Vulnerabilities in Dell

1,730 results
Vexday analysis

Com 1.414 CVEs catalogadas, a Dell apresenta um volume expressivo de vulnerabilidades, com 64 classificadas como críticas e 103 surgidas apenas nos últimos 90 dias, o que indica um ritmo contínuo de descobertas que exige acompanhamento próximo. A taxa de exploração ativa está abaixo da média geral do catálogo, com apenas 2 entradas no CISA KEV, sugerindo que, apesar do volume, a conversão em ameaças ativas confirmadas é relativamente contida. A falha mais comum é do tipo CWE-78 (injeção de comandos no SO), categoria que historicamente representa risco elevado de execução arbitrária de código. A CVE mais crítica atualmente em exploração ativa, CVE-2021-21551, registra EPSS de 0,5747 — indicando probabilidade relevante de exploração — e deve ser tratada com prioridade máxima por equipes que ainda não aplicaram a respectiva correção.

CVE-2023-28039MEDIUM Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator privileges may potenEPSS 0.2%CVE-2025-43913MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.2%CVE-2022-34386MEDIUM Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographEPSS 0.2%CVE-2025-23376LOWDell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in EPSS 0.2%CVE-2026-79970MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper VerificaEPSS 0.2%CVE-2023-32471MEDIUMDell Edge Gateway BIOS, versions 3200 and 5200, contains an out-of-bounds read vulnerability. A local authenticated malicious user with highEPSS 0.2%CVE-2023-39251MEDIUM Dell BIOS contains an Improper Input Validation vulnerability. A local malicious user with high privileges could potentially exploit this vEPSS 0.2%CVE-2026-59913HIGHDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulneraEPSS 0.2%CVE-2022-34390HIGHDell BIOS contains a use of uninitialized variable vulnerability. A local authenticated malicious user may potentially exploit this vulnerabEPSS 0.2%CVE-2022-34377LOW Dell PowerEdge BIOS and Dell Precision BIOS contain an Improper SMM communication buffer verification vulnerability. A local malicious usEPSS 0.2%CVE-2022-34391HIGHDell Client BIOS Versions prior to the remediated version contain an improper input validation vulnerability. A local authenticated maliciouEPSS 0.2%CVE-2024-52541HIGHDell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploEPSS 0.2%CVE-2023-28047HIGH Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local loEPSS 0.2%CVE-2021-21559HIGHDell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation vulnerability in theEPSS 0.2%CVE-2024-48016MEDIUMDell Secure Connect Gateway (SCG) 5.0 Appliance - SRS, version(s) 5.24, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerabEPSS 0.2%CVE-2022-34403HIGH Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerabilityEPSS 0.2%CVE-2026-23861MEDIUMDell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Input During Web Page Generation ('Cross-siteEPSS 0.2%CVE-2025-21102HIGHDell VxRail, versions 7.0.000 through 7.0.532, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with lEPSS 0.2%CVE-2024-48831HIGHDell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker withEPSS 0.2%CVE-2026-22767HIGHDell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local accEPSS 0.2%