Couchbase Server

Vendor:

First CVE: Aug 24, 2018 · Active for 7 years

63
Total CVEs
More Total CVEs than 98% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
4.8%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Couchbase Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2018
7 years ago
Most Recent CVE
Apr 30, 2025
450 days ago

CVE Severity & Scoring

Couchbase Server63 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (3.2%)
Network60 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.6%)
Attack Complexity
Low58 (92.1%)
High5 (7.9%)
Unknown0 (0.0%)
User Interaction
None56 (88.9%)
Unknown0 (0.0%)
Required7 (11.1%)
Privileges Required
Low8 (12.7%)
High7 (11.1%)
None48 (76.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:
Apr 14, 20238.884YESNO
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:
Jun 5, 20238.881YESNO
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur
Jan 16, 20248.869YESNO
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are
Nov 12, 20209.853NOYES
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they
Feb 22, 20209.844NOYES
Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.
Sep 29, 20219.830NONO
In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small sea
Sep 10, 20199.830NONO
Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send a
Aug 24, 20188.829NONO
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
Jun 14, 20229.127NONO
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
Jun 13, 20228.827NONO

Exploit Exposure

Signals from CVEs in this product scope (63 CVEs).

CISA KEV
3 CVEs
4.8% of CVEs· 97th percentile
Metasploit
1 CVE
1.6% of CVEs· 96th percentile
Nuclei
1 CVE
1.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (63 CVEs).

Media Mentions

Signals from CVEs in this product scope (63 CVEs).

Top CNAs Publishing CVEs For Couchbase Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.6.117.51.1%00
7.6.026.70.6%00
7.2.058.015.2%20
7.1.015.90.6%00
7.0.327.00.9%00
7.0.227.00.9%00
7.0.147.30.8%00
7.0.077.40.8%00
6.0.317.51.3%00
6.0.036.50.9%00
5.5.119.83.9%01
5.5.047.21.8%01
5.1.216.10.9%00
5.1.129.83.0%01
5.0.028.72.3%01
4.6.317.51.3%00
4.5.119.83.9%01
4.5.019.83.9%01
4.1.119.83.9%01
4.1.019.83.9%01