Записи Dell
1 792 опубликованных записей вендора dell.
Профиль для исследователя
- Попали в KEV
- 3 · 0,2 %
- С эксплойтом
- 5 · 0,3 %
- Pre-auth RCE
- 62
- С записью об исправлении
- 38,1 %
- Медиана: публикация → KEV
- 331 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')148
- CWE-20 Improper Input Validation113
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')67
- CWE-284 Improper Access Control67
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')51
- CWE-532 Insertion of Sensitive Information into Log File47
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 792 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
85Срочно | CVE-2021-21551Готовый эксплойт | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servidell · dbutil · CWE-782 | Высокая7,8 | KEV | 79,2 % | 4 мая 2021 г. |
74На этой неделе | CVE-2026-22769Готовый эксплойт | Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.dell · recoverpoint for virtual machines · CWE-798 | Критическая10,0 | KEV | 13,3 % | 17 февр. 2026 г. |
66На этой неделе | CVE-2018-1207Proof of concept | Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.dell · emc idrac7 · CWE-94 | Критическая9,8 | — | 90,1 % | 23 мар. 2018 г. |
58В плане | CVE-2025-36604Proof of concept | Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injectiondell · unity operating environment · CWE-78 | Критическая9,8 | — | 63,8 % | 4 авг. 2025 г. |
57В плане | CVE-2022-24422Эксплойта нет | Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability.dell · idrac9 · CWE-287 | Критическая9,8 | — | 58,5 % | 26 мая 2022 г. |
57В плане | CVE-2020-11899Готовый эксплойт | The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.treck · tcp\/ip · CWE-125 | Средняя5,4 | KEV | 18,6 % | 17 июн. 2020 г. |
54В плане | CVE-2018-1217Proof of concept | Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1dell · emc avamar · CWE-862 | Критическая9,8 | — | 50,9 % | 9 апр. 2018 г. |
51В плане | CVE-2009-0695Готовый эксплойт | hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain managemedell · wyse device manager · CWE-287 | Высокая7,5 | — | 68,9 % | 19 июн. 2012 г. |
50В плане | CVE-2020-5377Proof of concept | Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.dell · emc openmanage server administrator · CWE-22 | Критическая9,1 | — | 48,3 % | 28 июл. 2020 г. |
46В плане | CVE-2016-9682Proof of concept | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web addell · sonicwall secure remote access server · CWE-77 | Критическая9,8 | — | 23,3 % | 22 февр. 2017 г. |
45В плане | CVE-2018-1216Эксплойта нет | A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabdell · emc solutions enabler virtual appliance · CWE-798 | Критическая9,8 | — | 21,3 % | 8 мар. 2018 г. |
43В плане | CVE-2017-8011Эксплойта нет | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNXdell · emc m\&r · CWE-798 | Критическая9,8 | — | 14,0 % | 17 июл. 2017 г. |
42В плане | CVE-2021-36300Эксплойта нет | iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability.dell · emc idrac9 firmware · CWE-89 | Высокая8,2 | — | 33,3 % | 23 нояб. 2021 г. |
42В плане | CVE-2016-9683Proof of concept | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web adminidell · sonicwall secure remote access server · CWE-77 | Критическая9,8 | — | 11,6 % | 22 февр. 2017 г. |
42В плане | CVE-2018-11066Эксплойта нет | Dell EMC Avamar and Integrated Data Protection Appliance Remote Code Execution Vulnerabilitydell · emc avamar | Критическая9,8 | — | 9,9 % | 26 нояб. 2018 г. |
42В плане | CVE-2020-29495Эксплойта нет | DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer.dell · emc avamar server · CWE-22 | Критическая10,0 | — | 6,2 % | 14 янв. 2021 г. |
42В плане | CVE-2015-4067Эксплойта нет | Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted tedell · netvault backup · CWE-189 | Критическая10,0 | — | 5,9 % | 29 мая 2015 г. |
42В плане | CVE-2004-2359Proof of concept | Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray appdell · truemobile 1300 wlan mini-pci card util trayapplet | Критическая10,0 | — | 5,6 % | 31 дек. 2004 г. |
41В плане | CVE-2021-36299Эксплойта нет | Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability.dell · emc idrac9 firmware · CWE-89 | Высокая8,1 | — | 29,6 % | 23 нояб. 2021 г. |
41В плане | CVE-2009-1120Эксплойта нет | EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability.dell · emc replistor | Критическая9,8 | — | 7,4 % | 15 янв. 2020 г. |
41В плане | CVE-2016-9684Proof of concept | The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web adminidell · sonicwall secure remote access server · CWE-77 | Критическая9,8 | — | 7,1 % | 22 февр. 2017 г. |
41В плане | CVE-2021-21513Эксплойта нет | Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled configdell · openmanage server administrator · CWE-287 | Критическая9,8 | — | 5,9 % | 2 мар. 2021 г. |
41В плане | CVE-2017-8023Эксплойта нет | EMC Networker Remote Code Execution Vulnerabilitydell · emc networker · CWE-287 | Критическая9,8 | — | 5,9 % | 1 апр. 2019 г. |
41В плане | CVE-2019-18580Эксплойта нет | Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability.dell · emc storage monitoring and reporting · CWE-502 | Критическая10,0 | — | 4,9 % | 26 нояб. 2019 г. |
41В плане | CVE-2013-3594Эксплойта нет | The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of sedell · powerconnect 3348 · CWE-20 | Критическая10,0 | — | 3,9 % | 20 янв. 2014 г. |
- CVE-2021-2155185Срочно
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of servi
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 79 %dell · dbutil4 мая 2021 г.
- CVE-2026-2276974На этой неделе
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 13 %dell · recoverpoint for virtual machines17 февр. 2026 г.
- CVE-2018-120766На этой неделе
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code.
КритическаяCVSS 9,8Proof of conceptEPSS 90 %dell · emc idrac723 мар. 2018 г.
- CVE-2025-3660458В плане
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 64 %dell · unity operating environment4 авг. 2025 г.
- CVE-2022-2442257В плане
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 59 %dell · idrac926 мая 2022 г.
- CVE-2020-1189957В плане
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 19 %treck · tcp\/ip17 июн. 2020 г.
- CVE-2018-121754В плане
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1
КритическаяCVSS 9,8Proof of conceptEPSS 51 %dell · emc avamar9 апр. 2018 г.
- CVE-2009-069551В плане
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain manageme
ВысокаяCVSS 7,5Готовый эксплойтEPSS 69 %dell · wyse device manager19 июн. 2012 г.
- CVE-2020-537750В плане
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
КритическаяCVSS 9,1Proof of conceptEPSS 48 %dell · emc openmanage server administrator28 июл. 2020 г.
- CVE-2016-968246В плане
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web ad
КритическаяCVSS 9,8Proof of conceptEPSS 23 %dell · sonicwall secure remote access server22 февр. 2017 г.
- CVE-2018-121645В плане
A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enab
КритическаяCVSS 9,8Эксплойта нетEPSS 21 %dell · emc solutions enabler virtual appliance8 мар. 2018 г.
- CVE-2017-801143В плане
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R prior to 4.1, EMC VNX
КритическаяCVSS 9,8Эксплойта нетEPSS 14 %dell · emc m\&r17 июл. 2017 г.
- CVE-2021-3630042В плане
iDRAC9 versions prior to 5.00.00.00 contain an improper input validation vulnerability.
ВысокаяCVSS 8,2Эксплойта нетEPSS 33 %dell · emc idrac9 firmware23 нояб. 2021 г.
- CVE-2016-968342В плане
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web admini
КритическаяCVSS 9,8Proof of conceptEPSS 12 %dell · sonicwall secure remote access server22 февр. 2017 г.
- CVE-2018-1106642В плане
Dell EMC Avamar and Integrated Data Protection Appliance Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %dell · emc avamar26 нояб. 2018 г.
- CVE-2020-2949542В плане
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer.
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %dell · emc avamar server14 янв. 2021 г.
- CVE-2015-406742В плане
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted te
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %dell · netvault backup29 мая 2015 г.
- CVE-2004-235942В плане
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray app
КритическаяCVSS 10,0Proof of conceptEPSS 6 %dell · truemobile 1300 wlan mini-pci card util trayapplet31 дек. 2004 г.
- CVE-2021-3629941В плане
Dell iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.29.00 and 5.00.00.00 contain an SQL injection vulnerability.
ВысокаяCVSS 8,1Эксплойта нетEPSS 30 %dell · emc idrac9 firmware23 нояб. 2021 г.
- CVE-2009-112041В плане
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %dell · emc replistor15 янв. 2020 г.
- CVE-2016-968441В плане
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web admini
КритическаяCVSS 9,8Proof of conceptEPSS 7 %dell · sonicwall secure remote access server22 февр. 2017 г.
- CVE-2021-2151341В плане
Dell EMC OpenManage Server Administrator (OMSA) version 9.5 Microsoft Windows installations with Distributed Web Server (DWS) enabled config
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %dell · openmanage server administrator2 мар. 2021 г.
- CVE-2017-802341В плане
EMC Networker Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %dell · emc networker1 апр. 2019 г.
- CVE-2019-1858041В плане
Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability.
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %dell · emc storage monitoring and reporting26 нояб. 2019 г.
- CVE-2013-359441В плане
The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of se
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %dell · powerconnect 334820 янв. 2014 г.