Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
106 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.58% | — | Couchbase Server | 8/6/2020 | 17/6/2026 | In Couchbase Server 6.0, credentials cached by a browser can be used to perform a CSRF attack if an administrator has used their browser to check the results of a REST API request. | |
| Modificada | Alta (7.5) | 1.3% | — | Couchbase ServerCouchbase Sync Gateway | 8/6/2020 | 17/6/2026 | In Couchbase Server 6.0.3 and Couchbase Sync Gateway through 2.7.0, the Cluster management, views, query, and full-text search endpoints are vulnerable to the Slowloris denial-of-service attack because they don't more aggressively terminate slow connections. | |
| Modificada | Alta (7.5) | 0.67% | — | Couchbase Server Java SDK | 8/6/2020 | 17/6/2026 | Couchbase Server Java SDK before 2.7.1.1 allows a potential attacker to forge an SSL certificate and pose as the intended peer. An attacker can leverage this flaw by crafting a cryptographically valid certificate that will be accepted by Java SDK's Netty component due to missing hostname verification. | |
| Modificada | Crítica (9.8) | 1.8% | — | Apache Couchdb | 20/5/2020 | 17/6/2026 | CouchDB version 3.0.0 shipped with a new configuration setting that governs access control to the entire database server called `require_valid_user_except_for_up`. It was meant as an extension to the long standing setting `require_valid_user`, which in turn requires that any and all requests to CouchDB will have to be… | |
| Modificada | Crítica (9.8) | 3.9% | 💥 Exploit | Couchbase Server | 22/2/2020 | 17/6/2026 | Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an endpoint that administrators can use for… | |
| Modificada | Alta (7.5) | 0.66% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | In Couchbase Server 5.0.0, when an invalid Remote Cluster Certificate was entered as part of the reference creation, XDCR did not parse and check the certificate signature. It then accepted the invalid certificate and attempted to use it to establish future connections to the remote cluster. This has been fixed in… | |
| Modificada | Crítica (9.1) | 1.4% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | In versions of Couchbase Server prior to 5.0, the bucket named "default" was a special bucket that allowed read and write access without authentication. As part of 5.0, the behavior of all buckets including "default" were changed to only allow access by authenticated users with sufficient authorization. However, users… | |
| Modificada | Crítica (9.8) | 2.1% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | In Couchbase Server 5.1.1, the cookie used for intra-node communication was not generated securely. Couchbase Server uses erlang:now() to seed the PRNG which results in a small search space for potential random seeds that could then be used to brute force the cookie and execute code against a remote system. This has… | |
| Modificada | Alta (7.5) | 1.3% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | In Couchbase Server 4.6.3 and 5.5.0, secondary indexing encodes the entries to be indexed using collatejson. When index entries contain certain characters like \t, <, >, it caused buffer overrun as encoded string would be much larger than accounted for, causing indexer service to crash and restart. This has been… | |
| Modificada | Media (5.3) | 1.1% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | In Couchbase Server 6.0.0 and 5.5.0, the eventing service exposes system diagnostic profile via an HTTP endpoint that does not require credentials on a port earmarked for internal traffic only. This has been remedied in version 6.0.1 and now requires valid credentials to access. | |
| Modificada | Media (5.3) | 1.2% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | An issue was discovered in Couchbase Server 5.5.x through 5.5.3 and 6.0.0. The Memcached "connections" stat block command emits a non-redacted username. The system information submitted to Couchbase as part of a bug report included the usernames for all users currently logged into the system even if the log was… | |
| Modificada | Media (6.1) | 0.85% | — | Couchbase Server | 10/9/2019 | 17/6/2026 | Some enterprises require that REST API endpoints include security-related headers in REST responses. Headers such as X-Frame-Options and X-Content-Type-Options are generally advisable, however some information security professionals additionally look for X-Permitted-Cross-Domain-Policies and X-XSS-Protection, which… | |
| Modificada | Crítica (9.8) | 2.7% | — | Couchbase Sync Gateway | 26/6/2019 | 17/6/2026 | In Couchbase Sync Gateway 2.1.2, an attacker with access to the Sync Gateway’s public REST API was able to issue additional N1QL statements and extract sensitive data or call arbitrary N1QL functions through the parameters "startkey" and "endkey" on the "_all_docs" endpoint. By issuing nested queries with… | |
| Modificada | Alta (7.2) | 3.2% | — | Apache Couchdb | 2/1/2019 | 17/6/2026 | Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database. In some cases, this lead to vulnerabilities where CouchDB admin users could access the underlying operating system as the CouchDB user. Together with other vulnerabilities, it allowed full system entry for… | |
| Modificada | Alta (7.8) | 0.56% | — | Apache Couchdb | 21/9/2018 | 17/6/2026 | CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. | |
| Modificada | Alta (8.8) | 2.9% | — | Couchbase Server | 24/8/2018 | 17/6/2026 | Couchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that have 'Full Admin' role assigned could send arbitrary Erlang code to the 'diag/eval' endpoint of the API and the code would subsequently be executed in the underlying operating system… | |
| Modificada | Alta (7.2) | 8.2% | — | Apache Couchdb | 8/8/2018 | 17/6/2026 | CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user under which… | |
| Modificada | Alta (7.2) | 12% | — | Apache Couchdb | 11/7/2018 | 17/6/2026 | Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs… | |
| Modificada | Media (5.3) | 47% | 💥 Exploit | Couchcms Couch | 4/3/2018 | 17/6/2026 | Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php. | |
| Modificada | Alta (7.8) | 2.0% | 💥 Exploit | Apache Couchdb | 12/2/2018 | 17/6/2026 | The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files.… | |
| Modificada | Alta (7.2) | 90% | 💥 Exploit | Apache Couchdb | 14/11/2017 | 17/6/2026 | CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as… | |
| Modificada | Crítica (9.8) | 100% | 💥 Exploit | Apache Couchdb | 14/11/2017 | 17/6/2026 | Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes… | |
| Modificada | Media (6.8) | 6.6% | — | Apache Couchdb | 23/5/2014 | 16/6/2026 | Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to execute arbitrary code via a JSONP callback, related to Adobe Flash. | |
| Modificada | Media (5) | 23% | 💥 Exploit | Apache Couchdb | 28/3/2014 | 17/6/2026 | Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via the count parameter to /_uuids. | |
| Modificada | Media (4.3) | 3.8% | — | Apache Couchdb | 18/3/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Futon UI in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the browser-based test suite. |