Dell's vulnerability footprint spans an exceptionally broad portfolio encompassing enterprise storage systems, data protection appliances, client devices, and infrastructure software, representing one of the largest and most widely deployed product ecosystems in the landscape. The exposure concentrates in flagship storage and data-management products such as PowerScale OneFS and Data Domain, alongside client platforms like the Latitude line, where vulnerabilities recur through input-handling and command-injection weakness classes that reflect the complexity of networked storage, web interfaces, and system administration paths. A meaningful share of the vendor's disclosures reach serious severity, consistent with the high-value role these products play in enterprise data environments. Defenders should prioritize storage and backup infrastructure in patch cycles and inventory assessment, as these products often occupy trusted positions in critical data workflows; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dell over time
Of all the CVEs published by Dell as a CNA, 70.5% affect products that Dell develops as a vendor.
Of all the CVEs published that affect products developed by Dell, 94.6% are self-published by Dell as a CNA.
Signals from CVEs in this vendor scope (1591 CVEs).
1,591 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21551HIGH Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local aut | May 4, 2021 | 7.8 | 94 | YES | YES |
CVE-2018-1207CRITICAL Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentia | Mar 23, 2018 | 9.8 | 90 | NO | YES |
CVE-2026-22769CRITICAL Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attack | Feb 17, 2026 | 10.0 | 81 | YES | NO |
CVE-2025-36604CRITICAL Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated att | Aug 4, 2025 | 9.8 | 79 | NO | YES |
CVE-2009-0695HIGH hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demons | Jun 19, 2012 | 7.5 | 77 | NO | YES |
CVE-2018-1217CRITICAL Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access contro | Apr 9, 2018 | 9.8 | 75 | NO | YES |
CVE-2020-5377CRITICAL Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit | Jul 28, 2020 | 9.1 | 65 | NO | YES |
CVE-2022-24422CRITICAL Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this | May 26, 2022 | 9.8 | 63 | NO | NO |
CVE-2020-11899MEDIUM The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read. | Jun 17, 2020 | 5.4 | 61 | YES | NO |
CVE-2016-9682CRITICAL The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabil | Feb 22, 2017 | 9.8 | 56 | NO | YES |
Signals from CVEs in this vendor scope (1591 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dell.
Media articles that mention a CVE ID that affects a product developed by Dell — matched by CVE ID, not by vendor name.