mongo-express vendor intelligence

mongo-express Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting mongo-express products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
1
Known exploited vulnerabilities affecting mongo-express products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
mongo-express KEVs with sensor-observed exploitation activity

The catalog gap matters for mongo-express exposure

All one exploited mongo-express CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.

100%
Covered by CISA
0%
Beyond CISA
1
Product families

Attested mongo-express CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2019-10758

mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to...

mongo-express Confirmed In CISA 10 Dec 2021

Showing 1 of 1 mongo-express known exploited vulnerabilities.

Recurring weakness patterns

Control account for one mapped occurrence across this mongo-express KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.