Commvault Systems Inc.

First CVE: Aug 20, 2025Active for: 1 year
5
CVEs Published
More CVEs Published than 15% of tracked CNAs
2.5
Avg CVEs / Year
More Avg CVEs / Year than 16% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Commvault Systems Inc. as a CNA, 100.0% affect products that Commvault Systems Inc. develops as a vendor.

100.0%
Self-reported: 5Third-party: 0

Of all the CVEs published that affect products developed by Commvault Systems Inc., 27.8% are self-published by Commvault Systems Inc. as a CNA.

27.8%
72.2%
Self-published: 5Published by other CNAs: 13

Trends Over Time

The number and severity of CVEs published by Commvault Systems Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2025
11 months ago
Most Recent CVE
Jan 7, 2026
198 days ago

Top CVEs

All CVEs published by Commvault Systems Inc. as a CNA, regardless of affected vendor or product.

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to r
Aug 20, 20258.855NOYES
A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments passed to internal components due to insufficient input val
Aug 20, 20256.551NOYES
A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user credentials. RBAC helps limit the exposure but does not elim
Aug 20, 20256.549NOYES
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the se
Aug 20, 20255.435NOYES
The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns about a possible Cross-Site Scripting
Jan 7, 20265.419NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA5 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low3 (60.0%)
High0 (0.0%)
None2 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
60.0% of CVEs· 100th percentile
Nuclei
2 CVEs
40.0% of CVEs· 100th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Commvault Systems Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Commvault Systems Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs