CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

dell

unisphere_for_powermax

12 known vulnerabilities · sorted by CVSS score

CVE-2026-26359
HIGH8.8

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files.

dell / unisphere_for_powermax+1
Network
Published Feb 19, 2026
CVE-2025-36588
HIGH8.8

Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

dell / unisphere_for_powermax+1
Network
Published Jan 22, 2026
CVE-2026-26358
HIGH8.8

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

dell / unisphere_for_powermax+1
Network
Published Feb 19, 2026
CVE-2026-26360
HIGH8.1

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to delete arbitrary files.

dell / unisphere_for_powermax+1
Network
Published Feb 19, 2026
CVE-2026-26362
HIGH8.1

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical system files.

dell / unisphere_for_powermax+1
Network
Published Feb 19, 2026
CVE-2021-21531
HIGH8.1

Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticated malicious user with monitor role may exploit this vulnerability to perform unauthorized actions.

dell / solutions_enabler+8
Network
Published Apr 30, 2021
CVE-2021-36339
HIGH7.8

The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentially exploit this vulnerability to get privileged access to the virtual appliance.

dell / solutions_enabler+12
Local
Published Jan 21, 2022
CVE-2025-36589
HIGH7.6

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.

dell / unisphere_for_powermax+1
Network
Published Jan 6, 2026
CVE-2026-26361
MEDIUM6.5

Dell Unisphere for PowerMax, version(s) 10.2, contain(s) an External Control of File Name or Path vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

dell / unisphere_for_powermax+1
Network
Published Feb 19, 2026
CVE-2021-36338
MEDIUM6.3

Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious user could potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to. CVE-2022-31233 addresses the partial fix in CVE-2021-36338.

dell / solutions_enabler+12
Adjacent
Published Jan 21, 2022
CVE-2022-31233
MEDIUM6.3

Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An adjacent malicious user may potentially exploit this vulnerability to escalate their privileges and access functionalities they do not have access to.

dell / evasa_provider_virtual_appliance+7
Adjacent
Published Aug 31, 2022
CVE-2025-27686
LOW2.7

Dell Unisphere for PowerMax, version(s) prior to 10.2.0.9 and PowerMax version(s) prior to PowerMax 9.2.4.15, contain an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

dell / unisphere_for_powermax+1
Network
Published Apr 7, 2025