Commvault / Commvault
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-77106 | Cvlaunchd Code Execution | HIGH | 7.7 | Sep 8, 2026 |
| CVE-2026-77105 | CommServe Privilege Escalation | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-77104 | CommServe Path Traversal | HIGH | 8.3 | Sep 8, 2026 |
| CVE-2026-77103 | CommServe Information Disclosure | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-77102 | CommServe Denial of Service | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-77101 | CommServe Stack-based Buffer Overflow | HIGH | 8.7 | Sep 8, 2026 |
| CVE-2026-77098 | Private Metrics Server SQL Injection | HIGH | 8.8 | Sep 8, 2026 |
| CVE-2026-77097 | Private Metrics Server Denial of Service | HIGH | 8.8 | Sep 8, 2026 |
| CVE-2026-77092 | Content Extractor Privilege Escalation | HIGH | 7.3 | Sep 8, 2026 |
| CVE-2026-77091 | DataCube Security Feature Bypass | HIGH | 8.5 | Sep 8, 2026 |
| CVE-2026-77089 | Command Center API Authentication Bypass | CRITICAL | 9.3 | Sep 8, 2026 |
| CVE-2026-13738 | Improper Authorization Validation | CRITICAL | 9.2 | Aug 11, 2026 |
| CVE-2026-13737 | Command Restriction Bypass | CRITICAL | 9.2 | Aug 11, 2026 |
| CVE-2026-13739 | Server-Side Request Forgery (SSRF) | HIGH | 8.8 | Aug 11, 2026 |
| CVE-2025-12776 | Stored Cross-Site Scripting | LOW | 1.8 | Jan 7, 2026 |
| CVE-2025-57791 | Argument Injection Vulnerability in CommServe | MEDIUM | 6.9 | Aug 20, 2025 |
| CVE-2025-57790 | Path Traversal Vulnerability | HIGH | 8.7 | Aug 20, 2025 |
| CVE-2025-57789 | Vulnerability in Initial Administrator Login Process | MEDIUM | 5.3 | Aug 20, 2025 |
| CVE-2025-57788 | Unauthorized API Access Risk | MEDIUM | 6.9 | Aug 20, 2025 |
| CVE-2024-13975 | Commvault 11.20.0 - 11.36.0 Windows Access Nodes Compromise via Local File Server Agent Abuse | HIGH | 8.5 | Jul 25, 2025 |
| CVE-2025-34136 | Commvault CommServe Web Server Unauthenticated SQL Injection | MEDIUM | 6.9 | Jul 25, 2025 |
| CVE-2025-3928 KEV | Commvault Web Server unspecified vulnerability | HIGH | 8.7 | Apr 25, 2025 |
| CVE-2025-34028 KEV | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal | CRITICAL | 9.3 | Apr 22, 2025 |
| CVE-2017-18044 | A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvau… | CRITICAL | 9.8 | Jan 19, 2018 |
Showing 1 to 22 of 22 CVEs