VYPR

Vendor CVEs

Dell

All CVEs

1,944 total · sorted by risk
  • CVE-2026-24502HigMar 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-22765HigFeb 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.

  • CVE-2026-26359HigFeb 19, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files.

  • CVE-2026-26358HigFeb 19, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2026-22273HigJan 23, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell ECS, versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.2.0.0, contains an Use of Default Credentials vulnerability in the OS. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of…

  • CVE-2025-36588HigJan 22, 2026
    risk 0.57cvss 8.8epss 0.01

    Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2025-36553HigNov 17, 2025
    risk 0.57cvss 8.8epss 0.00

    A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger…

  • CVE-2025-32089HigNov 17, 2025
    risk 0.57cvss 8.8epss 0.00

    A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call…

  • CVE-2025-31649HigNov 17, 2025
    risk 0.57cvss 8.7epss 0.00

    A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can…

  • CVE-2025-31361HigNov 17, 2025
    risk 0.57cvss 8.7epss 0.00

    A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to privilege escalation. An…

  • CVE-2025-46428HigNov 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code…

  • CVE-2025-46427HigNov 12, 2025
    risk 0.57cvss 8.8epss 0.01

    Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2025-43888HigSep 10, 2025
    risk 0.57cvss 8.8epss 0.00

    Dell PowerProtect Data Manager, Hyper-V, version(s) 19.19 and 19.20, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2025-30105HigJul 30, 2025
    risk 0.57cvss 8.8epss 0.00

    Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the exposed…

  • CVE-2025-26332HigJul 30, 2025
    risk 0.57cvss 8.8epss 0.00

    TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may…

  • CVE-2025-36593HigJun 30, 2025
    risk 0.57cvss 8.8epss 0.00

    Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerability in the RADIUS protocol. An attacker with local network access could potentially exploit this vulnerability to forge a valid protocol accept message in…

  • CVE-2025-25215HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.03

    An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to …

  • CVE-2025-25050HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.02

    An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can…

  • CVE-2025-24922HigJun 13, 2025
    risk 0.57cvss 8.8epss 0.03

    A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker…

  • CVE-2025-29987HigApr 3, 2025
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) versions prior to 8.3.0.15 contain an Insufficient Granularity of Access Control vulnerability. An authenticated user from a trusted remote client could exploit this vulnerability to execute arbitrary…

  • CVE-2025-24381HigMar 28, 2025
    risk 0.57cvss 8.8epss 0.01

    Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to…

  • CVE-2024-49559HigMar 17, 2025
    risk 0.57cvss 8.8epss 0.00

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2024-48013HigMar 17, 2025
    risk 0.57cvss 8.8epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2024-22461HigDec 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentially exploit this vulnerability by running any command as root, leading to gaining of root-level access and compromise of complete system.

  • CVE-2024-39576HigAug 22, 2024
    risk 0.57cvss 8.8epss 0.00

    Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.

  • CVE-2024-37140HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an OS command injection vulnerability in an admin operation. A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS…

  • CVE-2024-29176HigJun 26, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD, version(s) 8.0, 7.13.1.0, 7.10.1.30, 7.7.5.40, contain(s) an Out-of-bounds Write vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2024-25949HigJun 12, 2024
    risk 0.57cvss 8.8epss 0.00

    Dell OS10 Networking Switches, versions10.5.6.x, 10.5.5.x, 10.5.4.x and 10.5.3.x ,contain an improper authorization vulnerability. A remote authenticated attacker could potentially exploit this vulnerability leading to escalation of privileges.

  • CVE-2024-28976HigApr 24, 2024
    risk 0.57cvss 8.8epss 0.00

    Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the…

  • CVE-2024-22454HigFeb 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect Data Manager, version 19.15 and prior versions, contain a weak password recovery mechanism for forgotten passwords. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to unauthorized access to the application with…

  • CVE-2024-22433HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.01

    Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info in DP Search. A remote unauthorized unauthenticated attacker could potentially exploit this vulnerability leading to a loss of…

  • CVE-2023-44286HigDec 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a DOM-based Cross-Site Scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the injection of malicious HTML or…

  • CVE-2023-32460HigDec 8, 2023
    risk 0.57cvss 8.8epss 0.00

    Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.

  • CVE-2023-44304HigDec 4, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell DM5500 contains a privilege escalation vulnerability in the appliance. A remote attacker with low privileges could potentially exploit this vulnerability to escape the restricted shell and gain root access to the appliance.

  • CVE-2023-28055HigSep 27, 2023
    risk 0.57cvss 8.8epss 0.00

    Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client. An unauthenticated attacker within the same network could potentially exploit this by manipulating a command leading to gain of complete access to the server file further resulting…

  • CVE-2023-32465HigJun 14, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell Power Protect Cyber Recovery, contains an Authentication Bypass vulnerability. An attacker could potentially exploit this vulnerability, leading to unauthorized admin access to the Cyber Recovery application. Exploitation may lead to complete system takeover by an…

  • CVE-2023-28062HigApr 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell PPDM versions 19.12, 19.11 and 19.10, contain an improper access control vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to bypass intended access restrictions and perform unauthorized actions.

  • CVE-2022-46754HigFeb 11, 2023
    risk 0.57cvss 8.7epss 0.01

    Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.

  • CVE-2022-45104HigFeb 11, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute arbitrary commands on the underlying…

  • CVE-2022-34448HigFeb 11, 2023
    risk 0.57cvss 8.8epss 0.00

    PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains a Cross-site Request Forgery vulnerability. An unauthenticated non-privileged user could potentially exploit the issue and perform any privileged state-changing actions.

  • CVE-2022-34446HigFeb 11, 2023
    risk 0.57cvss 8.8epss 0.01

    PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration. …

  • CVE-2023-22575HigFeb 1, 2023
    risk 0.57cvss 8.7epss 0.01

    Dell PowerScale OneFS 9.0.0.x - 9.4.0.x contain an insertion of sensitive information into log file vulnerability in celog. A low privileges user could potentially exploit this vulnerability, leading to information disclosure and escalation of privileges.

  • CVE-2023-23692HigFeb 1, 2023
    risk 0.57cvss 8.8epss 0.02

    Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of…

  • CVE-2022-34456HigJan 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application.

  • CVE-2022-34427HigOct 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Dell Container Storage Modules 1.2 contains an OS Command Injection in goiscsi and gobrick libraries. A remote unauthenticated attacker could exploit this vulnerability leading to modification of intended OS command execution.

  • CVE-2022-34426HigOct 11, 2022
    risk 0.57cvss 8.8epss 0.02

    Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vulnerability leading to unintentional…

  • CVE-2022-34375HigAug 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

  • CVE-2022-34374HigAug 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Dell Container Storage Modules 1.2 contains an OS command injection in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to to execute arbitrary OS commands on the affected system.

  • CVE-2021-36328HigNov 30, 2021
    risk 0.57cvss 8.8epss 0.01

    Dell EMC Streaming Data Platform versions before 1.3 contain a SQL Injection Vulnerability. A remote malicious user may potentially exploit this vulnerability to execute SQL commands to perform unauthorized actions and retrieve sensitive information from the database.

  • CVE-2021-36307HigNov 20, 2021
    risk 0.57cvss 8.8epss 0.01

    Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability. A malicious low privileged user with specific access to the API could potentially exploit this vulnerability to gain admin privileges on the affected system.

Page 4 of 39