Commvault records
30 published records for vendor commvault.
Researcher profile
- Entered KEV
- 2 · 6.7%
- Weaponized
- 6 · 20%
- Pre-auth RCE
- 6
- With a fix record
- 53.3%
- Median publish → KEV
- 7 days
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-863 Incorrect Authorization2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-121 Stack-based Buffer Overflow2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
96Now | CVE-2025-34028Weaponized | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversalcommvault · commvault · CWE-22 | Critical9.3 | KEV | 97.6% | Apr 22, 2025 |
65This week | CVE-2025-3928Weaponized | Commvault Web Server unspecified vulnerabilitycommvault · commvault | High8.7 | KEV | 2.3% | Apr 25, 2025 |
60This week | CVE-2021-34996No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-749 | High8.8 | — | 82.3% | Jan 13, 2022 |
60This week | CVE-2017-18044Weaponized | A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6.commvault · commvault · CWE-78 | Critical9.8 | — | 69.8% | Jan 19, 2018 |
56Plan | CVE-2021-34995No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-434 | High8.8 | — | 68.9% | Jan 13, 2022 |
45Plan | CVE-2017-3195Proof of concept | Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflcommvault · edge · CWE-121 | Critical9.8 | — | 21.4% | Dec 15, 2017 |
41Plan | CVE-2021-34993No exploit | This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-287 | Critical9.8 | — | 5.4% | Jan 13, 2022 |
41Plan | CVE-2015-7253No exploit | The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a coocommvault · edge server · CWE-78 | Critical10.0 | — | 4.0% | Nov 3, 2015 |
40Plan | CVE-2025-57790Weaponized | Path Traversal Vulnerabilitycommvault · commvault · CWE-36 | High8.7 | — | 19.4% | Aug 20, 2025 |
37Monitor | CVE-2021-34994No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-20 | High8.8 | — | 5.8% | Jan 13, 2022 |
37Monitor | CVE-2026-77089No exploit | Command Center API Authentication Bypasscommvault · commvault · CWE-290 | Critical9.3 | — | 0.6% | Sep 8, 2026 |
36Monitor | CVE-2021-34997No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.commvault · commcell · CWE-434 | High8.8 | — | 4.2% | Jan 13, 2022 |
36Monitor | CVE-2026-13738No exploit | Improper Authorization Validationcommvault · commvault · CWE-863 | Critical9.2 | — | 0.6% | Aug 11, 2026 |
36Monitor | CVE-2026-13737No exploit | Command Restriction Bypasscommvault · commvault · CWE-863 | Critical9.2 | — | 0.5% | Aug 11, 2026 |
35Monitor | CVE-2025-57791Weaponized | Argument Injection Vulnerability in CommServecommvault · commvault · CWE-88 | Medium6.9 | — | 25.1% | Aug 20, 2025 |
35Monitor | CVE-2026-77098No exploit | Private Metrics Server SQL Injectioncommvault · commvault · CWE-89 | High8.8 | — | 0.5% | Sep 8, 2026 |
35Monitor | CVE-2026-77097No exploit | Private Metrics Server Denial of Servicecommvault · commvault · CWE-306 | High8.8 | — | 0.5% | Sep 8, 2026 |
35Monitor | CVE-2026-13739No exploit | Server-Side Request Forgery (SSRF)commvault · commvault · CWE-918 | High8.8 | — | 0.4% | Aug 11, 2026 |
34Monitor | CVE-2026-77103No exploit | CommServe Information Disclosurecommvault · commvault · CWE-288 | High8.7 | — | 0.5% | Sep 8, 2026 |
34Monitor | CVE-2026-77102No exploit | CommServe Denial of Servicecommvault · commvault · CWE-122 | High8.7 | — | 0.5% | Sep 8, 2026 |
34Monitor | CVE-2026-77101No exploit | CommServe Stack-based Buffer Overflowcommvault · commvault · CWE-121 | High8.7 | — | 0.5% | Sep 8, 2026 |
34Monitor | CVE-2026-77105No exploit | CommServe Privilege Escalationcommvault · commvault · CWE-347 | High8.7 | — | 0.3% | Sep 8, 2026 |
34Monitor | CVE-2026-77091No exploit | DataCube Security Feature Bypasscommvault · commvault · CWE-22 | High8.5 | — | 0.2% | Sep 8, 2026 |
33Monitor | CVE-2020-25780Proof of concept | In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal ccommvault · commcell · CWE-22 | High7.5 | — | 9.9% | Oct 29, 2020 |
33Monitor | CVE-2026-77104No exploit | CommServe Path Traversalcommvault · commvault · CWE-22 | High8.3 | — | 0.6% | Sep 8, 2026 |
- CVE-2025-3402896Now
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
CriticalCVSS 9.3KEVWeaponizedEPSS 98%commvault · commvaultApr 22, 2025
- CVE-2025-392865This week
Commvault Web Server unspecified vulnerability
HighCVSS 8.7KEVWeaponizedEPSS 2%commvault · commvaultApr 25, 2025
- CVE-2021-3499660This week
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
HighCVSS 8.8No exploitEPSS 82%commvault · commcellJan 13, 2022
- CVE-2017-1804460This week
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6.
CriticalCVSS 9.8WeaponizedEPSS 70%commvault · commvaultJan 19, 2018
- CVE-2021-3499556Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
HighCVSS 8.8No exploitEPSS 69%commvault · commcellJan 13, 2022
- CVE-2017-319545Plan
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overfl
CriticalCVSS 9.8Proof of conceptEPSS 21%commvault · edgeDec 15, 2017
- CVE-2021-3499341Plan
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22.
CriticalCVSS 9.8No exploitEPSS 5%commvault · commcellJan 13, 2022
- CVE-2015-725341Plan
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a coo
CriticalCVSS 10.0No exploitEPSS 4%commvault · edge serverNov 3, 2015
- CVE-2025-5779040Plan
Path Traversal Vulnerability
HighCVSS 8.7WeaponizedEPSS 19%commvault · commvaultAug 20, 2025
- CVE-2021-3499437Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
HighCVSS 8.8No exploitEPSS 6%commvault · commcellJan 13, 2022
- CVE-2026-7708937Monitor
Command Center API Authentication Bypass
CriticalCVSS 9.3No exploitEPSS 1%commvault · commvaultSep 8, 2026
- CVE-2021-3499736Monitor
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22.
HighCVSS 8.8No exploitEPSS 4%commvault · commcellJan 13, 2022
- CVE-2026-1373836Monitor
Improper Authorization Validation
CriticalCVSS 9.2No exploitEPSS 1%commvault · commvaultAug 11, 2026
- CVE-2026-1373736Monitor
Command Restriction Bypass
CriticalCVSS 9.2No exploitEPSS 1%commvault · commvaultAug 11, 2026
- CVE-2025-5779135Monitor
Argument Injection Vulnerability in CommServe
MediumCVSS 6.9WeaponizedEPSS 25%commvault · commvaultAug 20, 2025
- CVE-2026-7709835Monitor
Private Metrics Server SQL Injection
HighCVSS 8.8No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2026-7709735Monitor
Private Metrics Server Denial of Service
HighCVSS 8.8No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2026-1373935Monitor
Server-Side Request Forgery (SSRF)
HighCVSS 8.8No exploitEPSS 0%commvault · commvaultAug 11, 2026
- CVE-2026-7710334Monitor
CommServe Information Disclosure
HighCVSS 8.7No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2026-7710234Monitor
CommServe Denial of Service
HighCVSS 8.7No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2026-7710134Monitor
CommServe Stack-based Buffer Overflow
HighCVSS 8.7No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2026-7710534Monitor
CommServe Privilege Escalation
HighCVSS 8.7No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2026-7709134Monitor
DataCube Security Feature Bypass
HighCVSS 8.5No exploitEPSS 0%commvault · commvaultSep 8, 2026
- CVE-2020-2578033Monitor
In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal c
HighCVSS 7.5Proof of conceptEPSS 10%commvault · commcellOct 29, 2020
- CVE-2026-7710433Monitor
CommServe Path Traversal
HighCVSS 8.3No exploitEPSS 1%commvault · commvaultSep 8, 2026