VulnSea

dell has 193 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 184 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 176. The median CVSS is 6.5 (medium), with 11 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-295 (23) and CWE-78 (12). Most affected products: secure_connect_gateway (89), OpenManage Server Administrator Managed Node (Patch) for Windows (19), Secure Connect Gateway 5.0 - Application (15).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
184 prev 2

Products

  • secure_connect_gateway 89
  • OpenManage Server Administrator Managed Node (Patch) for Windows 19
  • Secure Connect Gateway 5.0 - Application 15
  • policy_manager_for_secure_connect_gateway 8
  • thinos 7
  • wyse_management_suite 6
193
Total CVEs
11
Critical
0
CISA KEV
0
Exploited

dell vulnerabilities

CVEs affecting dell, newest first. Open any entry for full detail, references, and exploit status.

193 CVEsRSS

CVE-2026-56689High· 7.7
2mo ago

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit th…

▾ Twilightdell · powerflex_managerEPSS 0.37%via NVD
CVE-2026-56688Critical· 9.1
2mo ago

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exp…

▾ Midnightdell · powerflex_managerEPSS 2.0%via NVD
CVE-2026-54468Medium· 6.5
2mo ago

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.

▾ Sunlitdell · unisphere_for_powermaxEPSS 0.45%via NVD
CVE-2026-35159Medium· 5.3
2mo ago

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

▾ SunlitDell · Inspiron 15 3520EPSS 0.21%via NVD
CVE-2025-32750High· 7.5
4mo ago

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Informatio…

▾ Twilightdell · powerflex_appliance_intelligent_catalogEPSS 0.35%via NVD
CVE-2026-28265Medium· 4.4
5mo ago

PowerStore, contains a Path Traversal vulnerability in the Service user

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

▾ Sunlitdell · powerstoreosEPSS 0.16%via NVD
CVE-2025-36572Medium· 6.5
1y ago

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file

Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentiall…

▾ Sunlitdell · powerstoreosEPSS 0.31%via NVD
CVE-2024-51532High· 7.1
1y ago

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modificati…

▾ Twilightdell · powerstoreosEPSS 0.27%via NVD
CVE-2024-37129Medium· 6.7
2y ago

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.

▾ Sunlitdell · inventory_collectorEPSS 0.17%via NVD
CVE-2023-28045Medium· 6.3
3y ago

Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability

Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.

▾ Sunlitdell · aiops_collectorEPSS 0.18%via NVD
CVE-2016-6650High· 7.5
9y ago

EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.

EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.

▾ Twilightdell · recoverpoint_for_virtual_machinesEPSS 1.6%via NVD
CVE-2016-6649Medium· 6.7
9y ago

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass th…

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass th…

▾ Sunlitdell · recoverpoint_for_virtual_machinesEPSS 0.89%via NVD
CVE-2016-6648Medium· 4.4
9y ago

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file

EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A …

▾ Sunlitdell · recoverpoint_for_virtual_machinesEPSS 0.43%via NVD
dell vulnerabilities (CVEs) — page 7 · VulnSea