Known Vulnerabilities for products from Mongo-express Project
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Mongo-express Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-23372 json | All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, du... | 7.5 - HIGH | 2021-04-13 | 2021-04-19 |
| CVE-2021-21422 json | mongo-express is a web-based MongoDB admin interface, written with Node.js and express. 1: As mentioned in this issue: https:... | 6.1 - MEDIUM | 2021-06-21 | 2021-06-29 |
| CVE-2020-24391 json | mongo-express before 1.0.0 offers support for certain advanced syntax but implements this in an unsafe way. NOTE: this may ov... | 9.8 - CRITICAL | 2021-03-30 | 2021-04-02 |
| CVE-2019-10758 json | mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of t... | 9.9 - CRITICAL | 2019-12-24 | 2020-01-02 |
Known software with vulnerabilities from Mongo-express Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Mongo-express Project | Mongo-express | 0.10.0 |