Vulnerability index

Browse CVEs

1,383 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Recoverpoint For Virtual Machines HIGH 7.8
CVE-2025-21105

Dell RecoverPoint for Virtual Machines 6.0.X contains a command execution vulnerability. A Low privileged malicious user with local access could pote…

Mitigation only
Fix from $1,950 2025-02-20
Recoverpoint For Virtual Machines MEDIUM 5.5
CVE-2025-21106

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially…

Mitigation only
Fix from $1,600 2025-02-20
Alienware M15 R6 Firmware HIGH 8.2
CVE-2024-52541

Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this v…

Fix: 1.8.0 / 1.21.0+
Fix from $1,950 2025-02-19
Networker HIGH 7.8
CVE-2025-21103

Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improper neutralization of server-s…

Fix: 19.10.0.7+
Fix from $1,950 2025-02-17
Supportassist Os Recovery HIGH 7.8
CVE-2025-22480

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access c…

Fix: 5.5.13.1+
Fix from $1,950 2025-02-13
Bsafe Ssl J HIGH 7.5
CVE-2024-29171

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains an Improper certificate verification vulnerability. A remote attacker …

Fix: 6.6 / 7.2.1+
Fix from $1,950 2025-02-12
Bsafe Ssl J HIGH 7.5
CVE-2024-29172

Dell BSAFE SSL-J, versions prior to 6.6 and versions 7.0 through 7.2, contains a deadlock vulnerability. A remote attacker could potentially exploit …

Fix: 6.6 / 7.2.1+
Fix from $1,950 2025-02-12
Utility Configuration Collector Edge HIGH 7.8
CVE-2025-22399

Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could po…

Patch available
Fix from $1,950 2025-02-11
Update Manager Plugin MEDIUM 5.4
CVE-2025-22402

Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XS…

Fix: 1.7.0+
Fix from $1,600 2025-02-07
Avamar Server MEDIUM 5.5
CVE-2025-21117

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploi…

Mitigation only
Fix from $1,600 2025-02-05
Data Domain Operating System HIGH 7.5
CVE-2025-22475

Dell PowerProtect DD, versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.10 contains a use of a Cryptographic Primitive with a Risky Implementatio…

Fix: 7.10.1.50 / 7.13.1.10+
Fix from $1,950 2025-02-04
Data Domain Operating System HIGH 7.8
CVE-2024-53295

Dell PowerProtect DD versions prior to 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain an improper access control vulnerability. A local malicious user wit…

Fix: 7.10.1.50 / 7.13.1.20+
Fix from $1,950 2025-02-01
Data Domain Operating System HIGH 7.1
CVE-2024-51534

Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path traversal vulnerability. A local low privileged could po…

Fix: 7.10.1.50 / 7.13.1.20+
Fix from $1,950 2025-02-01
Networker HIGH 7.8
CVE-2025-21107

Dell NetWorker, version(s) prior to 19.11.0.3, all versions of 19.10 & prior versions contain(s) an Unquoted Search Path or Element vulnerability. A …

Fix: 19.11.0.3+
Fix from $1,950 2025-01-30
Display Manager HIGH 7.0
CVE-2025-22394

Dell Display Manager, versions prior to 2.3.2.18, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacke…

Fix: 2.3.2.20+
Fix from $1,950 2025-01-15
Display Manager MEDIUM 6.3
CVE-2025-21101

Dell Display Manager, versions prior to 2.3.2.20, contain a race condition vulnerability. A local malicious user could potentially exploit this vulne…

Fix: 2.3.2.20+
Fix from $1,600 2025-01-15
Powerscale Onefs MEDIUM 6.5
CVE-2024-47239

Dell PowerScale OneFS versions 8.2.2.x through 9.9.0.0 contain an uncontrolled resource consumption vulnerability. A remote low privileged attacker c…

Fix: 9.4.0.20 / 9.5.1.2+
Fix from $1,600 2025-01-08
Update Package Framework HIGH 7.8
CVE-2025-22395

Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker cou…

Fix: 22.01.02+
Fix from $1,950 2025-01-07
Powerscale Onefs MEDIUM 5.5
CVE-2024-47475

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticate…

Fix: 9.4.0.20+
Fix from $1,600 2025-01-06
Elastic Cloud Storage MEDIUM 6.5
CVE-2024-51540

Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user w…

Fix: 3.8.1.3+
Fix from $1,600 2024-12-26
Elastic Cloud Storage MEDIUM 5.4
CVE-2024-52534

Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote…

Fix: 3.8.1.3+
Fix from $1,600 2024-12-25
Supportassist For Business Pcs HIGH 8.8
CVE-2024-52535

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (s…

Fix: 4.5.1 / 4.6.2+
Fix from $1,950 2024-12-25
Nativeedge Orchestrator HIGH 7.5
CVE-2024-53291

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with…

Fix: 2.2.0.0+
Fix from $1,950 2024-12-25
Nativeedge Orchestrator HIGH 7.8
CVE-2024-47978

Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access c…

Fix: 2.2.0.0+
Fix from $1,950 2024-12-25
Powerstoreos HIGH 7.1
CVE-2024-51532

Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attack…

Fix: 4.0.1.0-2408234+
Fix from $1,950 2024-12-19
Inventory Collector HIGH 7.8
CVE-2024-47480

Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege att…

Fix: 12.7.0+
Fix from $1,950 2024-12-18
Appsync MEDIUM 5.5
CVE-2024-52542

Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potential…

Fix: 4.6.0.3+
Fix from $1,600 2024-12-17
Recoverpoint For Virtual Machines MEDIUM 6.5
CVE-2024-47984

Dell RecoverPoint for Virtual Machines 6.0.x contains Denial of Service vulnerability. A User with Remote access could potentially exploit this vulne…

Mitigation only
Fix from $1,600 2024-12-13
Recoverpoint For Virtual Machines CRITICAL 9.8
CVE-2024-28980

Dell RecoverPoint for VMs, version(s) 6.0.x contain(s) a Use of a Broken or Risky Cryptographic Algorithm vulnerability in the SSH. An unauthenticate…

Mitigation only
Fix from $2,300 2024-12-13
Recoverpoint For Virtual Machines MEDIUM 5.5
CVE-2024-24902

Dell RecoverPoint for Virtual Machines 6.0.x contains an Improper access control vulnerability. A low privileged local attacker could potentially exp…

Mitigation only
Fix from $1,600 2024-12-13