Database/Control plane, storage & DevOps
Commvault Command Center: Unauthenticated ZIP upload + path traversal
CVSS 10.0CVE-2025-34028Control plane, storage & DevOpsKnown exploitedcurated
Impact
Unauthenticated ZIP upload + path traversal -> RCE via a malicious JSP
Who can reach it
Network (remote)
What to do
Control-plane: patch immediately; the backup control plane is a crown-jewel target
References
Related entries
- HPE OneView (unauthenticated remote code execution): Unauthenticated remote code execution on OneView with scope changeCVE-2025-37164 · HPE OneView (unauthenticated remote code execution)Critical
- Ivanti Sentry: OS command injectionCVE-2026-10520 · Ivanti SentryCritical
- Cisco Secure Firewall Management Center: unauthenticated HTTP request yields root on the applianceCVE-2026-20079 · Cisco Secure Firewall Management Center (web interface)Critical
- Kestra: suffix-match auth bypass on /configs gives unauthenticated workflow execution as rootCVE-2026-49869 · Kestra AuthenticationFilter (suffix match on the /configs path whitelist)Critical
- Linux crypto driver for Marvell OCTEON TX: The scatter-gather cleanup path in the Marvell OCTEON TX crypto driver usesCVE-2026-74280 · Linux crypto driver for Marvell OCTEON TXCritical
- Linux VXLAN driver (neighbour hardware address read in route_shortcircuit): `route_shortcircuit()` reads a neighbour'sCVE-2026-74475 · Linux VXLAN driver (neighbour hardware address read in route_shortcircuit)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.