Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2025-52490
An issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passwords in …
Sync Gateway
3.2.6+
HIGH 7.6
CVE-2025-46619
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized acce…
Couchbase Server
7.2.7 / 7.6.4+
MEDIUM 6.5
CVE-2024-56178
An issue was discovered in Couchbase Server 7.6.x through 7.6.3. A user with the security_admin_local role can create a new user in a group that has …
Couchbase Server
after 7.6.3
MEDIUM 6.1
CVE-2024-25673
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP Host header injection.
Couchbase Server
7.2.6 / 7.6.2+
MEDIUM 5.9
CVE-2024-37034
An issue was discovered in Couchbase Server before 7.2.5 and 7.6.0 before 7.6.1. It does not ensure that credentials are negotiated with the Key-Valu…
Couchbase Server
7.2.5+
HIGH 7.5
CVE-2023-43768
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memo…
Couchbase Server
7.1.5+
HIGH 7.5
CVE-2024-23302
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
Couchbase Server
7.2.4+
HIGH 8.6
CVE-2023-50437
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with full admin on pools/default/serverGroups and engageClu…
Couchbase Server
7.2.4+
MEDIUM 5.3
CVE-2023-50436
An issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The earliest a…
Couchbase Server
7.2.4+
CRITICAL 9.8
CVE-2023-49930
An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted.
Couchbase Server
7.2.4+
CRITICAL 9.8
CVE-2023-49931
An issue was discovered in Couchbase Server before 7.2.4. SQL++ cURL calls to /diag/eval are not sufficiently restricted.
Couchbase Server
7.2.4+
MEDIUM 5.4
CVE-2023-49932
An issue was discovered in Couchbase Server before 7.2.4. An attacker can bypass SQL++ N1QL cURL host restrictions.
Couchbase Server
7.2.4+
MEDIUM 6.3
CVE-2023-43769
An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analy…
Couchbase Server
7.2.4+
HIGH 7.5
CVE-2023-49338
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of lo…
Couchbase Server
7.2.4+
MEDIUM 6.5
CVE-2023-45873
An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.
Couchbase Server
7.2.3+
HIGH 7.5
CVE-2023-36667
Couchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.
Couchbase Server
7.1.5+
HIGH 7.5
CVE-2023-45875
An issue was discovered in Couchbase Server 7.2.0. There is a private key leak in debug.log while adding a pre-7.0 node to a 7.2 cluster.
Couchbase Server
Mitigation only
MEDIUM 5.3
CVE-2023-28470
In Couchbase Server 5 through 7 before 7.1.4, the nsstats endpoint is accessible without authentication.
Couchbase Server
7.1.4+
HIGH 8.1
CVE-2022-42951
An issue was discovered in Couchbase Server 6.5.x and 6.6.x before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2. During the start-up of a Couchbas…
Couchbase Server
6.6.6 / 7.0.5+
HIGH 7.5
CVE-2023-25016
Couchbase Server before 6.6.6, 7.x before 7.0.5, and 7.1.x before 7.1.2 exposes Sensitive Information to an Unauthorized Actor.
Couchbase Server
6.6.6 / 7.0.5+
HIGH 7.5
CVE-2022-32556
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
Couchbase Server
7.1.1+
MEDIUM 5.9
CVE-2022-34826
In Couchbase Server 7.1.x before 7.1.1, an encrypted Private Key passphrase may be leaked in the logs.
Couchbase Server
Mitigation only
MEDIUM 5.3
CVE-2022-33911
An issue was discovered in Couchbase Server 7.x before 7.0.4. Field names are not redacted in logged validation messages for Analytics Service. An Un…
Couchbase Server
7.0.4+
HIGH 7.5
CVE-2022-33173
An algorithm-downgrade issue was discovered in Couchbase Server before 7.0.4. Analytics Remote Links may temporarily downgrade to non-TLS connection …
Couchbase Server
7.0.4+
CRITICAL 9.1
CVE-2022-32559
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
Couchbase Server
7.0.4+
HIGH 7.5
CVE-2022-32557
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
Couchbase Server
7.0.4+
HIGH 8.8
CVE-2022-32562
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
Couchbase Server
after 7.0.4
HIGH 7.5
CVE-2022-32192
Couchbase Server 5.x through 7.x before 7.0.4 exposes Sensitive Information to an Unauthorized Actor.
Couchbase Server
7.0.4+
HIGH 7.5
CVE-2022-32565
An issue was discovered in Couchbase Server before 7.0.4. The Backup Service log leaks unredacted usernames and document ids.
Couchbase Server
7.1.0+
HIGH 7.5
CVE-2022-32560
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
Couchbase Server
7.0.4+