Skip to content

Known CVE

Mongoose < 8.8.3 - Remote Code Execution

Mongoose before 8.8.3 can improperly use $where in match, leading to search injection.

CVE-2024-53900

Critical2024CVSS 9.1CWE-89

cve2024 · rce · mongoose · nosql · nodejs · oast · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website