VYPR

Vendor CVEs

HPE

All CVEs

1,066 total · sorted by risk
  • CVE-2026-44855HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.00

    Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through the command-line interface of the AOS-8 and AOS-10 Operating Systems. An authenticated attacker with administrative privileges could exploit these…

  • CVE-2026-44854HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.01

    Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote…

  • CVE-2026-44853HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.01

    Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arbitrary files to the underlying operating system, potentially leading to remote…

  • CVE-2026-44852HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.00

    An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authenticated remote attacker to overwrite arbitrary files on the underlying operating…

  • CVE-2026-23821HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an attacker to execute arbitrary commands on…

  • CVE-2026-23816HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2026-23815HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.

  • CVE-2026-23592HigJan 27, 2026
    risk 0.47cvss 7.2epss 0.01

    Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2025-37183HigJan 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database,…

  • CVE-2025-37182HigJan 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database,…

  • CVE-2025-37181HigJan 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database,…

  • CVE-2025-37175HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files as a privilege user and…

  • CVE-2025-37174HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or modify arbitrary files and…

  • CVE-2025-37173HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.00

    An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials to trigger unintended…

  • CVE-2025-37172HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the…

  • CVE-2025-37171HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the…

  • CVE-2025-37170HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the…

  • CVE-2025-37169HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    A stack overflow vulnerability exists in the AOS-10 web-based management interface of a Mobility Gateway. Successful exploitation could allow an authenticated malicious actor to execute arbitrary code as a privileged user on the underlying operating system.

  • CVE-2025-37163HigNov 18, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave Platform. An authenticated attacker could exploit this vulnerability to execute arbitrary operating system commands with elevated privileges on the underlying …

  • CVE-2025-37146HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying…

  • CVE-2025-37134HigOct 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying…

  • CVE-2025-37127HigSep 16, 2025
    risk 0.47cvss 7.2epss 0.00

    A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating…

  • CVE-2025-37126HigSep 16, 2025
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2025-37107HigJul 16, 2025
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

  • CVE-2025-37106HigJul 16, 2025
    risk 0.47cvss 7.3epss 0.00

    An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.

  • CVE-2025-37102HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.02

    An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system…

  • CVE-2025-37091HigJun 2, 2025
    risk 0.47cvss 7.2epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-23052HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2025-23051HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.01

    An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to overwrite arbitrary system files.

  • CVE-2024-54007HigJan 7, 2025
    risk 0.47cvss 7.2epss 0.02

    Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands…

  • CVE-2024-54006HigJan 7, 2025
    risk 0.47cvss 7.2epss 0.02

    Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands…

  • CVE-2024-54008HigDec 10, 2024
    risk 0.47cvss 7.2epss 0.01

    An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.

  • CVE-2024-51771HigDec 3, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attacker to run arbitrary commands on the…

  • CVE-2024-47463HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on…

  • CVE-2024-47462HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file creation vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. Successful exploitation of this vulnerability could allow an authenticated remote attacker to create arbitrary files, which could lead to a remote command execution (RCE) on…

  • CVE-2024-47461HigNov 5, 2024
    risk 0.47cvss 7.2epss 0.02

    An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This…

  • CVE-2024-41915HigJul 30, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify…

  • CVE-2024-41135HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-41134HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-41133HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-33519HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to…

  • CVE-2024-22443HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary…

  • CVE-2024-31476HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2024-22437HigApr 15, 2024
    risk 0.47cvss 7.3epss 0.00

    A potential security vulnerability has been identified in VSS Provider and CAPI Proxy software for certain HPE MSA storage products. This vulnerability could be exploited to gain elevated privilege on the system.

  • CVE-2023-50271HigDec 17, 2023
    risk 0.47cvss 7.2epss 0.01

    A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information.

  • CVE-2023-30912HigOct 25, 2023
    risk 0.47cvss 7.2epss 0.01

    A remote code execution issue exists in HPE OneView.

  • CVE-2023-1168HigMar 22, 2023
    risk 0.47cvss 7.2epss 0.01

    An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to…

  • CVE-2022-37933HigJan 5, 2023
    risk 0.47cvss 7.3epss 0.00

    A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to resolve the vulnerability in HPE Superdome…

  • CVE-2022-37931HigNov 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

  • CVE-2022-28633HigAug 12, 2022
    risk 0.47cvss 7.3epss 0.00

    A local disclosure of sensitive information and a local unauthorized data modification vulnerability were discovered in HPE Integrated Lights-Out 5 (iLO 5) firmware version(s): Prior to 2.71. An unprivileged user could locally exploit this vulnerability to read and write to the…

Page 14 of 22