VYPR

Vendor CVEs

HPE

All CVEs

938 total · sorted by risk
  • CVE-2026-23593HigJan 27, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the web-based management interface of HPE Aruba Networking Fabric Composer could allow an unauthenticated remote attacker to view some system files. Successful exploitation could allow an attacker to read files within the affected directory.

  • CVE-2025-37166HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability affecting HPE Networking Instant On Access Points has been identified where a device processing a specially crafted packet could enter a non-responsive state, in some cases requiring a hard reset to re-establish services. A malicious actor could leverage this…

  • CVE-2025-37165HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the router mode configuration of HPE Instant On Access Points exposed certain network configuration details to unintended interfaces. A malicious actor could gain knowledge of internal network configuration details through inspecting impacted packets.

  • CVE-2025-37161HigNov 18, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacker to cause a denial of service. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention…

  • CVE-2025-37125HigSep 16, 2025
    risk 0.49cvss 7.5epss 0.00

    A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

  • CVE-2025-37105HigJul 16, 2025
    risk 0.49cvss 7.5epss 0.01

    An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

  • CVE-2024-51770HigJul 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

  • CVE-2024-51769HigJul 14, 2025
    risk 0.49cvss 7.5epss 0.00

    An information disclosure vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.

  • CVE-2025-37097HigJul 1, 2025
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service

  • CVE-2024-6206HigJun 25, 2024
    risk 0.49cvss 7.5epss 0.00

    A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could execute arbitrary commands with the privilege of the underlying container leading to complete takeover of the…

  • CVE-2023-50275HigJan 23, 2024
    risk 0.49cvss 7.5epss 0.01

    HPE OneView may allow clusterService Authentication Bypass resulting in denial of service.

  • CVE-2023-50272HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability could be remotely exploited to allow authentication bypass.

  • CVE-2023-30906HigJul 18, 2023
    risk 0.49cvss 7.5epss 0.00

    The vulnerability could be locally exploited to allow escalation of privilege.

  • CVE-2022-28621HigJun 28, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote disclosure of sensitive information vulnerability was discovered in HPE NonStop DSM/SCM version: T6031H03^ADP. HPE has provided a software update to resolve this vulnerability in HPE NonStop DSM/SCM.

  • CVE-2022-28622HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in HPE StoreOnce Software. The SSH server supports weak key exchange algorithms which could lead to remote unauthorized access. HPE has made the following software update to resolve the vulnerability in HPE StoreOnce…

  • CVE-2022-23705HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays, and HPE Nimble Storage Secondary Flash Arrays which could potentially allow the upload, but not execution, of unauthorized update binaries to the array.…

  • CVE-2022-23704HigMay 9, 2022
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service. The vulnerability is resolved in Integrated Lights-Out 4 (iLO 4) 2.80 and later.

  • CVE-2022-23703HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays during update. This would potentially allow an attacker to intercept and modify network communication for…

  • CVE-2021-41004HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote vulnerability was discovered in Aruba Instant On 1930 Switch Series version(s): Firmware below v1.0.7.0.

  • CVE-2022-23698HigApr 4, 2022
    risk 0.49cvss 7.5epss 0.01

    A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-26586HigAug 5, 2021
    risk 0.49cvss 7.5epss 0.02

    A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates…

  • CVE-2021-26578HigMar 22, 2021
    risk 0.49cvss 7.5epss 0.01

    A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.

  • CVE-2020-24625HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Unathenticated directory traversal in the ReceiverServlet class doGet() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.

  • CVE-2020-24624HigSep 23, 2020
    risk 0.49cvss 7.5epss 0.02

    Unathenticated directory traversal in the DownloadServlet class execute() method can lead to arbitrary file reads in HPE Pay Per Use (PPU) Utility Computing Service (UCS) Meter version 1.9.

  • CVE-2020-7130HigMar 4, 2020
    risk 0.49cvss 7.5epss 0.02

    HPE OneView Global Dashboard (OVGD) 1.9 has a remote information disclosure vulnerability. HPE OneView Global Dashboard - After Upgrade or Install of OVGD Version 1.9, Appliance Firewall May Leave Ports Open. This is resolved in OVGD 1.91 or later.

  • CVE-2019-11993HigJan 3, 2020
    risk 0.49cvss 7.5epss 0.02

    A security vulnerability has been identified in HPE SimpliVity 380 Gen 9, HPE SimpliVity 380 Gen 10, HPE SimpliVity 380 Gen 10 G, HPE SimpliVity 2600 Gen 10, SimpliVity OmniCube, SimpliVity OmniStack for Cisco, SimpliVity OmniStack for Lenovo and SimpliVity OmniStack for Dell…

  • CVE-2019-11995HigDec 18, 2019
    risk 0.49cvss 7.5epss 0.02

    Security vulnerabilities in HPE UIoT version 1.2.4.2 could allow unauthorized remote access and access to sensitive data. HPE has addressed this issue in HPE UIoT: For customers with release UIoT 1.2.4.2 fixes are made available with 1.2.4.2 RP3 HF1. For customers with release…

  • CVE-2019-8936HigMay 15, 2019
    risk 0.49cvss 7.5epss 0.06

    NTP through 4.2.8p12 has a NULL Pointer Dereference.

  • CVE-2018-7102HigSep 27, 2018
    risk 0.49cvss 7.5epss 0.03

    A security vulnerability in HPE Intelligent Management Center (iMC) PLAT E0506P09, createFabricAutoCfgFile could be remotely exploited via directory traversal to allow remote arbitrary file modification.

  • CVE-2018-7101HigSep 27, 2018
    risk 0.49cvss 7.5epss 0.07

    A potential remote denial of service security vulnerability has been identified in HPE Integrated Lights Out 4 prior to v2.60 and iLO 5 for Gen 10 servers prior to v1.30.

  • CVE-2018-7077HigAug 14, 2018
    risk 0.49cvss 7.5epss 0.02

    A security vulnerability in HPE XP P9000 Command View Advanced Edition (CVAE) Device Manager (DevMgr 8.5.0-00 and prior to 8.6.0-00), Configuration Manager (CM 8.5.0-00 and prior to 8.6.0-00) could be exploited to allow local and remote unauthorized access to sensitive…

  • CVE-2018-7069HigAug 6, 2018
    risk 0.49cvss 7.5epss 0.02

    HPE has identified a remote unauthenticated access to files vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

  • CVE-2017-9003HigAug 6, 2018
    risk 0.49cvss 7.5epss 0.04

    Multiple memory corruption flaws are present in ArubaOS which could allow an unauthenticated user to crash ArubaOS processes. With sufficient time and effort, it is possible these vulnerabilities could lead to the ability to execute arbitrary code - remote code execution has not…

  • CVE-2018-7185HigMar 6, 2018
    risk 0.49cvss 7.5epss 0.09

    The protocol engine in ntp 4.2.6 before 4.2.8p11 allows a remote attackers to cause a denial of service (disruption) by continually sending a packet with a zero-origin timestamp and source IP address of the "other side" of an interleaved association causing the victim ntpd to…

  • CVE-2017-5812HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.05

    A remote sql information disclosure vulnerability in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

  • CVE-2017-5803HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.07

    A Remote Disclosure of Information vulnerability in HPE NonStop Servers using SSH Service version L series: T0801L02 through T0801L02^ABX; J and H series: T0801H01 through T0801H01^ACA was found.

  • CVE-2017-5801HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.06

    A Remote Unauthorized Access to Data vulnerability in HPE Business Process Monitor version v09.2x, v09.30 was found.

  • CVE-2017-5797HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.05

    A Remote Unauthenticated Disclosure of Information vulnerability in HPE Intelligent Management Center (IMC) SOM version v7.3 (E0501) was found.

  • CVE-2017-12545HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.07

    A remote denial of service vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2016-8525HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.09

    A Remote Disclosure of Information vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.

  • CVE-2016-8518HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.05

    A remote denial of service vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.

  • CVE-2016-8516HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.05

    A remote denial of service vulnerability in HPE Systems Insight Manager in all versions prior to 7.6 was found.

  • CVE-2016-4396HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.04

    HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.

  • CVE-2016-4395HigOct 28, 2016
    risk 0.49cvss 7.5epss 0.04

    HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.

  • CVE-2016-4378HigAug 26, 2016
    risk 0.49cvss 7.5epss 0.03

    The (1) Device Manager, (2) Tiered Storage Manager, (3) Replication Manager, (4) Replication Monitor, and (5) Hitachi Automation Director (HAD) components in HPE XP P9000 Command View Advanced Edition Software before 8.4.1-00 and XP7 Command View Advanced Edition Suite before…

  • CVE-2016-4367HigJun 8, 2016
    risk 0.49cvss 7.5epss 0.08

    The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2016-4365HigJun 8, 2016
    risk 0.49cvss 7.5epss 0.04

    HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.

  • CVE-2016-4361HigJun 8, 2016
    risk 0.49cvss 7.5epss 0.08

    HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allow…

  • CVE-2016-2027HigJun 8, 2016
    risk 0.49cvss 7.5epss 0.04

    HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026.

  • CVE-2016-2026HigJun 8, 2016
    risk 0.49cvss 7.5epss 0.04

    HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027.

Page 11 of 19