VYPR

Vendor CVEs

HPE

All CVEs

938 total · sorted by risk
  • CVE-2026-63455CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…

  • CVE-2026-23813CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

  • CVE-2026-23600CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

  • CVE-2025-37184CriJan 14, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor…

  • CVE-2025-37103CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.01

    Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

  • CVE-2025-37099CriJul 1, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

  • CVE-2025-37096CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37095CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37093CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37092CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37090CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A server-side request forgery vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37089CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37087CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.00

    A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.

  • CVE-2024-13804CriMar 30, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated RCE in HPE Insight Cluster Management Utility

  • CVE-2024-42395CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete…

  • CVE-2024-42394CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-42393CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-22442CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The vulnerability could be remotely exploited to bypass authentication.

  • CVE-2024-22441CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.00

    HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

  • CVE-2023-30909CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in some OneView APIs.

  • CVE-2023-30908CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in a OneView API.

  • CVE-2022-37938CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated server side request forgery in HPE Serviceguard Manager

  • CVE-2022-37937CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Pre-auth memory corruption in HPE Serviceguard

  • CVE-2022-37936CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Java deserialization vulnerability in Serviceguard Manager

  • CVE-2022-28623CriJul 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL…

  • CVE-2022-28620CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis…

  • CVE-2022-28618CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has…

  • CVE-2022-28616CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-28617CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-29215CriJan 18, 2022
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9:…

  • CVE-2021-26588CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts…

  • CVE-2021-26583CriMay 10, 2021
    risk 0.64cvss 9.8epss 0.04

    A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.

  • CVE-2021-25139CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.08

    A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500…

  • CVE-2020-7203CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.05

    A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.

  • CVE-2020-7199CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.09

    A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,…

  • CVE-2020-7128CriNov 4, 2020
    risk 0.64cvss 9.8epss 0.02

    A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

  • CVE-2020-7197CriOct 26, 2020
    risk 0.64cvss 9.8epss 0.02

    SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console…

  • CVE-2020-7172CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7171CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7170CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7169CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7168CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7167CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7166CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A operatorgrouptreeselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7165CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7164CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A operationselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7163CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A navigationto expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7162CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A operatorgroupselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7161CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7160CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A iccselectdeviceseries expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

Page 2 of 19