Marvell manufactures storage controllers and firmware for solid-state drives and data-center storage appliances, a moderately represented but strategically important component category that sits between enterprise systems and persistent storage. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, though the exposure does not show a pronounced tendency toward public exploit availability or confirmed in-the-wild exploitation. The recurring weakness classes center on path traversal, input validation, out-of-bounds writes, and unrestricted file uploads, typical of firmware and management-console attack surfaces where parsing logic and access boundaries are security-critical. Defenders should prioritize Marvell advisories affecting storage infrastructure, particularly the 88SS firmware family and QConverge management console, given the vendor's placement in the I/O path and the potential for supply-chain impact. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Marvell over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15643HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit | Aug 25, 2020 | 8.8 | 59 | NO | NO |
CVE-2025-6793CRITICAL Marvell QConvergeConsole QLogicDownloadImpl Directory Traversal Arbitrary File Deletion and Information Disclosure Vulnerability. This vulnerability allows remote attackers to dele | Jul 7, 2025 | 9.4 | 47 | NO | YES |
CVE-2025-8426CRITICAL Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose | Jul 31, 2025 | 9.4 | 34 | NO | NO |
CVE-2020-15645HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit | Aug 25, 2020 | 8.8 | 32 | NO | NO |
CVE-2025-6802CRITICAL Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect | Jul 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-6794CRITICAL Marvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | Jul 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2019-13581CRITICAL An issue was discovered in Marvell 88W8688 Wi-Fi firmware before version p52, as used on Tesla Model S/X vehicles manufactured before March 2018, via the Parrot Faurecia Automotive | Nov 15, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-17388HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit | Aug 25, 2020 | 8.8 | 29 | NO | NO |
CVE-2020-15644HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit | Aug 25, 2020 | 8.8 | 29 | NO | NO |
CVE-2020-15642HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is req | Aug 25, 2020 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Marvell.
Media articles that mention a CVE ID that affects a product developed by Marvell — matched by CVE ID, not by vendor name.