Known Vulnerabilities for Couchbase Server by Couchbase

Listed below are 10 of the newest known vulnerabilities associated with "Couchbase Server" by "Couchbase".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-35945 Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent from a... 7.5 - HIGH 2021-09-29 2021-10-03
CVE-2021-35944 Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent from an... 7.5 - HIGH 2021-09-29 2021-10-03
CVE-2021-35943 Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from ... 9.8 - CRITICAL 2021-09-29 2022-07-12
CVE-2021-33504 Couchbase Server before 7.1.0 has Incorrect Access Control. 4.9 - MEDIUM 2022-06-02 2023-08-08
CVE-2021-31158 In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctly che... 6.5 - MEDIUM 2021-05-19 2021-05-25
CVE-2021-27925 An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is enabled... 4.4 - MEDIUM 2021-05-19 2022-07-12
CVE-2021-27924 An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session cookies ... 5.9 - MEDIUM 2021-05-19 2021-05-26
CVE-2021-25645 An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An intern... 4.4 - MEDIUM 2021-05-10 2021-05-24
CVE-2021-25644 An issue was discovered in Couchbase Server 5.x and 6.x through 6.6.1 and 7.0.0 Beta. Incorrect commands to the REST API can ... 7.5 - HIGH 2021-05-19 2021-05-25
CVE-2021-25643 An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with administrato... 4.9 - MEDIUM 2021-05-26 2021-09-09

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCouchbaseCouchbase Server6.6.0AllAllAll
ApplicationCouchbaseCouchbase Server6.5.1AllAllAll
ApplicationCouchbaseCouchbase Server6.5.0AllAllAll
ApplicationCouchbaseCouchbase Server6.0.4AllAllAll
ApplicationCouchbaseCouchbase Server6.0.3AllAllAll
ApplicationCouchbaseCouchbase Server6.0.2AllAllAll
ApplicationCouchbaseCouchbase Server6.0.1AllAllAll
ApplicationCouchbaseCouchbase Server6.0.0AllAllAll
ApplicationCouchbaseCouchbase Server6.0AllAllAll
ApplicationCouchbaseCouchbase Server5.5.5AllAllAll
ApplicationCouchbaseCouchbase Server5.5.4AllAllAll
ApplicationCouchbaseCouchbase Server5.5.3AllAllAll
ApplicationCouchbaseCouchbase Server5.5.2AllAllAll
ApplicationCouchbaseCouchbase Server5.5.1AllAllAll
ApplicationCouchbaseCouchbase Server5.5.0AllAllAll
ApplicationCouchbaseCouchbase Server5.1.2AllAllAll
ApplicationCouchbaseCouchbase Server5.1.1AllAllAll
ApplicationCouchbaseCouchbase Server5.0.1AllAllAll
ApplicationCouchbaseCouchbase Server5.0.0AllAllAll
ApplicationCouchbaseCouchbase Server4.6.5AllAllAll
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report