Vulnerabilities > Dell > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-10-17 CVE-2024-45767 Unspecified vulnerability in Dell Openmanage Enterprise 3.5/3.6.1/3.8.4
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability.
network
low complexity
dell
6.5
2024-10-09 CVE-2024-39586 XXE vulnerability in Dell EMC Appsync
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability.
low complexity
dell CWE-611
4.3
2024-09-10 CVE-2024-39574 Unspecified vulnerability in Dell Insightiq 5.1.0
Dell PowerScale InsightIQ, version 5.1, contain an Improper Privilege Management vulnerability.
local
low complexity
dell
4.4
2024-09-10 CVE-2024-39580 Unspecified vulnerability in Dell Insightiq 5.0.1/5.1.0
Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains an Improper Access Control vulnerability.
local
low complexity
dell
6.7
2024-09-10 CVE-2024-39582 Use of Hard-coded Credentials vulnerability in Dell Insightiq 5.0
Dell PowerScale InsightIQ, version 5.0, contain a Use of hard coded Credentials vulnerability.
local
low complexity
dell CWE-798
4.4
2024-09-10 CVE-2024-42425 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Dell 7920 XL Firmware and Precision 7920 Firmware
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability.
local
low complexity
dell CWE-119
5.5
2024-09-10 CVE-2024-42424 Unspecified vulnerability in Dell products
Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Improper Input Validation vulnerability.
local
low complexity
dell
6.0
2024-09-03 CVE-2024-37136 Unspecified vulnerability in Dell Path to Powerprotect 1.1/1.2
Dell Path to PowerProtect, versions 1.1, 1.2, contains an Exposure of Private Personal Information to an Unauthorized Actor vulnerability.
network
low complexity
dell
4.9
2024-08-31 CVE-2024-39578 Link Following vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.1 contains a UNIX symbolic link (symlink) following vulnerability.
local
low complexity
dell CWE-59
6.3
2024-08-31 CVE-2024-39579 Unspecified vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contains an incorrect privilege assignment vulnerability.
local
low complexity
dell
6.7