Commvault Systems Inc.
Self-Reporting Analysis
Of all the CVEs published by Commvault Systems Inc. as a CNA, 100.0% affect products that Commvault Systems Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Commvault Systems Inc., 27.8% are self-published by Commvault Systems Inc. as a CNA.
Trends Over Time
The number and severity of CVEs published by Commvault Systems Inc. over time
Top CVEs
All CVEs published by Commvault Systems Inc. as a CNA, regardless of affected vendor or product.
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-57790HIGH A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to r | Aug 20, 2025 | 8.8 | 55 | NO | YES |
CVE-2025-57791MEDIUM A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input val | Aug 20, 2025 | 6.5 | 51 | NO | YES |
CVE-2025-57788MEDIUM A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not elim | Aug 20, 2025 | 6.5 | 49 | NO | YES |
CVE-2025-57789MEDIUM During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the se | Aug 20, 2025 | 5.4 | 35 | NO | YES |
CVE-2025-12776MEDIUM The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting | Jan 7, 2026 | 5.4 | 19 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (5 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Commvault Systems Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Commvault Systems Inc. as a CNA — matched by CVE ID, not by organization name.