Vulnerability index

Browse CVEs

59 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sync Gateway HIGH 7.3
CVE-2025-52490

An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in …

Fix: 3.2.6+
Fix from $1,950 2025-07-29
Couchbase Server HIGH 7.6
CVE-2025-46619

A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized acce…

Fix: 7.2.7 / 7.6.4+
Fix from $1,950 2025-04-30
Couchbase Server MEDIUM 6.5
CVE-2024-56178

An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has …

Fix: after 7.6.3
Fix from $1,600 2025-01-27
Couchbase Server MEDIUM 6.1
CVE-2024-25673

Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.

Fix: 7.2.6 / 7.6.2+
Fix from $1,600 2024-09-19
Couchbase Server MEDIUM 5.9
CVE-2024-37034

An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Valu…

Fix: 7.2.5+
Fix from $1,600 2024-07-26
Couchbase Server HIGH 7.5
CVE-2023-43768

An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memo…

Fix: 7.1.5+
Fix from $1,950 2024-03-27
Couchbase Server HIGH 7.5
CVE-2024-23302

Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.

Fix: 7.2.4+
Fix from $1,950 2024-02-29
Couchbase Server HIGH 8.6
CVE-2023-50437

An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageClu…

Fix: 7.2.4+
Fix from $1,950 2024-02-29
Couchbase Server MEDIUM 5.3
CVE-2023-50436

An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest a…

Fix: 7.2.4+
Fix from $1,600 2024-02-29
Couchbase Server CRITICAL 9.8
CVE-2023-49930

An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.

Fix: 7.2.4+
Fix from $2,300 2024-02-29
Couchbase Server CRITICAL 9.8
CVE-2023-49931

An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.

Fix: 7.2.4+
Fix from $2,300 2024-02-29
Couchbase Server MEDIUM 5.4
CVE-2023-49932

An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.

Fix: 7.2.4+
Fix from $1,600 2024-02-29
Couchbase Server MEDIUM 6.3
CVE-2023-43769

An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analy…

Fix: 7.2.4+
Fix from $1,600 2024-02-29
Couchbase Server HIGH 7.5
CVE-2023-49338

Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of lo…

Fix: 7.2.4+
Fix from $1,950 2024-02-28
Couchbase Server MEDIUM 6.5
CVE-2023-45873

An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.

Fix: 7.2.3+
Fix from $1,600 2024-02-28
Couchbase Server HIGH 7.5
CVE-2023-36667

Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.

Fix: 7.1.5+
Fix from $1,950 2023-11-08
Couchbase Server HIGH 7.5
CVE-2023-45875

An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.

Mitigation only
Fix from $1,950 2023-11-08
Couchbase Server MEDIUM 5.3
CVE-2023-28470

In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.

Fix: 7.1.4+
Fix from $1,600 2023-03-23
Couchbase Server HIGH 8.1
CVE-2022-42951

An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbas…

Fix: 6.6.6 / 7.0.5+
Fix from $1,950 2023-02-06
Couchbase Server HIGH 7.5
CVE-2023-25016

Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.

Fix: 6.6.6 / 7.0.5+
Fix from $1,950 2023-02-06
Couchbase Server HIGH 7.5
CVE-2022-32556

An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.

Fix: 7.1.1+
Fix from $1,950 2022-07-21
Couchbase Server MEDIUM 5.9
CVE-2022-34826

In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.

Mitigation only
Fix from $1,600 2022-07-15
Couchbase Server MEDIUM 5.3
CVE-2022-33911

An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Un…

Fix: 7.0.4+
Fix from $1,600 2022-07-12
Couchbase Server HIGH 7.5
CVE-2022-33173

An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection …

Fix: 7.0.4+
Fix from $1,950 2022-07-12
Couchbase Server CRITICAL 9.1
CVE-2022-32559

An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.

Fix: 7.0.4+
Fix from $2,300 2022-06-14
Couchbase Server HIGH 7.5
CVE-2022-32557

An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.

Fix: 7.0.4+
Fix from $1,950 2022-06-14
Couchbase Server HIGH 8.8
CVE-2022-32562

An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.

Fix: after 7.0.4
Fix from $1,950 2022-06-13
Couchbase Server HIGH 7.5
CVE-2022-32192

Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.

Fix: 7.0.4+
Fix from $1,950 2022-06-13
Couchbase Server HIGH 7.5
CVE-2022-32565

An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.

Fix: 7.1.0+
Fix from $1,950 2022-06-13
Couchbase Server HIGH 7.5
CVE-2022-32560

An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.

Fix: 7.0.4+
Fix from $1,950 2022-06-13