CVE security advisories and vulnerability history for mongo by mongodb.
74
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
1
Public exploits
With known exploit
6.4
Avg CVSS
2016–2026
Last updated
Overview
mongodb mongo has 74 published CVE records since 2016, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 1 have a known public exploit. The average CVSS base score across scored CVEs is 6.4.
This page aggregates every publicly disclosed vulnerability (CVE) affecting mongodb mongo, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of mongodb mongo's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical0
High23
Medium45
Low2
4 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of mongodb mongo's CVEs is confirmed exploited in the wild.
Public exploits
1
One of mongodb mongo's CVEs has a known public exploit available.
Affected versions and CVEs
Browse every mongodb mongo version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about mongodb mongo vulnerabilities.
How many CVEs does mongodb mongo have?
mongodb mongo has 74 published CVE records since 2016.
How many mongodb mongo CVEs are in CISA KEV?
Yes — 1 of mongodb mongo's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for mongodb mongo vulnerabilities?
Yes — 1 of mongodb mongo's CVEs have a known public exploit.
Which versions of mongodb mongo are affected?
1,054 distinct mongodb mongo versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in mongodb mongo CVEs?
mongodb mongo's CVEs most often map to these CWE weakness types: CWE-20 (Improper Input Validation), CWE-617 (Reachable Assertion), CWE-285 (Improper Authorization), CWE-770 (Allocation of Resources Without Limits or Throttling).
What is the average severity of mongodb mongo CVEs?
The average CVSS base score across mongodb mongo's scored CVEs is 6.4.