couchbase records
71 published records for vendor couchbase.
Researcher profile
- Entered KEV
- 3 · 4.2%
- Weaponized
- 4 · 5.6%
- Pre-auth RCE
- 1
- With a fix record
- 14.1%
- Median publish → KEV
- 2 days
Recurring classes
- CWE-532 Insertion of Sensitive Information into Log File6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-306 Missing Authentication for Critical Function4
- CWE-319 Cleartext Transmission of Sensitive Information4
- CWE-312 Cleartext Storage of Sensitive Information4
- CWE-276 Incorrect Default Permissions3
The weakness classes this vendor ships most often: where to look.
CWEAll records
71 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
77This week | CVE-2023-2033Weaponized | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | High8.8 | KEV | 40.8% | Apr 14, 2023 |
75This week | CVE-2023-3079Weaponized | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | High8.8 | KEV | 32.1% | Jun 5, 2023 |
66This week | CVE-2024-0519Weaponized | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption google · chrome · CWE-787 | High8.8 | KEV | 3.8% | Jan 16, 2024 |
46Plan | CVE-2020-24719Weaponized | Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.couchbase · couchbase server · CWE-78 | Critical9.8 | — | 23.3% | Nov 12, 2020 |
40Plan | CVE-2020-9039Proof of concept | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the procouchbase · couchbase server · CWE-276 | Critical9.8 | — | 3.9% | Feb 21, 2020 |
40Plan | CVE-2019-9039No exploit | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements couchbase · sync gateway · CWE-89 | Critical9.8 | — | 2.7% | Jun 26, 2019 |
40Plan | CVE-2019-11495No exploit | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.couchbase · couchbase server · CWE-335 | Critical9.8 | — | 2.1% | Sep 10, 2019 |
39Monitor | CVE-2021-35943No exploit | Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.couchbase · couchbase server · CWE-287 | Critical9.8 | — | 1.1% | Sep 29, 2021 |
39Monitor | CVE-2023-49930No exploit | An issue was discovered in Couchbase Server before 7.2.4.couchbase · couchbase server · CWE-284 | Critical9.8 | — | 0.9% | Feb 28, 2024 |
39Monitor | CVE-2023-49931No exploit | An issue was discovered in Couchbase Server before 7.2.4.couchbase · couchbase server · CWE-284 | Critical9.8 | — | 0.9% | Feb 28, 2024 |
39Monitor | CVE-2022-32563No exploit | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.couchbase · sync gateway · CWE-295 | Critical9.8 | — | 0.8% | Jun 10, 2022 |
36Monitor | CVE-2018-15728No exploit | Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.couchbase · couchbase server · CWE-94 | High8.8 | — | 2.9% | Aug 24, 2018 |
36Monitor | CVE-2019-11496No exploit | In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without autcouchbase · couchbase server · CWE-306 | Critical9.1 | — | 1.4% | Sep 10, 2019 |
36Monitor | CVE-2022-32559No exploit | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-770 | Critical9.1 | — | 1.3% | Jun 14, 2022 |
35Monitor | CVE-2022-32562No exploit | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-276 | High8.8 | — | 1.0% | Jun 13, 2022 |
35Monitor | CVE-2020-9042No exploit | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to couchbase · couchbase server · CWE-352 | High8.8 | — | 0.6% | Jun 8, 2020 |
34Monitor | CVE-2023-50437No exploit | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.couchbase · couchbase server · CWE-266 | High8.6 | — | 0.7% | Feb 28, 2024 |
32Monitor | CVE-2022-42951No exploit | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.couchbase · couchbase server · CWE-287 | High8.1 | — | 0.7% | Feb 6, 2023 |
32Monitor | CVE-2021-43963No exploit | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.couchbase · sync gateway · CWE-200 | High8.1 | — | 0.5% | Dec 7, 2021 |
30Monitor | CVE-2019-11467No exploit | In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.couchbase · couchbase server · CWE-119 | High7.5 | — | 1.3% | Sep 10, 2019 |
30Monitor | CVE-2020-9041No exploit | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints arecouchbase · couchbase server · CWE-404 | High7.5 | — | 1.3% | Jun 8, 2020 |
30Monitor | CVE-2022-33173No exploit | An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server | High7.5 | — | 1.2% | Jul 12, 2022 |
30Monitor | CVE-2022-32558No exploit | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server | High7.5 | — | 1.2% | Jun 13, 2022 |
30Monitor | CVE-2022-26311No exploit | Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.couchbase · cloud native operator | High7.5 | — | 1.2% | Mar 10, 2022 |
30Monitor | CVE-2022-32565No exploit | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-532 | High7.5 | — | 1.2% | Jun 13, 2022 |
- CVE-2023-203377This week
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 41%google · chromeApr 14, 2023
- CVE-2023-307975This week
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted
HighCVSS 8.8KEVWeaponizedEPSS 32%google · chromeJun 5, 2023
- CVE-2024-051966This week
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption
HighCVSS 8.8KEVWeaponizedEPSS 4%google · chromeJan 16, 2024
- CVE-2020-2471946Plan
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.
CriticalCVSS 9.8WeaponizedEPSS 23%couchbase · couchbase serverNov 12, 2020
- CVE-2020-903940Plan
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro
CriticalCVSS 9.8Proof of conceptEPSS 4%couchbase · couchbase serverFeb 21, 2020
- CVE-2019-903940Plan
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements
CriticalCVSS 9.8No exploitEPSS 3%couchbase · sync gatewayJun 26, 2019
- CVE-2019-1149540Plan
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.
CriticalCVSS 9.8No exploitEPSS 2%couchbase · couchbase serverSep 10, 2019
- CVE-2021-3594339Monitor
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.
CriticalCVSS 9.8No exploitEPSS 1%couchbase · couchbase serverSep 29, 2021
- CVE-2023-4993039Monitor
An issue was discovered in Couchbase Server before 7.2.4.
CriticalCVSS 9.8No exploitEPSS 1%couchbase · couchbase serverFeb 28, 2024
- CVE-2023-4993139Monitor
An issue was discovered in Couchbase Server before 7.2.4.
CriticalCVSS 9.8No exploitEPSS 1%couchbase · couchbase serverFeb 28, 2024
- CVE-2022-3256339Monitor
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.
CriticalCVSS 9.8No exploitEPSS 1%couchbase · sync gatewayJun 10, 2022
- CVE-2018-1572836Monitor
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.
HighCVSS 8.8No exploitEPSS 3%couchbase · couchbase serverAug 24, 2018
- CVE-2019-1149636Monitor
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without aut
CriticalCVSS 9.1No exploitEPSS 1%couchbase · couchbase serverSep 10, 2019
- CVE-2022-3255936Monitor
An issue was discovered in Couchbase Server before 7.0.4.
CriticalCVSS 9.1No exploitEPSS 1%couchbase · couchbase serverJun 14, 2022
- CVE-2022-3256235Monitor
An issue was discovered in Couchbase Server before 7.0.4.
HighCVSS 8.8No exploitEPSS 1%couchbase · couchbase serverJun 13, 2022
- CVE-2020-904235Monitor
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to
HighCVSS 8.8No exploitEPSS 1%couchbase · couchbase serverJun 8, 2020
- CVE-2023-5043734Monitor
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.
HighCVSS 8.6No exploitEPSS 1%couchbase · couchbase serverFeb 28, 2024
- CVE-2022-4295132Monitor
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.
HighCVSS 8.1No exploitEPSS 1%couchbase · couchbase serverFeb 6, 2023
- CVE-2021-4396332Monitor
An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.
HighCVSS 8.1No exploitEPSS 1%couchbase · sync gatewayDec 7, 2021
- CVE-2019-1146730Monitor
In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.
HighCVSS 7.5No exploitEPSS 1%couchbase · couchbase serverSep 10, 2019
- CVE-2020-904130Monitor
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are
HighCVSS 7.5No exploitEPSS 1%couchbase · couchbase serverJun 8, 2020
- CVE-2022-3317330Monitor
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.
HighCVSS 7.5No exploitEPSS 1%couchbase · couchbase serverJul 12, 2022
- CVE-2022-3255830Monitor
An issue was discovered in Couchbase Server before 7.0.4.
HighCVSS 7.5No exploitEPSS 1%couchbase · couchbase serverJun 13, 2022
- CVE-2022-2631130Monitor
Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.
HighCVSS 7.5No exploitEPSS 1%couchbase · cloud native operatorMar 10, 2022
- CVE-2022-3256530Monitor
An issue was discovered in Couchbase Server before 7.0.4.
HighCVSS 7.5No exploitEPSS 1%couchbase · couchbase serverJun 13, 2022