Database/Control plane, storage & DevOps
Commvault Web Server: Remote authenticated attacker creates and executes webshells
CVSS 8.8CVE-2025-3928Control plane, storage & DevOpsKnown exploitedcurated
Impact
Remote authenticated attacker creates and executes webshells
Who can reach it
Network (remote)
What to do
Control-plane: patch; sweep the web server for webshells
References
Related entries
- Linux iommu/amd - race while increasing host page table level: The AMD IOMMU host page table implementation supportsCVE-2025-39961 · Linux iommu/amd - race while increasing host page table levelHigh
- VMware vCenter Server (authenticated command execution via alarms): A user with permission to create or modify alarmsCVE-2025-41225 · VMware vCenter Server (authenticated command execution via alarms)High
- N-able N-central: Improper input validationCVE-2025-8876 · N-able N-centralHigh
- Grafana: symlink escape in plugin archive extraction gives remote code execution as the Grafana processCVE-2026-15815 · Grafana OSS / Enterprise (plugin archive extraction)High
- Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole): The RHOAI overlayCVE-2026-18951 · Kubeflow Training Operator (RHOAI overlay, trainjobs aggregated into the edit ClusterRole)High
- NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID): An attacker who already has valid credentialsCVE-2026-22049 · NetApp ONTAP WebAuthn multi-factor authentication (Relying Party ID)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.