Dell Security Vulnerabilities (CVEs)

Track 469 security vulnerabilities affecting Dell products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

40 Critical
283 High
143 Medium
3 Low
🔔 Get Alerts for Dell
CVE-2026-26949 5.5

Dell Device Management Agent (DDMA) versions before 26.02 contain an incorrect authorization vulnerability that allows local low-privileged attackers ...

Mar 4, 2026
CVE-2026-25907 5.3

Dell PowerScale OneFS version 9.13.0.0 has an overly restrictive account lockout mechanism that allows unauthenticated remote attackers to trigger acc...

Mar 4, 2026
CVE-2026-21423 6.7

Dell PowerScale OneFS has an incorrect default permissions vulnerability that allows high-privileged local attackers to execute arbitrary code, cause ...

Mar 4, 2026
CVE-2026-21425 6.7

Dell PowerScale OneFS contains an incorrect privilege assignment vulnerability that allows local low-privileged attackers to elevate their privileges....

Mar 4, 2026
CVE-2026-22270 6.7

Dell PowerScale OneFS contains an uncontrolled search path vulnerability that allows high-privileged local attackers to execute arbitrary code by mani...

Mar 4, 2026
CVE-2026-21421 6.7

Dell PowerScale OneFS contains a privilege escalation vulnerability where high-privileged local attackers can execute code with unnecessary privileges...

Mar 4, 2026
CVE-2026-24502 8.8

Dell Command | Intel vPro Out of Band versions before 4.7.0 have a path traversal vulnerability that allows local low-privileged attackers to execute ...

Mar 3, 2026
CVE-2026-23858 5.4

Dell Wyse Management Suite versions before 5.5 contain a cross-site scripting (XSS) vulnerability that allows low-privileged remote attackers to injec...

Feb 24, 2026
CVE-2026-22765 8.8

Dell Wyse Management Suite versions before 5.5 have a missing authorization vulnerability that allows low-privileged remote attackers to elevate their...

Feb 24, 2026
CVE-2026-21420 7.3

Dell Repository Manager versions before 3.4.8 have a path traversal vulnerability where attackers with local access can execute arbitrary code and esc...

Feb 23, 2026
CVE-2026-22266 4.7

Dell PowerProtect Data Manager versions before 19.22 have a REST API vulnerability where improper verification of communication channels allows high-p...

Feb 19, 2026
CVE-2026-22267 8.1

Dell PowerProtect Data Manager versions before 19.22 have an incorrect privilege assignment vulnerability that allows low-privileged remote attackers ...

Feb 19, 2026
CVE-2026-26362 8.1

Dell Unisphere for PowerMax version 10.2 contains a relative path traversal vulnerability that allows low-privileged remote attackers to modify critic...

Feb 19, 2026
CVE-2026-26358 8.8

Dell Unisphere for PowerMax versions 10.2 contain a missing authorization vulnerability that allows low-privileged remote attackers to gain unauthoriz...

Feb 19, 2026
CVE-2026-26360 8.1

Dell Unisphere for PowerMax version 10.2 contains a path traversal vulnerability that allows low-privileged remote attackers to delete arbitrary files...

Feb 19, 2026
CVE-2026-22269 4.7

Dell PowerProtect Data Manager versions before 19.22 have a REST API vulnerability where improper verification of communication channels allows high-p...

Feb 19, 2026
CVE-2026-22769 10.0

Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 HF1 contain hardcoded credentials that allow unauthenticated remote attackers to gain r...

Feb 17, 2026
CVE-2026-22284 6.6

Dell SmartFabric OS10 Software contains a command injection vulnerability that allows authenticated high-privileged attackers to execute arbitrary com...

Feb 17, 2026
CVE-2026-23857 8.2

This vulnerability in Dell Update Package (DUP) Framework allows low-privileged local attackers to elevate their privileges to higher levels. It affec...

Feb 12, 2026
CVE-2026-22764 4.3

Dell OpenManage Network Integration versions before 3.9 have an improper authentication vulnerability that allows low-privileged remote attackers to a...

Jan 29, 2026
CVE-2026-21417 7.0

Dell CloudBoost Virtual Appliance versions before 19.14.0.0 store passwords in plaintext, allowing attackers with remote access and high privileges to...

Jan 27, 2026
CVE-2026-22273 8.8

Dell ECS and ObjectScale systems contain default credentials that allow low-privileged attackers with remote access to elevate privileges. This affect...

Jan 23, 2026
CVE-2026-22274 6.5

Dell ECS and ObjectScale systems transmit sensitive information in cleartext via Fabric Syslog, allowing unauthenticated attackers with network access...

Jan 23, 2026
CVE-2026-22275 4.4

Dell ECS and ObjectScale contain sensitive information in source code that could be exposed to local low-privileged attackers. This vulnerability affe...

Jan 23, 2026
CVE-2026-22276 5.5

Dell ECS and ObjectScale store sensitive information in cleartext, allowing local low-privileged attackers to read confidential data. This affects Del...

Jan 23, 2026
CVE-2025-46699 4.3

Dell Data Protection Advisor versions before 19.12 contain a template engine injection vulnerability that allows low-privileged remote attackers to ac...

Jan 23, 2026
CVE-2026-22271 7.5

Dell ECS and ObjectScale systems transmit sensitive information without encryption, allowing unauthenticated remote attackers to intercept and read th...

Jan 23, 2026
CVE-2026-22281 3.5

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Dell PowerScale OneFS allows low-privileged attackers with adjacent network acces...

Jan 22, 2026
CVE-2026-22280 5.0

Dell PowerScale OneFS contains an incorrect permission assignment vulnerability that allows low-privileged local attackers to cause denial of service....

Jan 22, 2026
CVE-2026-22279 4.3

Dell PowerScale OneFS versions before 9.13.0.0 have an insufficient logging vulnerability that allows unauthenticated remote attackers to potentially ...

Jan 22, 2026
CVE-2026-22278 8.1

Dell PowerScale OneFS versions before 9.13.0.0 have a vulnerability where attackers can bypass authentication rate limiting. Unauthenticated remote at...

Jan 22, 2026
CVE-2025-36588 8.8

This SQL injection vulnerability in Dell Unisphere for PowerMax allows low-privileged remote attackers to execute arbitrary commands on affected syste...

Jan 22, 2026
CVE-2025-46685 7.5

Dell SupportAssist OS Recovery versions before 5.5.15.1 create temporary files with insecure permissions, allowing local low-privileged attackers to m...

Jan 13, 2026
CVE-2025-46684 6.6

Dell SupportAssist OS Recovery versions before 5.5.15.1 create temporary files with insecure permissions, allowing local low-privileged attackers to m...

Jan 13, 2026
CVE-2025-46645 6.5

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...

Jan 9, 2026
CVE-2025-46643 2.3

A heap-based buffer overflow vulnerability in Dell PowerProtect Data Domain with DD OS allows high-privileged attackers with local access to cause den...

Jan 9, 2026
CVE-2025-46644 6.0

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access could ...

Jan 9, 2026
CVE-2025-46676 2.7

Dell PowerProtect Data Domain systems running affected DD OS versions contain an information disclosure vulnerability. A high-privileged attacker with...

Jan 9, 2026
CVE-2025-36589 7.6

This XXE vulnerability in Dell Unisphere for PowerMax allows low-privileged remote attackers to access unauthorized data and resources by exploiting i...

Jan 6, 2026
CVE-2025-46636 6.6

Dell Encryption versions before 11.12.1 contain a link following vulnerability that allows local low-privileged attackers to manipulate symbolic links...

Dec 9, 2025
CVE-2025-46637 7.3

Dell Encryption versions before 11.12.1 contain a link-following vulnerability that allows local attackers to escalate privileges. This affects system...

Dec 9, 2025
CVE-2025-46603 7.0

Dell CloudBoost Virtual Appliance versions 19.13.0.0 and earlier have a vulnerability that allows attackers to bypass authentication rate limiting. Un...

Dec 5, 2025
CVE-2025-46369 7.8

Dell Alienware Command Center versions before 6.10.15.0 have an insecure temporary file vulnerability that allows local low-privileged attackers to es...

Nov 13, 2025
CVE-2025-46362 6.6

Dell Alienware Command Center versions before 6.10.15.0 have an improper access control vulnerability that allows local low-privileged attackers to ta...

Nov 13, 2025
CVE-2025-46367 7.8

Dell Alienware Command Center versions before 6.10.15.0 contain a vulnerability where error conditions are detected but not properly handled. A local ...

Nov 13, 2025
CVE-2025-46608 9.1

Dell Data Lakehouse versions before 1.6.0.0 have an improper access control vulnerability that allows high-privileged attackers with remote access to ...

Nov 12, 2025
CVE-2025-46427 8.8

Dell SmartFabric OS10 Software versions before 10.6.1.0 contain a command injection vulnerability that allows low-privileged remote attackers to execu...

Nov 12, 2025
CVE-2025-46428 8.8

Dell SmartFabric OS10 Software contains a command injection vulnerability that allows low-privileged remote attackers to execute arbitrary code on aff...

Nov 12, 2025
CVE-2024-48829 6.7

This vulnerability allows a high-privileged attacker with local access to Dell SmartFabric OS10 switches to execute arbitrary code through improper in...

Nov 12, 2025
CVE-2025-43723 5.9

Dell PowerScale OneFS contains a broken cryptographic algorithm vulnerability that allows unauthenticated remote attackers to potentially access sensi...

Nov 10, 2025

Why Monitor Dell Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 469+ known vulnerabilities affecting Dell products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Dell packages in under 60 seconds. No agents required - completely agentless scanning that works across Dell deployments.

Free vulnerability database: Access detailed information about every Dell CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Dell CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Dell CVEs Free