CVEs classified under CWE-943, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-40141 — CVSS 9.9 (critical): A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to…
CVE-2024-4872 — CVSS 9.9 (critical): A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated…
CVE-2026-77070 — CVSS 9.8 (critical): n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate…
CVE-2026-41274 — CVSS 9.8 (critical): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node…
CVE-2026-40351 — CVSS 9.8 (critical): FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion…
CVE-2026-32248 — CVSS 9.8 (critical): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.12 and 8.6.38…
CVE-2026-29793 — CVSS 9.8 (critical): Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42…
CVE-2026-45689 — CVSS 9.1 (critical): Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5…
CVE-2026-45688 — CVSS 9.1 (critical): Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5…
CVE-2026-41328 — CVSS 9.1 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an…
CVE-2026-41327 — CVSS 9.1 (critical): Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gives an…
CVE-2026-76316 — CVSS 8.8 (high): In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.9, and 9.4.14, an unauthenticated user who can reach the Splunk management port…
CVE-2026-40352 — CVSS 8.8 (high): FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An…
CVE-2018-7829 — CVSS 8.8 (high): An Improper Neutralization of Special Elements in Query vulnerability exists in the 1st Gen. Pelco Sarix Enhanced Camera and Spectra…
CVE-2017-12904 — CVSS 8.8 (high): Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows…
CVE-2026-63637 — CVSS 8.6 (high): Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp…
CVE-2026-47835 — CVSS 8.6 (high): In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and…
CVE-2025-24787 — CVSS 8.6 (high): WhoDB is an open source database management tool. In affected versions the application is vulnerable to parameter injection in database…
CVE-2026-88036 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied…
CVE-2026-88034 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a…
CVE-2026-88033 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a…
CVE-2026-88030 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a…
CVE-2026-88029 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a…
CVE-2026-88025 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a…
CVE-2026-88024 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a…
CVE-2026-88023 — CVSS 8.3 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a…
CVE-2026-73618 — CVSS 8.3 (high): Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied…
CVE-2026-33980 — CVSS 8.3 (high): Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL queries and explore Azure…
CVE-2026-46591 — CVSS 8.2 (high): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer…
CVE-2026-88031 — CVSS 8.1 (high): Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a…
CVE-2026-81525 — CVSS 8.1 (high): The MongoDB client library for PHP does not sufficiently sanitize special elements in application-supplied namespace identifiers before…
CVE-2026-76331 — CVSS 8.1 (high): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could…
CVE-2025-60357 — CVSS 8.1 (high): AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.
CVE-2026-32247 — CVSS 8.1 (high): Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher…
CVE-2026-28211 — CVSS 7.8 (high): The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions…
CVE-2026-88022 — CVSS 7.7 (high): Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an…
CVE-2026-22558 — CVSS 7.7 (high): An Authenticated NoSQL Injection vulnerability found in UniFi Network Application could allow a malicious actor with authenticated access…
CVE-2026-76254 — CVSS 7.5 (high): In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to…
CVE-2026-44840 — CVSS 7.5 (high): Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in Dgraph is…
CVE-2026-30941 — CVSS 7.5 (high): Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1…
CVE-2026-62906 — CVSS 7.4 (high): Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose…
CVE-2026-10698 — CVSS 7.2 (high): Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This…
CVE-2026-88027 — CVSS 7.1 (high): Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for…
CVE-2026-73617 — CVSS 7.1 (high): Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are…
CVE-2026-53674 — CVSS 7.1 (high): BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility…
CVE-2026-42156: Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to…
CVE-2026-48121 — CVSS 6.7 (medium): @langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions…
CVE-2026-88028 — CVSS 6.5 (medium): Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel…
CVE-2026-88026 — CVSS 6.5 (medium): Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a…
CVE-2026-85167 — CVSS 6.5 (medium): n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud…