Couchbase / Couchbase Server
63 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-46619 | A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sens… | HIGH | 7.6 | Apr 30, 2025 |
| CVE-2024-56178 | An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has the admin… | MEDIUM | 6.5 | Jan 27, 2025 |
| CVE-2024-25673 | Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. | MEDIUM | 6.1 | Sep 19, 2024 |
| CVE-2024-37034 | An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Value (KV) ser… | MEDIUM | 5.9 | Jul 26, 2024 |
| CVE-2023-43768 | An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via lar… | HIGH | 7.5 | Mar 27, 2024 |
| CVE-2024-23302 | Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. | HIGH | 7.5 | Feb 28, 2024 |
| CVE-2023-50437 | An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageCluster2. | HIGH | 8.6 | Feb 28, 2024 |
| CVE-2023-50436 | An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest affected ve… | MEDIUM | 5.3 | Feb 28, 2024 |
| CVE-2023-49932 | An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions. | MEDIUM | 5.4 | Feb 28, 2024 |
| CVE-2023-49931 | An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted. | CRITICAL | 9.8 | Feb 28, 2024 |
| CVE-2023-49930 | An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. | CRITICAL | 9.8 | Feb 28, 2024 |
| CVE-2023-49338 | Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost. | HIGH | 7.5 | Feb 28, 2024 |
| CVE-2023-45874 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (outage of reader threads). | MEDIUM | 4.3 | Feb 28, 2024 |
| CVE-2023-45873 | An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer. | MEDIUM | 6.5 | Feb 28, 2024 |
| CVE-2023-43769 | An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics. | MEDIUM | 6.3 | Feb 28, 2024 |
| CVE-2023-50782 | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659 | HIGH | 8.7 | Feb 5, 2024 |
| CVE-2024-0519 KEV | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML… | HIGH | 8.8 | Jan 16, 2024 |
| CVE-2023-45875 | An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster. | HIGH | 7.5 | Nov 8, 2023 |
| CVE-2023-36667 | Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal. | HIGH | 7.5 | Nov 8, 2023 |
| CVE-2023-3079 KEV | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… | HIGH | 8.8 | Jun 5, 2023 |
| CVE-2023-2033 KEV | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… | HIGH | 8.8 | Apr 14, 2023 |
| CVE-2023-28470 | In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. | MEDIUM | 5.3 | Mar 23, 2023 |
| CVE-2023-25016 | Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor. | HIGH | 7.5 | Feb 6, 2023 |
| CVE-2022-42951 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbase Server n… | HIGH | 8.1 | Feb 6, 2023 |
| CVE-2022-42950 | An issue was discovered in Couchbase Server 7.x before 7.0.5 and 7.1.x before 7.1.2. A crafted HTTP REST request from an administrator account to the Couchbase… | MEDIUM | 4.9 | Feb 6, 2023 |
Showing 1 to 25 of 63 CVEs