• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2022-32562
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-06-22
N/A
8.8 HIGH
An issue was discovered in Couchbase Server before 7.0.4. Operations may succeed on a collection using stale RBAC permission.
CVE-2022-32561
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-06-24
N/A
4.9 MEDIUM
An issue was discovered in Couchbase Server before 6.6.5 and 7.x before 7.0.4. Previous mitigations for CVE-2018-15728 were found to be insufficient when it was discovered that diagnostic endpoints could still be accessed from the network.
CVE-2022-32560
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-06-22
N/A
7.5 HIGH
An issue was discovered in Couchbase Server before 7.0.4. XDCR lacks role checking when changing internal settings.
CVE-2022-3256
2023-01-20
N/A
7.8 HIGH
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
CVE-2022-32559
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-06-24
N/A
9.1 CRITICAL
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked metrics.
CVE-2022-32558
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-06-22
N/A
7.5 HIGH
An issue was discovered in Couchbase Server before 7.0.4. Sample bucket loading may leak internal user passwords during a failure.
CVE-2022-32557
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-06-24
N/A
7.5 HIGH
An issue was discovered in Couchbase Server before 7.0.4. The Index Service does not enforce authentication for TCP/TLS servers.
CVE-2022-32556
Couchbase, Couchbase Server
Bleve, Cloud_native_operator, Couchbase_server, Couchbase_server_java_sdk, Server, Sync_gateway
2022-07-27
N/A
7.5 HIGH
An issue was discovered in Couchbase Server before 7.0.4. A private key is leaked to the log files with certain crashes.
CVE-2022-32555
2022-09-17
N/A
8.8 HIGH
Unisys Data Exchange Management Studio before 6.0.IC2 and 7.x before 7.0.IC1 doesn't have an Anti-CSRF token to authenticate the POST request. Thus, a cross-site request forgery attack could occur.
CVE-2022-32554
2022-07-05
N/A
9.8 CRITICAL
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to possibly exposed credentials for accessing the product’s management interface. The password may be known outside Pure Storage and could be used on an affected system, if reachable, to execute arbitrary instructions with root privileges. No other Pure Storage products or services are affected. Remediation is available from Pure Storage via a self-serve “opt-in” patch, manual patch application or a software upgrade to an unaffected version of Purity software.
« Previous 1 … 9,869 9,870 9,871 9,872 9,873 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE