Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-12776 The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about … Commvault after 11.36.68 Fix from $1,6002026-01-07 HIGH 8.8 CVE-2025-57790EPSS 17% A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. … Commvault 11.36.60+ Fix from $1,9502025-08-20 MEDIUM 6.5 CVE-2025-57791EPSS 21% A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal component… Commvault 11.36.60+ Fix from $1,6002025-08-20 MEDIUM 6.5 CVE-2025-57788 A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit… Commvault 11.36.60+ Fix from $1,6002025-08-20 MEDIUM 5.4 CVE-2025-57789 During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin con… Commvault 11.36.60+ Fix from $1,6002025-08-20 HIGH 8.8 CVE-2025-3928 KEV Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory:… Commvault 11.20.217 / 11.28.141+ Fix from $1,9502025-04-25 CRITICAL 10.0 CVE-2025-34028 KEVEPSS 98% The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expand… Commvault 11.38.20+ Fix from $2,3002025-04-22 HIGH 8.8 CVE-2021-34995EPSS 69% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio… Commcell Mitigation only Fix from $1,9502022-01-13 HIGH 8.8 CVE-2021-34996EPSS 82% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio… Commcell Mitigation only Fix from $1,9502022-01-13 HIGH 8.8 CVE-2021-34997 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio… Commcell Mitigation only Fix from $1,9502022-01-13 CRITICAL 9.8 CVE-2021-34993EPSS 5% This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not r… Commcell Mitigation only Fix from $2,3002022-01-13 HIGH 8.8 CVE-2021-34994EPSS 6% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authenticatio… Commcell Mitigation only Fix from $1,9502022-01-13 HIGH 7.5 CVE-2020-25780EPSS 10% In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur … Commcell 14.68 / 15.58+ Fix from $1,9502020-10-29 CRITICAL 9.8 CVE-2017-18044EPSS 70% A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside t… Commvault after 11.0 Fix from $2,3002018-01-19 CRITICAL 9.8 CVE-2017-3195EPSS 21% Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulner… Edge Patch available Fix from $2,3002017-12-16 HIGH 10.0 CVE-2015-7253 The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie. Edge Server Mitigation only Fix from $1,9502015-11-04