Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Couchbase

First CVE: Aug 24, 2018Active for: 8 yearsTotal CVEs: 71
58.6
VTI Score
TOP TARGET

Couchbase develops a narrowly scoped portfolio centered on its distributed NoSQL database platform and related server, synchronization, and SDK components that serve as datastores and backend infrastructure for applications requiring high availability and scalability. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the sensitivity of database-layer flaws and credential-handling issues in infrastructure software. The exposure recurs across products including Couchbase Server, Sync Gateway, and language SDKs, and is characterized by a durable pattern of authentication, logging, and data-protection weaknesses such as missing authentication for critical functions, cleartext storage and transmission of sensitive information, and inadvertent sensitive-data logging—issues that compound the risk when a database layer is compromised. Defenders should treat database-layer updates from this vendor as high-priority and audit access controls and credential storage in dependent applications; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
71
Total CVEs
More Total CVEs than 99% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
4.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Couchbase over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2018
7 years ago
Most Recent CVE
Jul 29, 2025
360 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (71 CVEs).

71 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-2033HIGH
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:
Apr 14, 20238.884YESNO
CVE-2023-3079HIGH
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:
Jun 5, 20238.881YESNO
CVE-2024-0519HIGH
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur
Jan 16, 20248.869YESNO
CVE-2020-24719CRITICAL
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are
Nov 12, 20209.853NOYES
CVE-2020-9039CRITICAL
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they
Feb 22, 20209.844NOYES
CVE-2022-32563CRITICAL
An issue was discovered in Couchbase Sync Gateway 3.x before 3.0.2. Admin credentials are not verified when using X.509 client-certificate authentication from Sync Gateway to Couch
Jun 10, 20229.831NONO
CVE-2021-35943CRITICAL
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
Sep 29, 20219.830NONO
CVE-2019-11495CRITICAL
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small sea
Sep 10, 20199.830NONO
CVE-2018-15728HIGH
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send a
Aug 24, 20188.829NONO
CVE-2022-32559CRITICAL
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
Jun 14, 20229.127NONO
View all 71 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products71 CVEs
35%
51%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (4.2%)
Network67 (94.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.4%)
Attack Complexity
Low66 (93.0%)
High5 (7.0%)
Unknown0 (0.0%)
User Interaction
None64 (90.1%)
Unknown0 (0.0%)
Required7 (9.9%)
Privileges Required
Low10 (14.1%)
High8 (11.3%)
None53 (74.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (71 CVEs).

CISA KEV
3 CVEs
4.2% of CVEs· 99th percentile
Metasploit
1 CVE
1.4% of CVEs· 97th percentile
Nuclei
1 CVE
1.4% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Couchbase.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Couchbase — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Couchbase's Products

View all 4 CNAs →

Top CWEs