dell has 193 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 184 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 176. The median CVSS is 6.5 (medium), with 11 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-295 (23) and CWE-78 (12). Most affected products: secure_connect_gateway (89), OpenManage Server Administrator Managed Node (Patch) for Windows (19), Secure Connect Gateway 5.0 - Application (15).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 184 prev 2
Weakness classes
Products
- secure_connect_gateway 89
- OpenManage Server Administrator Managed Node (Patch) for Windows 19
- Secure Connect Gateway 5.0 - Application 15
- policy_manager_for_secure_connect_gateway 8
- thinos 7
- wyse_management_suite 6
Worst active — by depth score
CVE-2026-70416Critical· 10.0Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability55CVE-2026-63695Critical· 9.8Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability54CVE-2026-81467Critical· 9.8Dell ThinOS 10, versions prior to 2605_1054CVE-2026-80172Critical· 9.8Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability54CVE-2026-81048Critical· 9.6Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability53
dell vulnerabilities
CVEs affecting dell, newest first. Open any entry for full detail, references, and exploit status.
193 CVEsRSS
CVE-2026-56689High· 7.7Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit th…
CVE-2026-56688Critical· 9.1Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability
Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exp…
CVE-2026-54468Medium· 6.5Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.
CVE-2026-35159Medium· 5.3Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability
Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
CVE-2025-32750High· 7.5Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability
Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Informatio…
CVE-2026-28265Medium· 4.4PowerStore, contains a Path Traversal vulnerability in the Service user
PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
CVE-2025-36572Medium· 6.5Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in the PowerStore image file. A low privileged attacker with remote access, with the knowledge of the hard-coded credentials, could potentiall…
CVE-2024-51532High· 7.1Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modificati…
CVE-2024-37129Medium· 6.7Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability
Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.
CVE-2023-28045Medium· 6.3Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability
Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could potentially exploit this vulnerability, leading to gain access to unauthorized data.
CVE-2016-6650High· 7.5EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.
EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint for Virtual Machines versions prior to 5.0 have an SSL Stripping Vulnerability that may potentially be exploited by malicious users to compromise the affected system.
CVE-2016-6649Medium· 6.7EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass th…
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass th…
CVE-2016-6648Medium· 4.4EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A …