couchbase kayıtları
couchbase üreticisine ait 71 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 3 · %4,2
- Silahlaştırılmış
- 4 · %5,6
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %14,1
- Yayından KEV’e ortanca
- 2 gün
Tekrar eden sınıflar
- CWE-532 Insertion of Sensitive Information into Log File6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-306 Missing Authentication for Critical Function4
- CWE-319 Cleartext Transmission of Sensitive Information4
- CWE-312 Cleartext Storage of Sensitive Information4
- CWE-276 Incorrect Default Permissions3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
71 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
77Bu hafta | CVE-2023-2033Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %40,8 | 14 Nis 2023 |
75Bu hafta | CVE-2023-3079Silahlaştırılmış | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a craftedgoogle · chrome · CWE-843 | Yüksek8,8 | KEV | %32,1 | 5 Haz 2023 |
66Bu hafta | CVE-2024-0519Silahlaştırılmış | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption google · chrome · CWE-787 | Yüksek8,8 | KEV | %3,8 | 16 Oca 2024 |
46Planlayın | CVE-2020-24719Silahlaştırılmış | Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.couchbase · couchbase server · CWE-78 | Kritik9,8 | — | %23,3 | 12 Kas 2020 |
40Planlayın | CVE-2020-9039Kavram kanıtı | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the procouchbase · couchbase server · CWE-276 | Kritik9,8 | — | %3,9 | 21 Şub 2020 |
40Planlayın | CVE-2019-9039İstismar yok | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements couchbase · sync gateway · CWE-89 | Kritik9,8 | — | %2,7 | 26 Haz 2019 |
40Planlayın | CVE-2019-11495İstismar yok | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.couchbase · couchbase server · CWE-335 | Kritik9,8 | — | %2,1 | 10 Eyl 2019 |
39İzleyin | CVE-2021-35943İstismar yok | Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.couchbase · couchbase server · CWE-287 | Kritik9,8 | — | %1,1 | 29 Eyl 2021 |
39İzleyin | CVE-2023-49930İstismar yok | An issue was discovered in Couchbase Server before 7.2.4.couchbase · couchbase server · CWE-284 | Kritik9,8 | — | %0,9 | 28 Şub 2024 |
39İzleyin | CVE-2023-49931İstismar yok | An issue was discovered in Couchbase Server before 7.2.4.couchbase · couchbase server · CWE-284 | Kritik9,8 | — | %0,9 | 28 Şub 2024 |
39İzleyin | CVE-2022-32563İstismar yok | An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.couchbase · sync gateway · CWE-295 | Kritik9,8 | — | %0,8 | 10 Haz 2022 |
36İzleyin | CVE-2018-15728İstismar yok | Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.couchbase · couchbase server · CWE-94 | Yüksek8,8 | — | %2,9 | 24 Ağu 2018 |
36İzleyin | CVE-2019-11496İstismar yok | In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without autcouchbase · couchbase server · CWE-306 | Kritik9,1 | — | %1,4 | 10 Eyl 2019 |
36İzleyin | CVE-2022-32559İstismar yok | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-770 | Kritik9,1 | — | %1,3 | 14 Haz 2022 |
35İzleyin | CVE-2022-32562İstismar yok | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-276 | Yüksek8,8 | — | %1,0 | 13 Haz 2022 |
35İzleyin | CVE-2020-9042İstismar yok | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to couchbase · couchbase server · CWE-352 | Yüksek8,8 | — | %0,6 | 8 Haz 2020 |
34İzleyin | CVE-2023-50437İstismar yok | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.couchbase · couchbase server · CWE-266 | Yüksek8,6 | — | %0,7 | 28 Şub 2024 |
32İzleyin | CVE-2022-42951İstismar yok | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.couchbase · couchbase server · CWE-287 | Yüksek8,1 | — | %0,7 | 6 Şub 2023 |
32İzleyin | CVE-2021-43963İstismar yok | An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.couchbase · sync gateway · CWE-200 | Yüksek8,1 | — | %0,5 | 7 Ara 2021 |
30İzleyin | CVE-2019-11467İstismar yok | In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.couchbase · couchbase server · CWE-119 | Yüksek7,5 | — | %1,3 | 10 Eyl 2019 |
30İzleyin | CVE-2020-9041İstismar yok | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints arecouchbase · couchbase server · CWE-404 | Yüksek7,5 | — | %1,3 | 8 Haz 2020 |
30İzleyin | CVE-2022-33173İstismar yok | An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server | Yüksek7,5 | — | %1,2 | 12 Tem 2022 |
30İzleyin | CVE-2022-32558İstismar yok | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server | Yüksek7,5 | — | %1,2 | 13 Haz 2022 |
30İzleyin | CVE-2022-26311İstismar yok | Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.couchbase · cloud native operator | Yüksek7,5 | — | %1,2 | 10 Mar 2022 |
30İzleyin | CVE-2022-32565İstismar yok | An issue was discovered in Couchbase Server before 7.0.4.couchbase · couchbase server · CWE-532 | Yüksek7,5 | — | %1,2 | 13 Haz 2022 |
- CVE-2023-203377Bu hafta
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %41google · chrome14 Nis 2023
- CVE-2023-307975Bu hafta
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %32google · chrome5 Haz 2023
- CVE-2024-051966Bu hafta
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %4google · chrome16 Oca 2024
- CVE-2020-2471946Planlayın
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack.
KritikCVSS 9,8SilahlaştırılmışEPSS %23couchbase · couchbase server12 Kas 2020
- CVE-2020-903940Planlayın
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the pro
KritikCVSS 9,8Kavram kanıtıEPSS %4couchbase · couchbase server21 Şub 2020
- CVE-2019-903940Planlayın
In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements
KritikCVSS 9,8İstismar yokEPSS %3couchbase · sync gateway26 Haz 2019
- CVE-2019-1149540Planlayın
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely.
KritikCVSS 9,8İstismar yokEPSS %2couchbase · couchbase server10 Eyl 2019
- CVE-2021-3594339İzleyin
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control.
KritikCVSS 9,8İstismar yokEPSS %1couchbase · couchbase server29 Eyl 2021
- CVE-2023-4993039İzleyin
An issue was discovered in Couchbase Server before 7.2.4.
KritikCVSS 9,8İstismar yokEPSS %1couchbase · couchbase server28 Şub 2024
- CVE-2023-4993139İzleyin
An issue was discovered in Couchbase Server before 7.2.4.
KritikCVSS 9,8İstismar yokEPSS %1couchbase · couchbase server28 Şub 2024
- CVE-2022-3256339İzleyin
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2.
KritikCVSS 9,8İstismar yokEPSS %1couchbase · sync gateway10 Haz 2022
- CVE-2018-1572836İzleyin
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091.
YüksekCVSS 8,8İstismar yokEPSS %3couchbase · couchbase server24 Ağu 2018
- CVE-2019-1149636İzleyin
In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without aut
KritikCVSS 9,1İstismar yokEPSS %1couchbase · couchbase server10 Eyl 2019
- CVE-2022-3255936İzleyin
An issue was discovered in Couchbase Server before 7.0.4.
KritikCVSS 9,1İstismar yokEPSS %1couchbase · couchbase server14 Haz 2022
- CVE-2022-3256235İzleyin
An issue was discovered in Couchbase Server before 7.0.4.
YüksekCVSS 8,8İstismar yokEPSS %1couchbase · couchbase server13 Haz 2022
- CVE-2020-904235İzleyin
In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to
YüksekCVSS 8,8İstismar yokEPSS %1couchbase · couchbase server8 Haz 2020
- CVE-2023-5043734İzleyin
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4.
YüksekCVSS 8,6İstismar yokEPSS %1couchbase · couchbase server28 Şub 2024
- CVE-2022-4295132İzleyin
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2.
YüksekCVSS 8,1İstismar yokEPSS %1couchbase · couchbase server6 Şub 2023
- CVE-2021-4396332İzleyin
An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2.
YüksekCVSS 8,1İstismar yokEPSS %1couchbase · sync gateway7 Ara 2021
- CVE-2019-1146730İzleyin
In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson.
YüksekCVSS 7,5İstismar yokEPSS %1couchbase · couchbase server10 Eyl 2019
- CVE-2020-904130İzleyin
In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are
YüksekCVSS 7,5İstismar yokEPSS %1couchbase · couchbase server8 Haz 2020
- CVE-2022-3317330İzleyin
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4.
YüksekCVSS 7,5İstismar yokEPSS %1couchbase · couchbase server12 Tem 2022
- CVE-2022-3255830İzleyin
An issue was discovered in Couchbase Server before 7.0.4.
YüksekCVSS 7,5İstismar yokEPSS %1couchbase · couchbase server13 Haz 2022
- CVE-2022-2631130İzleyin
Couchbase Operator 2.2.x before 2.2.3 exposes Sensitive Information to an Unauthorized Actor.
YüksekCVSS 7,5İstismar yokEPSS %1couchbase · cloud native operator10 Mar 2022
- CVE-2022-3256530İzleyin
An issue was discovered in Couchbase Server before 7.0.4.
YüksekCVSS 7,5İstismar yokEPSS %1couchbase · couchbase server13 Haz 2022