Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

MongoDB, Inc.

First CVE: Jul 4, 2013Active for: 13 yearsTotal CVEs: 152
53.5
VTI Score
TOP TARGET

MongoDB, Inc. maintains a focused portfolio of database and tooling products—including MongoDB server, language drivers, and administrative tools such as Compass and MongoDB Shell—that occupy a prominent position in the modern application data layer. The vendor's vulnerability profile is characterized by a recurring pattern of input-validation weaknesses, certificate-handling flaws, and assertion failures that reflect the parsing and protocol complexities inherent to a distributed database system and its client ecosystem. While the volume of disclosures is moderate relative to the vendor's prominence in the landscape, defenders should treat MongoDB security advisories seriously given the central role these products play in application infrastructure and data handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
152
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by MongoDB, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 4, 2013
13 years ago
Most Recent CVE
Jun 12, 2026
42 days ago

Self-Reporting Analysis

Of all the CVEs published by MongoDB, Inc. as a CNA, 76.9% affect products that MongoDB, Inc. develops as a vendor.

76.9%
23.1%
Self-reported: 133 (76.9%)
Third-party: 40 (23.1%)

Of all the CVEs published that affect products developed by MongoDB, Inc., 87.5% are self-published by MongoDB, Inc. as a CNA.

87.5%
12.5%
Self-published: 133 (87.5%)
Other CNAs: 19 (12.5%)

Products(25 total)

Top CVEs

Signals from CVEs in this vendor scope (152 CVEs).

152 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-14847HIGH
Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0
Dec 19, 20257.598YESYES
CVE-2013-1892MEDIUM
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a den
Oct 1, 20136.057NOYES
CVE-2026-8053HIGH
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongo
May 12, 20268.837NONO
CVE-2026-11933HIGH
A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privile
Jun 12, 20268.835NONO
CVE-2026-9753HIGH
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the serv
Jun 9, 20268.134NONO
CVE-2026-9740HIGH
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's ha
Jun 9, 20267.533NONO
CVE-2026-6691HIGH
The MongoDB C Driver's Cyrus SASL integration performs unsafe string copying during username canonicalization, enabling a heap buffer overflow before any authentication or network
May 6, 20267.832NONO
CVE-2026-4148HIGH
A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issues a specially crafted $lookup or $graphLookup aggregation p
Mar 17, 20268.832NONO
CVE-2026-8201HIGH
A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting client-side uses of mongocryptd and crypt_shared. Triggering thi
May 13, 20268.831NONO
CVE-2024-6376CRITICAL
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issu
Jul 1, 20249.831NONO
View all 152 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products152 CVEs
60%
34%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (11.8%)
Network124 (81.6%)
Unknown7 (4.6%)
Physical0 (0.0%)
Adjacent Network3 (2.0%)
Attack Complexity
Low132 (86.8%)
High13 (8.6%)
Unknown7 (4.6%)
User Interaction
None135 (88.8%)
Unknown7 (4.6%)
Required10 (6.6%)
Privileges Required
Low79 (52.0%)
High9 (5.9%)
None57 (37.5%)
Unknown7 (4.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (152 CVEs).

CISA KEV
1 CVE
0.7% of CVEs· 99th percentile
Metasploit
3 CVEs
2.0% of CVEs· 97th percentile
Nuclei
1 CVE
0.7% of CVEs· 95th percentile
ExploitDB
2 CVEs
1.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by MongoDB, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by MongoDB, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For MongoDB, Inc.'s Products

View all 4 CNAs →

Top CWEs