Записи couchbase
71 опубликованных записей вендора couchbase.
Профиль для исследователя
- Попали в KEV
- 3 · 4,2 %
- С эксплойтом
- 4 · 5,6 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 14,1 %
- Медиана: публикация → KEV
- 2 дн.
Повторяющиеся классы
- CWE-532 Insertion of Sensitive Information into Log File6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-306 Missing Authentication for Critical Function4
- CWE-319 Cleartext Transmission of Sensitive Information4
- CWE-312 Cleartext Storage of Sensitive Information4
- CWE-276 Incorrect Default Permissions3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
71 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
77На этой неделе | CVE-2023-2033Готовый эксплойт | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Высокая8,8 | KEV | 40,8 % | 14 апр. 2023 г. |
75На этой неделе | CVE-2023-3079Готовый эксплойт | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Высокая8,8 | KEV | 32,1 % | 5 июн. 2023 г. |
66На этой неделе | CVE-2024-0519Готовый эксплойт | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption google · chrome · CWE-787 | Высокая8,8 | KEV | 3,8 % | 16 янв. 2024 г. |
46В плане | CVE-2020-24719Готовый эксплойт | Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.couchbase · couchbase server · CWE-78 | Критическая9,8 | — | 23,3 % | 12 нояб. 2020 г. |
40В плане | CVE-2020-9039Proof of concept | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the procouchbase · couchbase server · CWE-276 | Критическая9,8 | — | 3,9 % | 21 февр. 2020 г. |
40В плане | CVE-2019-9039Эксплойта нет | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements couchbase · sync gateway · CWE-89 | Критическая9,8 | — | 2,7 % | 26 июн. 2019 г. |
40В плане | CVE-2019-11495Эксплойта нет | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.couchbase · couchbase server · CWE-335 | Критическая9,8 | — | 2,1 % | 10 сент. 2019 г. |
39Наблюдать | CVE-2021-35943Эксплойта нет | Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.couchbase · couchbase server · CWE-287 | Критическая9,8 | — | 1,1 % | 29 сент. 2021 г. |
39Наблюдать | CVE-2023-49930Эксплойта нет | An issue was discovered in Couchbase Server before 7.2.4.couchbase · couchbase server · CWE-284 | Критическая9,8 | — | 0,9 % | 28 февр. 2024 г. |
39Наблюдать | CVE-2023-49931Эксплойта нет | An issue was discovered in Couchbase Server before 7.2.4.couchbase · couchbase server · CWE-284 | Критическая9,8 | — | 0,9 % | 28 февр. 2024 г. |
39Наблюдать | CVE-2022-32563Эксплойта нет | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.couchbase · sync gateway · CWE-295 | Критическая9,8 | — | 0,8 % | 10 июн. 2022 г. |
36Наблюдать | CVE-2018-15728Эксплойта нет | Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.couchbase · couchbase server · CWE-94 | Высокая8,8 | — | 2,9 % | 24 авг. 2018 г. |
36Наблюдать | CVE-2019-11496Эксплойта нет | In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without autcouchbase · couchbase server · CWE-306 | Критическая9,1 | — | 1,4 % | 10 сент. 2019 г. |
36Наблюдать | CVE-2022-32559Эксплойта нет | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-770 | Критическая9,1 | — | 1,3 % | 14 июн. 2022 г. |
35Наблюдать | CVE-2022-32562Эксплойта нет | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-276 | Высокая8,8 | — | 1,0 % | 13 июн. 2022 г. |
35Наблюдать | CVE-2020-9042Эксплойта нет | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to couchbase · couchbase server · CWE-352 | Высокая8,8 | — | 0,6 % | 8 июн. 2020 г. |
34Наблюдать | CVE-2023-50437Эксплойта нет | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.couchbase · couchbase server · CWE-266 | Высокая8,6 | — | 0,7 % | 28 февр. 2024 г. |
32Наблюдать | CVE-2022-42951Эксплойта нет | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.couchbase · couchbase server · CWE-287 | Высокая8,1 | — | 0,7 % | 6 февр. 2023 г. |
32Наблюдать | CVE-2021-43963Эксплойта нет | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.couchbase · sync gateway · CWE-200 | Высокая8,1 | — | 0,5 % | 7 дек. 2021 г. |
30Наблюдать | CVE-2019-11467Эксплойта нет | In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.couchbase · couchbase server · CWE-119 | Высокая7,5 | — | 1,3 % | 10 сент. 2019 г. |
30Наблюдать | CVE-2020-9041Эксплойта нет | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints arecouchbase · couchbase server · CWE-404 | Высокая7,5 | — | 1,3 % | 8 июн. 2020 г. |
30Наблюдать | CVE-2022-33173Эксплойта нет | An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server | Высокая7,5 | — | 1,2 % | 12 июл. 2022 г. |
30Наблюдать | CVE-2022-32558Эксплойта нет | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server | Высокая7,5 | — | 1,2 % | 13 июн. 2022 г. |
30Наблюдать | CVE-2022-26311Эксплойта нет | Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.couchbase · cloud native operator | Высокая7,5 | — | 1,2 % | 10 мар. 2022 г. |
30Наблюдать | CVE-2022-32565Эксплойта нет | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-532 | Высокая7,5 | — | 1,2 % | 13 июн. 2022 г. |
- CVE-2023-203377На этой неделе
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 41 %google · chrome14 апр. 2023 г.
- CVE-2023-307975На этой неделе
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 32 %google · chrome5 июн. 2023 г.
- CVE-2024-051966На этой неделе
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 4 %google · chrome16 янв. 2024 г.
- CVE-2020-2471946В плане
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.
КритическаяCVSS 9,8Готовый эксплойтEPSS 23 %couchbase · couchbase server12 нояб. 2020 г.
- CVE-2020-903940В плане
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro
КритическаяCVSS 9,8Proof of conceptEPSS 4 %couchbase · couchbase server21 февр. 2020 г.
- CVE-2019-903940В плане
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %couchbase · sync gateway26 июн. 2019 г.
- CVE-2019-1149540В плане
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %couchbase · couchbase server10 сент. 2019 г.
- CVE-2021-3594339Наблюдать
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %couchbase · couchbase server29 сент. 2021 г.
- CVE-2023-4993039Наблюдать
An issue was discovered in Couchbase Server before 7.2.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %couchbase · couchbase server28 февр. 2024 г.
- CVE-2023-4993139Наблюдать
An issue was discovered in Couchbase Server before 7.2.4.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %couchbase · couchbase server28 февр. 2024 г.
- CVE-2022-3256339Наблюдать
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %couchbase · sync gateway10 июн. 2022 г.
- CVE-2018-1572836Наблюдать
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %couchbase · couchbase server24 авг. 2018 г.
- CVE-2019-1149636Наблюдать
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without aut
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %couchbase · couchbase server10 сент. 2019 г.
- CVE-2022-3255936Наблюдать
An issue was discovered in Couchbase Server before 7.0.4.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %couchbase · couchbase server14 июн. 2022 г.
- CVE-2022-3256235Наблюдать
An issue was discovered in Couchbase Server before 7.0.4.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %couchbase · couchbase server13 июн. 2022 г.
- CVE-2020-904235Наблюдать
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %couchbase · couchbase server8 июн. 2020 г.
- CVE-2023-5043734Наблюдать
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %couchbase · couchbase server28 февр. 2024 г.
- CVE-2022-4295132Наблюдать
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %couchbase · couchbase server6 февр. 2023 г.
- CVE-2021-4396332Наблюдать
An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %couchbase · sync gateway7 дек. 2021 г.
- CVE-2019-1146730Наблюдать
In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %couchbase · couchbase server10 сент. 2019 г.
- CVE-2020-904130Наблюдать
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %couchbase · couchbase server8 июн. 2020 г.
- CVE-2022-3317330Наблюдать
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %couchbase · couchbase server12 июл. 2022 г.
- CVE-2022-3255830Наблюдать
An issue was discovered in Couchbase Server before 7.0.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %couchbase · couchbase server13 июн. 2022 г.
- CVE-2022-2631130Наблюдать
Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %couchbase · cloud native operator10 мар. 2022 г.
- CVE-2022-3256530Наблюдать
An issue was discovered in Couchbase Server before 7.0.4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %couchbase · couchbase server13 июн. 2022 г.