CVEs classified under CWE-943, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-40141 — CVSS 9.9 (critical): A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to…
CVE-2024-4872 — CVSS 9.9 (critical): A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated…
CVE-2026-77070 — CVSS 9.8 (critical): n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate…
CVE-2026-41274 — CVSS 9.8 (critical): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node…
CVE-2026-40351 — CVSS 9.8 (critical): FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion…
CVE-2026-32248 — CVSS 9.8 (critical): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38…
CVE-2026-29793 — CVSS 9.8 (critical): Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42…
CVE-2026-20284 — CVSS 9.1 (critical): A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This…
CVE-2026-45689 — CVSS 9.1 (critical): Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5…
CVE-2026-45688 — CVSS 9.1 (critical): Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5…
CVE-2026-41328 — CVSS 9.1 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an…
CVE-2026-41327 — CVSS 9.1 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an…
CVE-2026-76316 — CVSS 8.8 (high): In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port…
CVE-2026-40352 — CVSS 8.8 (high): FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An…
CVE-2018-7829 — CVSS 8.8 (high): An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra…
CVE-2017-12904 — CVSS 8.8 (high): Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows…
CVE-2026-63637 — CVSS 8.6 (high): Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp…
CVE-2026-47835 — CVSS 8.6 (high): In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and…
CVE-2025-24787 — CVSS 8.6 (high): WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter injection in database…
CVE-2026-73975: djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject…
CVE-2026-88036 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied…
CVE-2026-88034 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a…
CVE-2026-88033 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a…
CVE-2026-88030 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a…
CVE-2026-88029 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a…
CVE-2026-88025 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a…
CVE-2026-88024 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a…
CVE-2026-88023 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a…
CVE-2026-73618 — CVSS 8.3 (high): Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied…
CVE-2026-33980 — CVSS 8.3 (high): Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure…
CVE-2026-93760 — CVSS 8.2 (high): Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its…
CVE-2026-46591 — CVSS 8.2 (high): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer…
CVE-2026-103250 — CVSS 8.1 (high): n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the…
CVE-2026-88031 — CVSS 8.1 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a…
CVE-2026-81525 — CVSS 8.1 (high): The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before…
CVE-2026-76331 — CVSS 8.1 (high): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could…
CVE-2025-60357 — CVSS 8.1 (high): AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
CVE-2026-32247 — CVSS 8.1 (high): Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher…
CVE-2026-28211 — CVSS 7.8 (high): The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions…
CVE-2026-55253 — CVSS 7.7 (high): LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and…
CVE-2026-88022 — CVSS 7.7 (high): Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an…
CVE-2026-22558 — CVSS 7.7 (high): An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access…
CVE-2026-100631 — CVSS 7.5 (high): Parse Server is an open source backend server. In versions prior to 8.6.90 and in versions from 9.0.0 prior to 9.10.1-alpha.9, the device…
CVE-2026-91937 — CVSS 7.5 (high): Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory…
CVE-2026-76254 — CVSS 7.5 (high): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to…
CVE-2026-44840 — CVSS 7.5 (high): Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is…
CVE-2026-30941 — CVSS 7.5 (high): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1…
CVE-2026-62906 — CVSS 7.4 (high): Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose…
CVE-2026-10698 — CVSS 7.2 (high): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This…
CVE-2026-73976: djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, An unauthenticated attacker can inject…