VYPR

Vendor CVEs

HPE

All CVEs

938 total · sorted by risk
  • CVE-2017-12553MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12552MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12551MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary execution of commands vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12550MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local security misconfiguration vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12549MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local authentication bypass vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12548MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12547MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local arbitrary command execution vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2017-12546MedFeb 15, 2018
    risk 0.36cvss 5.6epss 0.00

    A local buffer overflow vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2016-2023MedMay 30, 2016
    risk 0.36cvss 5.5epss 0.00

    HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.

  • CVE-2016-2016MedMay 14, 2016
    risk 0.36cvss 5.5epss 0.00

    Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and…

  • CVE-2026-44873MedMay 12, 2026
    risk 0.35cvss 5.4epss 0.00

    A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated when credentials are revoked, enabling continued access until session expiration.…

  • CVE-2026-23601MedMar 4, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows…

  • CVE-2023-30910MedOct 9, 2023
    risk 0.35cvss 5.4epss 0.00

    HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP requests. 

  • CVE-2022-23701MedFeb 24, 2022
    risk 0.35cvss 5.3epss 0.01

    A potential remote host header injection security vulnerability has been identified in HPE Integrated Lights-Out 4 (iLO 4) firmware version(s): Prior to 2.60. This vulnerability could be remotely exploited to allow an attacker to supply invalid input to the iLO 4 webserver,…

  • CVE-2020-7202MedJan 5, 2021
    risk 0.35cvss 5.3epss 0.01

    A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information.

  • CVE-2020-24627MedOct 2, 2020
    risk 0.35cvss 5.4epss 0.01

    A remote stored xss vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.

  • CVE-2020-7132MedApr 23, 2020
    risk 0.35cvss 5.4epss 0.01

    A potential security vulnerability has been identified in HPE Onboard Administrator. The vulnerability could be remotely exploited to allow Reflected Cross Site Scripting. HPE has made the following software updates and mitigation information to resolve the vulnerability in HPE…

  • CVE-2019-5398MedAug 9, 2019
    risk 0.35cvss 5.4epss 0.01

    A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1.

  • CVE-2018-7122MedJun 5, 2019
    risk 0.35cvss 5.3epss 0.02

    A remote disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.

  • CVE-2018-7111MedOct 17, 2018
    risk 0.35cvss 5.3epss 0.05

    A remote unauthorized access vulnerability was identified in HPE UIoT versions 1.5, 1.4.0, 1.4.1, 1.4.2, 1.2.4.2. Specifically, there is a malfunction identified in some section of the DSM portal and some DSM APIs. The impact of the malfunction is that the info can be changed by…

  • CVE-2018-7070MedAug 6, 2018
    risk 0.35cvss 5.3epss 0.02

    HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

  • CVE-2016-4392MedAug 6, 2018
    risk 0.35cvss 5.4epss 0.01

    A remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.

  • CVE-2018-7170MedMar 6, 2018
    risk 0.35cvss 5.3epss 0.03

    ntpd in ntp 4.2.x before 4.2.8p7 and 4.3.x before 4.3.92 allows authenticated users that know the private symmetric key to create arbitrarily-many ephemeral associations in order to win the clock selection of ntpd and modify a victim's clock via a Sybil attack. This issue exists…

  • CVE-2017-5800MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A Remote Cross-Site Scripting (XSS) vulnerability in HPE Operations Bridge Analytics version v3.0 was found.

  • CVE-2017-5783MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.01

    A remote clickjacking vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-5782MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A missing HSTS Header vulnerability in HPE Matrix Operating Environment version v7.6 was found.

  • CVE-2017-12544MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.05

    A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

  • CVE-2016-8532MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross site scripting vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8531MedFeb 15, 2018
    risk 0.35cvss 5.3epss 0.02

    A remote information disclosure vulnerability in HPE Matrix Operating Environment version 7.6 was found.

  • CVE-2016-8522MedFeb 15, 2018
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

  • CVE-2017-14359MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    A potential security vulnerability has been identified in HPE Performance Center versions 12.20. The vulnerability could be remotely exploited to allow cross-site scripting.

  • CVE-2017-13991MedSep 30, 2017
    risk 0.35cvss 5.3epss 0.01

    An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of product license features.

  • CVE-2017-13990MedSep 30, 2017
    risk 0.35cvss 5.3epss 0.01

    An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disclosure of Apache Tomcat application server version.

  • CVE-2016-4393MedOct 28, 2016
    risk 0.35cvss 5.4epss 0.01

    HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.

  • CVE-2016-4380MedSep 8, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in the AdminUI in HPE Operations Manager 9.21.x before 9.21.130 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-2011MedMay 7, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2010.

  • CVE-2016-2010MedMay 7, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-2011.

  • CVE-2015-5447MedJan 5, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-23822MedMay 12, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitation could allow an attacker to cause excessive resource consumption upon user interaction, leading to…

  • CVE-2025-37178MedJan 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific…

  • CVE-2025-37160MedNov 18, 2025
    risk 0.34cvss 5.3epss 0.00

    A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote attacker with low privileges to view sensitive information. Successful exploitation of this vulnerability could enable the attacker to disclose sensitive data.

  • CVE-2024-42400MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42399MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42398MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42397MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42396MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-31479MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2022-37940MedMar 22, 2023
    risk 0.34cvss 5.3epss 0.00

    Potential security vulnerabilities have been identified in the HPE FlexFabric 5700 Switch Series. These vulnerabilities could be remotely exploited to allow host header injection and URL redirection. HPE has made the following software to resolve the vulnerability in HPE…

  • CVE-2019-5394MedJun 5, 2019
    risk 0.33cvss 5.1epss 0.00

    The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.

  • CVE-2026-44874MedMay 12, 2026
    risk 0.32cvss 4.9epss 0.00

    A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of…