Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2025-12776
The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about …
Commvault
after 11.36.68
HIGH 8.8
CVE-2025-57790EPSS 17%
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. …
Commvault
11.36.60+
MEDIUM 6.5
CVE-2025-57791EPSS 21%
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal component…
Commvault
11.36.60+
MEDIUM 6.5
CVE-2025-57788
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit…
Commvault
11.36.60+
MEDIUM 5.4
CVE-2025-57789
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin con…
Commvault
11.36.60+
HIGH 8.8
CVE-2025-3928 KEV
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:…
Commvault
11.20.217 / 11.28.141+
CRITICAL 10.0
CVE-2025-34028 KEVEPSS 98%
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand…
Commvault
11.38.20+
HIGH 8.8
CVE-2021-34995EPSS 69%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…
Commcell
Mitigation only
HIGH 8.8
CVE-2021-34996EPSS 82%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…
Commcell
Mitigation only
HIGH 8.8
CVE-2021-34997
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…
Commcell
Mitigation only
CRITICAL 9.8
CVE-2021-34993EPSS 5%
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not r…
Commcell
Mitigation only
HIGH 8.8
CVE-2021-34994EPSS 6%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio…
Commcell
Mitigation only
HIGH 7.5
CVE-2020-25780EPSS 10%
In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur …
Commcell
14.68 / 15.58+
CRITICAL 9.8
CVE-2017-18044EPSS 70%
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside t…
Commvault
after 11.0
CRITICAL 9.8
CVE-2017-3195EPSS 21%
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulner…
Edge
Patch available
HIGH 10.0
CVE-2015-7253
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.
Edge Server
Mitigation only