Couchbase Server
Vendor:
First CVE: Aug 24, 2018 · Active for 7 years
63
Total CVEs
More Total CVEs than 98% of tracked products
7.9
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
4.8%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Couchbase Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2018
7 years ago
Most Recent CVE
Apr 30, 2025
450 days ago
CVE Severity & Scoring
Couchbase Server63 CVEs
37%
51%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (3.2%)
Network60 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.6%)
Attack Complexity
Low58 (92.1%)
High5 (7.9%)
Unknown0 (0.0%)
User Interaction
None56 (88.9%)
Unknown0 (0.0%)
Required7 (11.1%)
Privileges Required
Low8 (12.7%)
High7 (11.1%)
None48 (76.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (63 CVEs).
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2033HIGH Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: | Apr 14, 2023 | 8.8 | 84 | YES | NO |
CVE-2023-3079HIGH Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: | Jun 5, 2023 | 8.8 | 81 | YES | NO |
CVE-2024-0519HIGH Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur | Jan 16, 2024 | 8.8 | 69 | YES | NO |
CVE-2020-24719CRITICAL Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are | Nov 12, 2020 | 9.8 | 53 | NO | YES |
CVE-2020-9039CRITICAL Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they | Feb 22, 2020 | 9.8 | 44 | NO | YES |
CVE-2021-35943CRITICAL Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513. | Sep 29, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-11495CRITICAL In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small sea | Sep 10, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-15728HIGH Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send a | Aug 24, 2018 | 8.8 | 29 | NO | NO |
CVE-2022-32559CRITICAL An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics. | Jun 14, 2022 | 9.1 | 27 | NO | NO |
CVE-2022-32562HIGH An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission. | Jun 13, 2022 | 8.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (63 CVEs).
CISA KEV
3 CVEs
4.8% of CVEs· 97th percentile
Metasploit
1 CVE
1.6% of CVEs· 96th percentile
Nuclei
1 CVE
1.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (63 CVEs).
Media Mentions
Signals from CVEs in this product scope (63 CVEs).
Top CNAs Publishing CVEs For Couchbase Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.6.1 | 1 | 7.5 | 1.1% | 0 | 0 |
| 7.6.0 | 2 | 6.7 | 0.6% | 0 | 0 |
| 7.2.0 | 5 | 8.0 | 15.2% | 2 | 0 |
| 7.1.0 | 1 | 5.9 | 0.6% | 0 | 0 |
| 7.0.3 | 2 | 7.0 | 0.9% | 0 | 0 |
| 7.0.2 | 2 | 7.0 | 0.9% | 0 | 0 |
| 7.0.1 | 4 | 7.3 | 0.8% | 0 | 0 |
| 7.0.0 | 7 | 7.4 | 0.8% | 0 | 0 |
| 6.0.3 | 1 | 7.5 | 1.3% | 0 | 0 |
| 6.0.0 | 3 | 6.5 | 0.9% | 0 | 0 |
| 5.5.1 | 1 | 9.8 | 3.9% | 0 | 1 |
| 5.5.0 | 4 | 7.2 | 1.8% | 0 | 1 |
| 5.1.2 | 1 | 6.1 | 0.9% | 0 | 0 |
| 5.1.1 | 2 | 9.8 | 3.0% | 0 | 1 |
| 5.0.0 | 2 | 8.7 | 2.3% | 0 | 1 |
| 4.6.3 | 1 | 7.5 | 1.3% | 0 | 0 |
| 4.5.1 | 1 | 9.8 | 3.9% | 0 | 1 |
| 4.5.0 | 1 | 9.8 | 3.9% | 0 | 1 |
| 4.1.1 | 1 | 9.8 | 3.9% | 0 | 1 |
| 4.1.0 | 1 | 9.8 | 3.9% | 0 | 1 |