Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Commvault MEDIUM 5.4
CVE-2025-12776

The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about …

Fix: after 11.36.68
Fix from $1,600 2026-01-07
Commvault HIGH 8.8
CVE-2025-57790EPSS 17%

A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. …

Fix: 11.36.60+
Fix from $1,950 2025-08-20
Commvault MEDIUM 6.5
CVE-2025-57791EPSS 21%

A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal component…

Fix: 11.36.60+
Fix from $1,600 2025-08-20
Commvault MEDIUM 6.5
CVE-2025-57788

A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit…

Fix: 11.36.60+
Fix from $1,600 2025-08-20
Commvault MEDIUM 5.4
CVE-2025-57789

During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin con…

Fix: 11.36.60+
Fix from $1,600 2025-08-20
Commvault HIGH 8.8
CVE-2025-3928 KEV

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:…

Fix: 11.20.217 / 11.28.141+
Fix from $1,950 2025-04-25
Commvault CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%

The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…

Fix: 11.38.20+
Fix from $2,300 2025-04-22
Commcell HIGH 8.8
CVE-2021-34995EPSS 69%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Commcell HIGH 8.8
CVE-2021-34996EPSS 82%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Commcell HIGH 8.8
CVE-2021-34997

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Commcell CRITICAL 9.8
CVE-2021-34993EPSS 5%

This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not r…

Mitigation only
Fix from $2,300 2022-01-13
Commcell HIGH 8.8
CVE-2021-34994EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…

Mitigation only
Fix from $1,950 2022-01-13
Commcell HIGH 7.5
CVE-2020-25780EPSS 10%

In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur …

Fix: 14.68 / 15.58+
Fix from $1,950 2020-10-29
Commvault CRITICAL 9.8
CVE-2017-18044EPSS 70%

A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside t…

Fix: after 11.0
Fix from $2,300 2018-01-19
Edge CRITICAL 9.8
CVE-2017-3195EPSS 21%

Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulner…

Patch available
Fix from $2,300 2017-12-16
Edge Server HIGH 10.0
CVE-2015-7253

The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.

Mitigation only
Fix from $1,950 2015-11-04