Vulnerability index

Browse CVEs

59 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2025-52490 An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in … Sync Gateway 3.2.6+ Fix from $1,9502025-07-29 HIGH 7.6 CVE-2025-46619 A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized acce… Couchbase Server 7.2.7 / 7.6.4+ Fix from $1,9502025-04-30 MEDIUM 6.5 CVE-2024-56178 An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has … Couchbase Server after 7.6.3 Fix from $1,6002025-01-27 MEDIUM 6.1 CVE-2024-25673 Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection. Couchbase Server 7.2.6 / 7.6.2+ Fix from $1,6002024-09-19 MEDIUM 5.9 CVE-2024-37034 An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Valu… Couchbase Server 7.2.5+ Fix from $1,6002024-07-26 HIGH 7.5 CVE-2023-43768 An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memo… Couchbase Server 7.1.5+ Fix from $1,9502024-03-27 HIGH 7.5 CVE-2024-23302 Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. Couchbase Server 7.2.4+ Fix from $1,9502024-02-29 HIGH 8.6 CVE-2023-50437 An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageClu… Couchbase Server 7.2.4+ Fix from $1,9502024-02-29 MEDIUM 5.3 CVE-2023-50436 An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest a… Couchbase Server 7.2.4+ Fix from $1,6002024-02-29 CRITICAL 9.8 CVE-2023-49930 An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. Couchbase Server 7.2.4+ Fix from $2,3002024-02-29 CRITICAL 9.8 CVE-2023-49931 An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted. Couchbase Server 7.2.4+ Fix from $2,3002024-02-29 MEDIUM 5.4 CVE-2023-49932 An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions. Couchbase Server 7.2.4+ Fix from $1,6002024-02-29 MEDIUM 6.3 CVE-2023-43769 An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analy… Couchbase Server 7.2.4+ Fix from $1,6002024-02-29 HIGH 7.5 CVE-2023-49338 Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of lo… Couchbase Server 7.2.4+ Fix from $1,9502024-02-28 MEDIUM 6.5 CVE-2023-45873 An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer. Couchbase Server 7.2.3+ Fix from $1,6002024-02-28 HIGH 7.5 CVE-2023-36667 Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal. Couchbase Server 7.1.5+ Fix from $1,9502023-11-08 HIGH 7.5 CVE-2023-45875 An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster. Couchbase Server Mitigation only Fix from $1,9502023-11-08 MEDIUM 5.3 CVE-2023-28470 In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication. Couchbase Server 7.1.4+ Fix from $1,6002023-03-23 HIGH 8.1 CVE-2022-42951 An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbas… Couchbase Server 6.6.6 / 7.0.5+ Fix from $1,9502023-02-06 HIGH 7.5 CVE-2023-25016 Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor. Couchbase Server 6.6.6 / 7.0.5+ Fix from $1,9502023-02-06 HIGH 7.5 CVE-2022-32556 An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes. Couchbase Server 7.1.1+ Fix from $1,9502022-07-21 MEDIUM 5.9 CVE-2022-34826 In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs. Couchbase Server Mitigation only Fix from $1,6002022-07-15 MEDIUM 5.3 CVE-2022-33911 An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Un… Couchbase Server 7.0.4+ Fix from $1,6002022-07-12 HIGH 7.5 CVE-2022-33173 An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection … Couchbase Server 7.0.4+ Fix from $1,9502022-07-12 CRITICAL 9.1 CVE-2022-32559 An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. Couchbase Server 7.0.4+ Fix from $2,3002022-06-14 HIGH 7.5 CVE-2022-32557 An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers. Couchbase Server 7.0.4+ Fix from $1,9502022-06-14 HIGH 8.8 CVE-2022-32562 An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission. Couchbase Server after 7.0.4 Fix from $1,9502022-06-13 HIGH 7.5 CVE-2022-32192 Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor. Couchbase Server 7.0.4+ Fix from $1,9502022-06-13 HIGH 7.5 CVE-2022-32565 An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids. Couchbase Server 7.1.0+ Fix from $1,9502022-06-13 HIGH 7.5 CVE-2022-32560 An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings. Couchbase Server 7.0.4+ Fix from $1,9502022-06-13