Dell

First CVE: Apr 15, 2009Active for: 17 years
2,134
CVEs Published
More CVEs Published than 93% of tracked CNAs
118.6
Avg CVEs / Year
More Avg CVEs / Year than 91% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 79% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Dell as a CNA, 70.5% affect products that Dell develops as a vendor.

70.5%
29.5%
Self-reported: 1,505Third-party: 629

Of all the CVEs published that affect products developed by Dell, 94.6% are self-published by Dell as a CNA.

94.6%
Self-published: 1,505Published by other CNAs: 86

Trends Over Time

The number and severity of CVEs published by Dell over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 15, 2009
17 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Dell as a CNA, regardless of affected vendor or product.

2,134 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of s
Apr 11, 20189.898YESYES
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local aut
May 4, 20217.895YESYES
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentia
Mar 23, 20189.890NOYES
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arb
May 6, 20196.588NOYES
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.
Jan 4, 20189.888NOYES
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attack
Feb 17, 202610.081YESNO
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spri
May 25, 20178.881NOYES
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary comm
Feb 10, 201110.080NOYES
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated att
Aug 4, 20259.879NOYES
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access contro
Apr 9, 20189.875NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA2,134 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local753 (35.3%)
Network1,048 (49.1%)
Unknown249 (11.7%)
Physical39 (1.8%)
Adjacent Network45 (2.1%)
Attack Complexity
Low1,762 (82.6%)
High123 (5.8%)
Unknown249 (11.7%)
User Interaction
None1,653 (77.5%)
Unknown249 (11.7%)
Required232 (10.9%)
Privileges Required
Low805 (37.7%)
High468 (21.9%)
None612 (28.7%)
Unknown249 (11.7%)

Exploit Exposure

Signals from CVEs in this cna scope (2134 CVEs).

CISA KEV
3 CVEs
0.1% of CVEs· 79th percentile
Metasploit
6 CVEs
0.3% of CVEs· 80th percentile
Nuclei
8 CVEs
0.4% of CVEs· 73rd percentile
ExploitDB
37 CVEs
1.7% of CVEs· 87th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Dell as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Dell as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs