Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dell

First CVE: Sep 12, 2001Active for: 25 yearsTotal CVEs: 1,591
54.3
VTI Score
TOP TARGET

Dell's vulnerability footprint spans an exceptionally broad portfolio encompassing enterprise storage systems, data protection appliances, client devices, and infrastructure software, representing one of the largest and most widely deployed product ecosystems in the landscape. The exposure concentrates in flagship storage and data-management products such as PowerScale OneFS and Data Domain, alongside client platforms like the Latitude line, where vulnerabilities recur through input-handling and command-injection weakness classes that reflect the complexity of networked storage, web interfaces, and system administration paths. A meaningful share of the vendor's disclosures reach serious severity, consistent with the high-value role these products play in enterprise data environments. Defenders should prioritize storage and backup infrastructure in patch cycles and inventory assessment, as these products often occupy trusted positions in critical data workflows; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,591
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Dell over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2001
24 years ago
Most Recent CVE
Jul 15, 2026
10 days ago

Self-Reporting Analysis

Of all the CVEs published by Dell as a CNA, 70.5% affect products that Dell develops as a vendor.

70.5%
29.5%
Self-reported: 1,505 (70.5%)
Third-party: 629 (29.5%)

Of all the CVEs published that affect products developed by Dell, 94.6% are self-published by Dell as a CNA.

94.6%
Self-published: 1,505 (94.6%)
Other CNAs: 86 (5.4%)

Products(3,656 total)

Top CVEs

Signals from CVEs in this vendor scope (1591 CVEs).

1,591 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-21551HIGH
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local aut
May 4, 20217.894YESYES
CVE-2018-1207CRITICAL
Dell EMC iDRAC7/iDRAC8, versions prior to 2.52.52.52, contain CGI injection vulnerability which could be used to execute remote code. A remote unauthenticated attacker may potentia
Mar 23, 20189.890NOYES
CVE-2026-22769CRITICAL
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attack
Feb 17, 202610.081YESNO
CVE-2025-36604CRITICAL
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated att
Aug 4, 20259.879NOYES
CVE-2009-0695HIGH
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demons
Jun 19, 20127.577NOYES
CVE-2018-1217CRITICAL
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection Appliance 2.0 and 2.1, is affected by a missing access contro
Apr 9, 20189.875NOYES
CVE-2020-5377CRITICAL
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities. An unauthenticated remote attacker could potentially exploit
Jul 28, 20209.165NOYES
CVE-2022-24422CRITICAL
Dell iDRAC9 versions 5.00.00.00 and later but prior to 5.10.10.00, contain an improper authentication vulnerability. A remote unauthenticated attacker may potentially exploit this
May 26, 20229.863NONO
CVE-2020-11899MEDIUM
The Treck TCP/IP stack before 6.0.1.66 has an IPv6 Out-of-bounds Read.
Jun 17, 20205.461YESNO
CVE-2016-9682CRITICAL
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabil
Feb 22, 20179.856NOYES
View all 1,591 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,591 CVEs
44%
44%
9%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local708 (44.5%)
Network742 (46.6%)
Unknown62 (3.9%)
Physical35 (2.2%)
Adjacent Network44 (2.8%)
Attack Complexity
Low1,454 (91.4%)
High75 (4.7%)
Unknown62 (3.9%)
User Interaction
None1,386 (87.1%)
Unknown62 (3.9%)
Required143 (9.0%)
Privileges Required
Low667 (41.9%)
High434 (27.3%)
None428 (26.9%)
Unknown62 (3.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (1591 CVEs).

CISA KEV
3 CVEs
0.2% of CVEs· 99th percentile
Metasploit
3 CVEs
0.2% of CVEs· 97th percentile
Nuclei
3 CVEs
0.2% of CVEs· 95th percentile
ExploitDB
34 CVEs
2.1% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dell.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dell — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dell's Products

View all 12 CNAs →

Top CWEs