Vulnerabilities > Apache > Couchdb > High

DATE CVE VULNERABILITY TITLE RISK
2021-10-14 CVE-2021-38295 Cross-site Scripting vulnerability in Apache Couchdb
In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachment to a document.
local
low complexity
apache CWE-79
7.3
2019-01-02 CVE-2018-17188 Unspecified vulnerability in Apache Couchdb
Prior to CouchDB version 2.3.0, CouchDB allowed for runtime-configuration of key components of the database.
network
low complexity
apache
7.2
2018-09-21 CVE-2018-14889 Improper Input Validation vulnerability in Apache Couchdb
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
local
low complexity
apache CWE-20
7.8
2018-08-08 CVE-2018-11769 Unspecified vulnerability in Apache Couchdb
CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S).
network
low complexity
apache
7.2
2018-07-11 CVE-2018-8007 Improper Input Validation vulnerability in Apache Couchdb
Apache CouchDB administrative users can configure the database server via HTTP(S).
network
low complexity
apache CWE-20
7.2
2018-02-12 CVE-2016-8742 Permissions, Privileges, and Access Controls vulnerability in Apache Couchdb 2.0.0
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation.
local
low complexity
apache CWE-264
7.8
2017-11-14 CVE-2017-12636 OS Command Injection vulnerability in Apache Couchdb
CouchDB administrative users can configure the database server via HTTP(S).
network
low complexity
apache CWE-78
7.2