Skip to content
Noroxi

Commvault records

30 published records for vendor commvault.

All records

30 records
  • Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal

    CriticalCVSS 9.3KEVWeaponizedEPSS 98%

    commvault · commvaultApr 22, 2025

  • CVE-2025-3928
    65This week

    Commvault Web Server unspecified vulnerability

    HighCVSS 8.7KEVWeaponizedEPSS 2%

    commvault · commvaultApr 25, 2025

  • CVE-2021-34996
    60This week

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.

    HighCVSS 8.8No exploitEPSS 82%

    commvault · commcellJan 13, 2022

  • CVE-2017-18044
    60This week

    A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6.

    CriticalCVSS 9.8WeaponizedEPSS 70%

    commvault · commvaultJan 19, 2018

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.

    HighCVSS 8.8No exploitEPSS 69%

    commvault · commcellJan 13, 2022

  • Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overfl

    CriticalCVSS 9.8Proof of conceptEPSS 21%

    commvault · edgeDec 15, 2017

  • This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22.

    CriticalCVSS 9.8No exploitEPSS 5%

    commvault · commcellJan 13, 2022

  • The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a coo

    CriticalCVSS 10.0No exploitEPSS 4%

    commvault · edge serverNov 3, 2015

  • Path Traversal Vulnerability

    HighCVSS 8.7WeaponizedEPSS 19%

    commvault · commvaultAug 20, 2025

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.

    HighCVSS 8.8No exploitEPSS 6%

    commvault · commcellJan 13, 2022

  • Command Center API Authentication Bypass

    CriticalCVSS 9.3No exploitEPSS 1%

    commvault · commvaultSep 8, 2026

  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.

    HighCVSS 8.8No exploitEPSS 4%

    commvault · commcellJan 13, 2022

  • Improper Authorization Validation

    CriticalCVSS 9.2No exploitEPSS 1%

    commvault · commvaultAug 11, 2026

  • Command Restriction Bypass

    CriticalCVSS 9.2No exploitEPSS 1%

    commvault · commvaultAug 11, 2026

  • Argument Injection Vulnerability in CommServe

    MediumCVSS 6.9WeaponizedEPSS 25%

    commvault · commvaultAug 20, 2025

  • Private Metrics Server SQL Injection

    HighCVSS 8.8No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • Private Metrics Server Denial of Service

    HighCVSS 8.8No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • Server-Side Request Forgery (SSRF)

    HighCVSS 8.8No exploitEPSS 0%

    commvault · commvaultAug 11, 2026

  • CommServe Information Disclosure

    HighCVSS 8.7No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • CommServe Denial of Service

    HighCVSS 8.7No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • CommServe Stack-based Buffer Overflow

    HighCVSS 8.7No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • CommServe Privilege Escalation

    HighCVSS 8.7No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • DataCube Security Feature Bypass

    HighCVSS 8.5No exploitEPSS 0%

    commvault · commvaultSep 8, 2026

  • In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal c

    HighCVSS 7.5Proof of conceptEPSS 10%

    commvault · commcellOct 29, 2020

  • CommServe Path Traversal

    HighCVSS 8.3No exploitEPSS 1%

    commvault · commvaultSep 8, 2026