Skip to content
Noroxi

couchbase records

71 published records for vendor couchbase.

All records

71 records
  • CVE-2023-2033
    77This week

    Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 41%

    google · chromeApr 14, 2023

  • CVE-2023-3079
    75This week

    Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 32%

    google · chromeJun 5, 2023

  • CVE-2024-0519
    66This week

    Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption

    HighCVSS 8.8KEVWeaponizedEPSS 4%

    google · chromeJan 16, 2024

  • Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.

    CriticalCVSS 9.8WeaponizedEPSS 23%

    couchbase · couchbase serverNov 12, 2020

  • Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    couchbase · couchbase serverFeb 21, 2020

  • In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements

    CriticalCVSS 9.8No exploitEPSS 3%

    couchbase · sync gatewayJun 26, 2019

  • In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.

    CriticalCVSS 9.8No exploitEPSS 2%

    couchbase · couchbase serverSep 10, 2019

  • Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.

    CriticalCVSS 9.8No exploitEPSS 1%

    couchbase · couchbase serverSep 29, 2021

  • An issue was discovered in Couchbase Server before 7.2.4.

    CriticalCVSS 9.8No exploitEPSS 1%

    couchbase · couchbase serverFeb 28, 2024

  • An issue was discovered in Couchbase Server before 7.2.4.

    CriticalCVSS 9.8No exploitEPSS 1%

    couchbase · couchbase serverFeb 28, 2024

  • An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.

    CriticalCVSS 9.8No exploitEPSS 1%

    couchbase · sync gatewayJun 10, 2022

  • Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.

    HighCVSS 8.8No exploitEPSS 3%

    couchbase · couchbase serverAug 24, 2018

  • In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without aut

    CriticalCVSS 9.1No exploitEPSS 1%

    couchbase · couchbase serverSep 10, 2019

  • An issue was discovered in Couchbase Server before 7.0.4.

    CriticalCVSS 9.1No exploitEPSS 1%

    couchbase · couchbase serverJun 14, 2022

  • An issue was discovered in Couchbase Server before 7.0.4.

    HighCVSS 8.8No exploitEPSS 1%

    couchbase · couchbase serverJun 13, 2022

  • CVE-2020-9042
    35Monitor

    In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to

    HighCVSS 8.8No exploitEPSS 1%

    couchbase · couchbase serverJun 8, 2020

  • An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.

    HighCVSS 8.6No exploitEPSS 1%

    couchbase · couchbase serverFeb 28, 2024

  • An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.

    HighCVSS 8.1No exploitEPSS 1%

    couchbase · couchbase serverFeb 6, 2023

  • An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.

    HighCVSS 8.1No exploitEPSS 1%

    couchbase · sync gatewayDec 7, 2021

  • In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.

    HighCVSS 7.5No exploitEPSS 1%

    couchbase · couchbase serverSep 10, 2019

  • CVE-2020-9041
    30Monitor

    In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are

    HighCVSS 7.5No exploitEPSS 1%

    couchbase · couchbase serverJun 8, 2020

  • An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.

    HighCVSS 7.5No exploitEPSS 1%

    couchbase · couchbase serverJul 12, 2022

  • An issue was discovered in Couchbase Server before 7.0.4.

    HighCVSS 7.5No exploitEPSS 1%

    couchbase · couchbase serverJun 13, 2022

  • Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.

    HighCVSS 7.5No exploitEPSS 1%

    couchbase · cloud native operatorMar 10, 2022

  • An issue was discovered in Couchbase Server before 7.0.4.

    HighCVSS 7.5No exploitEPSS 1%

    couchbase · couchbase serverJun 13, 2022