Dell records
1,792 published records for vendor dell.
Researcher profile
- Entered KEV
- 3 · 0.2%
- Weaponized
- 5 · 0.3%
- Pre-auth RCE
- 62
- With a fix record
- 38.1%
- Median publish → KEV
- 331 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')148
- CWE-20 Improper Input Validation113
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-284 Improper Access Control67
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')51
- CWE-532 Insertion of Sensitive Information into Log File47
The weakness classes this vendor ships most often: where to look.
CWEAll records
1,792 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
85Now | CVE-2021-21551Weaponized | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servidell · dbutil · CWE-782 | High7.8 | KEV | 79.2% | May 4, 2021 |
74This week | CVE-2026-22769Weaponized | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.dell · recoverpoint for virtual machines · CWE-798 | Critical10.0 | KEV | 13.3% | Feb 17, 2026 |
66This week | CVE-2018-1207Proof of concept | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.dell · emc idrac7 · CWE-94 | Critical9.8 | — | 90.1% | Mar 23, 2018 |
58Plan | CVE-2025-36604Proof of concept | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectiondell · unity operating environment · CWE-78 | Critical9.8 | — | 63.8% | Aug 4, 2025 |
57Plan | CVE-2022-24422No exploit | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability.dell · idrac9 · CWE-287 | Critical9.8 | — | 58.5% | May 26, 2022 |
57Plan | CVE-2020-11899Weaponized | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Medium5.4 | KEV | 18.6% | Jun 17, 2020 |
54Plan | CVE-2018-1217Proof of concept | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1dell · emc avamar · CWE-862 | Critical9.8 | — | 50.9% | Apr 9, 2018 |
51Plan | CVE-2009-0695Weaponized | hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain managemedell · wyse device manager · CWE-287 | High7.5 | — | 68.9% | Jun 19, 2012 |
50Plan | CVE-2020-5377Proof of concept | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.dell · emc openmanage server administrator · CWE-22 | Critical9.1 | — | 48.3% | Jul 28, 2020 |
46Plan | CVE-2016-9682Proof of concept | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web addell · sonicwall secure remote access server · CWE-77 | Critical9.8 | — | 23.3% | Feb 22, 2017 |
45Plan | CVE-2018-1216No exploit | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabdell · emc solutions enabler virtual appliance · CWE-798 | Critical9.8 | — | 21.3% | Mar 8, 2018 |
43Plan | CVE-2017-8011No exploit | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNXdell · emc m\&r · CWE-798 | Critical9.8 | — | 14.0% | Jul 17, 2017 |
42Plan | CVE-2021-36300No exploit | iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability.dell · emc idrac9 firmware · CWE-89 | High8.2 | — | 33.3% | Nov 23, 2021 |
42Plan | CVE-2016-9683Proof of concept | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web adminidell · sonicwall secure remote access server · CWE-77 | Critical9.8 | — | 11.6% | Feb 22, 2017 |
42Plan | CVE-2018-11066No exploit | Dell EMC Avamar and Integrated Data Protection Appliance Remote Code Execution Vulnerabilitydell · emc avamar | Critical9.8 | — | 9.9% | Nov 26, 2018 |
42Plan | CVE-2020-29495No exploit | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer.dell · emc avamar server · CWE-22 | Critical10.0 | — | 6.2% | Jan 14, 2021 |
42Plan | CVE-2015-4067No exploit | Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted tedell · netvault backup · CWE-189 | Critical10.0 | — | 5.9% | May 29, 2015 |
42Plan | CVE-2004-2359Proof of concept | Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray appdell · truemobile 1300 wlan mini-pci card util trayapplet | Critical10.0 | — | 5.6% | Dec 31, 2004 |
41Plan | CVE-2021-36299No exploit | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability.dell · emc idrac9 firmware · CWE-89 | High8.1 | — | 29.6% | Nov 23, 2021 |
41Plan | CVE-2009-1120No exploit | EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability.dell · emc replistor | Critical9.8 | — | 7.4% | Jan 15, 2020 |
41Plan | CVE-2016-9684Proof of concept | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web adminidell · sonicwall secure remote access server · CWE-77 | Critical9.8 | — | 7.1% | Feb 22, 2017 |
41Plan | CVE-2021-21513No exploit | Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configdell · openmanage server administrator · CWE-287 | Critical9.8 | — | 5.9% | Mar 2, 2021 |
41Plan | CVE-2017-8023No exploit | EMC Networker Remote Code Execution Vulnerabilitydell · emc networker · CWE-287 | Critical9.8 | — | 5.9% | Apr 1, 2019 |
41Plan | CVE-2019-18580No exploit | Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability.dell · emc storage monitoring and reporting · CWE-502 | Critical10.0 | — | 4.9% | Nov 26, 2019 |
41Plan | CVE-2013-3594No exploit | The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of sedell · powerconnect 3348 · CWE-20 | Critical10.0 | — | 3.9% | Jan 20, 2014 |
- CVE-2021-2155185Now
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servi
HighCVSS 7.8KEVWeaponizedEPSS 79%dell · dbutilMay 4, 2021
- CVE-2026-2276974This week
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.
CriticalCVSS 10.0KEVWeaponizedEPSS 13%dell · recoverpoint for virtual machinesFeb 17, 2026
- CVE-2018-120766This week
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.
CriticalCVSS 9.8Proof of conceptEPSS 90%dell · emc idrac7Mar 23, 2018
- CVE-2025-3660458Plan
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
CriticalCVSS 9.8Proof of conceptEPSS 64%dell · unity operating environmentAug 4, 2025
- CVE-2022-2442257Plan
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability.
CriticalCVSS 9.8No exploitEPSS 59%dell · idrac9May 26, 2022
- CVE-2020-1189957Plan
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
MediumCVSS 5.4KEVWeaponizedEPSS 19%treck · tcp\/ipJun 17, 2020
- CVE-2018-121754Plan
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1
CriticalCVSS 9.8Proof of conceptEPSS 51%dell · emc avamarApr 9, 2018
- CVE-2009-069551Plan
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain manageme
HighCVSS 7.5WeaponizedEPSS 69%dell · wyse device managerJun 19, 2012
- CVE-2020-537750Plan
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
CriticalCVSS 9.1Proof of conceptEPSS 48%dell · emc openmanage server administratorJul 28, 2020
- CVE-2016-968246Plan
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web ad
CriticalCVSS 9.8Proof of conceptEPSS 23%dell · sonicwall secure remote access serverFeb 22, 2017
- CVE-2018-121645Plan
A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enab
CriticalCVSS 9.8No exploitEPSS 21%dell · emc solutions enabler virtual applianceMar 8, 2018
- CVE-2017-801143Plan
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX
CriticalCVSS 9.8No exploitEPSS 14%dell · emc m\&rJul 17, 2017
- CVE-2021-3630042Plan
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability.
HighCVSS 8.2No exploitEPSS 33%dell · emc idrac9 firmwareNov 23, 2021
- CVE-2016-968342Plan
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web admini
CriticalCVSS 9.8Proof of conceptEPSS 12%dell · sonicwall secure remote access serverFeb 22, 2017
- CVE-2018-1106642Plan
Dell EMC Avamar and Integrated Data Protection Appliance Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 10%dell · emc avamarNov 26, 2018
- CVE-2020-2949542Plan
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer.
CriticalCVSS 10.0No exploitEPSS 6%dell · emc avamar serverJan 14, 2021
- CVE-2015-406742Plan
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted te
CriticalCVSS 10.0No exploitEPSS 6%dell · netvault backupMay 29, 2015
- CVE-2004-235942Plan
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray app
CriticalCVSS 10.0Proof of conceptEPSS 6%dell · truemobile 1300 wlan mini-pci card util trayappletDec 31, 2004
- CVE-2021-3629941Plan
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability.
HighCVSS 8.1No exploitEPSS 30%dell · emc idrac9 firmwareNov 23, 2021
- CVE-2009-112041Plan
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability.
CriticalCVSS 9.8No exploitEPSS 7%dell · emc replistorJan 15, 2020
- CVE-2016-968441Plan
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web admini
CriticalCVSS 9.8Proof of conceptEPSS 7%dell · sonicwall secure remote access serverFeb 22, 2017
- CVE-2021-2151341Plan
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled config
CriticalCVSS 9.8No exploitEPSS 6%dell · openmanage server administratorMar 2, 2021
- CVE-2017-802341Plan
EMC Networker Remote Code Execution Vulnerability
CriticalCVSS 9.8No exploitEPSS 6%dell · emc networkerApr 1, 2019
- CVE-2019-1858041Plan
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability.
CriticalCVSS 10.0No exploitEPSS 5%dell · emc storage monitoring and reportingNov 26, 2019
- CVE-2013-359441Plan
The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of se
CriticalCVSS 10.0No exploitEPSS 4%dell · powerconnect 3348Jan 20, 2014