|
61
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechani…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9748
|
2026-06-16 02:10 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
62
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from in…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9750
|
2026-06-16 02:10 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
63
|
7.5 |
HIGH
Network
|
image-size
|
image-size
|
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-71329
|
2026-06-16 02:09 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
64
|
8.8 |
HIGH
Network
|
splunk
|
splunk splunk_cloud_platform splunk_secure_gateway
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway vers…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-20251
|
2026-06-16 02:08 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
65
|
7.5 |
HIGH
Network
|
image-size
|
image-size
|
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attack…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-71330
|
2026-06-16 02:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
66
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9747
|
2026-06-16 01:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
67
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, the server may derefe…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9743
|
2026-06-16 01:56 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
68
|
7.5 |
HIGH
Network
|
mongodb
|
mongodb
|
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain n…
Update
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-9740
|
2026-06-16 01:55 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
69
|
7.6 |
HIGH
Network
|
splunk
|
splunk splunk_cloud_platform
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privile…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-20252
|
2026-06-16 01:51 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
70
|
5.5 |
MEDIUM
Local
|
mongodb
|
mongodb
|
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parame…
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-9735
|
2026-06-16 01:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|