VYPR

OneView

by HPE

CVEs (29)

  • CVE-2025-37164CriKEVDec 16, 2025
    risk 0.87cvss 10.0epss 0.90

    A remote code execution issue exists in HPE OneView.

  • CVE-2024-22442CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The vulnerability could be remotely exploited to bypass authentication.

  • CVE-2023-30909CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A remote authentication bypass issue exists in some OneView APIs.

  • CVE-2023-30908CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in a OneView API.

  • CVE-2022-28616CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-28617CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2020-7198HigNov 6, 2020
    risk 0.57cvss 8.8epss 0.02

    There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

  • CVE-2026-76719HigSep 29, 2026
    risk 0.53cvss 8.2epss 0.00

    A security vulnerability in HPE OneView may be exploited remotely to perform session hijacking, data theft or other unauthorized actions.

  • CVE-2026-76718HigSep 29, 2026
    risk 0.53cvss 8.2epss 0.00

    A potential security vulnerability in HPE OneView can be exploited to allow remote session hijacking or other unauthorized actions.

  • CVE-2023-50274HigJan 23, 2024
    risk 0.51cvss 7.8epss 0.01

    HPE OneView may allow command injection with local privilege escalation.

  • CVE-2023-28088HigApr 25, 2023
    risk 0.51cvss 7.8epss 0.00

    An HPE OneView appliance dump may expose SAN switch administrative credentials

  • CVE-2022-23699HigApr 4, 2022
    risk 0.51cvss 7.8epss 0.00

    A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2023-50275HigJan 23, 2024
    risk 0.49cvss 7.5epss 0.01

    HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

  • CVE-2022-23698HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2023-30912HigOct 25, 2023
    risk 0.47cvss 7.2epss 0.01

    A remote code execution issue exists in HPE OneView.

  • CVE-2023-28089HigApr 25, 2023
    risk 0.46cvss 7.1epss 0.00

    An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules

  • CVE-2026-23596MedFeb 17, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the management API of the affected product could allow an unauthenticated remote attacker to trigger service restarts. Successful exploitation could allow an attacker to disrupt services and negatively impact system availability.

  • CVE-2022-23706MedMay 17, 2022
    risk 0.40cvss 6.1epss 0.01

    A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-23697MedApr 4, 2022
    risk 0.40cvss 6.1epss 0.01

    A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2024-42508MedOct 18, 2024
    risk 0.36cvss 5.5epss 0.00

    This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

Page 1 of 2

VYPR — Vulnerability Intelligence