Skip to content

Known CVE

mongo-express Remote Code Execution

mongo-express before 0.54.0 is vulnerable to remote code execution via endpoints that uses the `toBSON` method and misuse the `vm` dependency to perform `exec` commands in a non-safe environment.

CVE-2019-10758

Critical2019CVSS 9.9

cve2019 · vulhub · mongo · mongo-express · kev · mongo-express_project · node.js · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website