13062 | MEDIUM | 6.5 | An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be … | Jul 22, 2026 |