Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-44090 — OhSoft CoffeeZip Arbitrary Code Execution

An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

| Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2025-44089 — NCH Software ExpressZip Arbitrary Code Execution

An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.

| Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-9737 — Find command with $meta sort can lead to crash

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to inva…

mongodb | Remote | Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-64829 — Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot…

Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
0.0 NA
CVE-2026-14899 — Off-by-one out of bounds read in MIME header parser for forwarding

The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after …

thunderbird | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.4 HIGH
CVE-2026-14881 — Compass connection import allows to override OIDC browser open command (usually set throu…

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In particular it is possible to provide a custom brow…

compass | Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.7 HIGH
CVE-2026-13078 — Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader

A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files fr…

mongodb | Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13077 — Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data

A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an a…

mongodb | Remote | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13076 — Aggregation Framework Memory Exhaustion Leading to Process Termination

An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation within MongoDB's aggregatio…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13075 — $rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generati…

An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. The issue originates in the …

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.9 MEDIUM
CVE-2026-13074 — Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Se…

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's h…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-13073 — MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
9.2 CRITICAL
CVE-2026-13072 — MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Mem…

When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potential…

mongodb | Remote | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13071 — Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Term…

An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory ha…

mongodb | Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.0 MEDIUM
CVE-2026-13070 — Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Ter…

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enab…

mongodb | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13069 — Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhau…

An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used t…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
4.2 MEDIUM
CVE-2026-13068 — MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database…

An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for ot…

mongodb | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.2 HIGH
CVE-2026-13067 — tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket

When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unin…

mongodb | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13066 — Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure

Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the clien…

mongodb | Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.1 HIGH
CVE-2026-13065 — MongoDB $linearFill Window Function Improper Input Validation Leading to Process Terminat…

A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminat…

mongodb | Remote | Denial of Service
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
Showing 20 of 9659 Results