MongoDB Vulnerabilities
CVE security advisories and vulnerability history for MongoDB.
CVE security advisories and vulnerability history for MongoDB.
MongoDB has 249 published CVE records since 2013, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 4 have a known public exploit. The average CVSS base score across scored CVEs is 6.9.
This page aggregates every publicly disclosed vulnerability (CVE) affecting MongoDB products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
A quick read on MongoDB's vulnerability posture, as a share of its 249 published CVEs.
across 249 scored CVEs
139 of 249 scored
1 of 249 CVEs
4 of 249 CVEs
238 of 249 CVEs
How the CVSS severity of MongoDB's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of MongoDB's CVEs is confirmed exploited in the wild.
Public exploits
4
4 of MongoDB's CVEs have a known public exploit available.
The MongoDB products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
The CWE weakness categories most often found in MongoDB CVEs. Follow any weakness for its full explanation.
The CVE Numbering Authorities that publish MongoDB CVE records.
How many MongoDB CVEs were published each year.
The most recently disclosed vulnerabilities affecting MongoDB.
Track new MongoDB CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor MongoDB CVEsBrowse vulnerabilities for other tracked vendors.
Common questions about MongoDB vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new MongoDB vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.