VYPR

Vendor CVEs

HPE

All CVEs

1,066 total · sorted by risk
  • CVE-2016-1988CriMar 15, 2016
    risk 0.65cvss 9.8epss 0.10

    HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.

  • CVE-2026-76674CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to execute arbitrary code. Successful exploitation could allow an attacker to execute arbitrary commands on…

  • CVE-2026-76673CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerabilities have been identified in the API of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges…

  • CVE-2026-76672CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization…

  • CVE-2026-76670CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system…

  • CVE-2026-76669CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Privilege escalation vulnerabilities exist in the API of HPE Networking EdgeConnect SD-WAN Orchestrator. Successful exploitation could allow a remote low-privileged authenticated user to escalate their privileges to those of an administrative user, leading to complete system…

  • CVE-2026-73749CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could…

  • CVE-2026-63456CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…

  • CVE-2026-63455CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…

  • CVE-2026-23813CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in the web-based management interface of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. In some cases this could enable resetting the admin password.

  • CVE-2026-23600CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

  • CVE-2025-37184CriJan 14, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor…

  • CVE-2025-37103CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.01

    Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

  • CVE-2025-37099CriJul 1, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

  • CVE-2025-37096CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37095CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37093CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37092CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37090CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A server-side request forgery vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37089CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

  • CVE-2025-37087CriApr 22, 2025
    risk 0.64cvss 9.8epss 0.00

    A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.

  • CVE-2024-13804CriMar 30, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated RCE in HPE Insight Cluster Management Utility

  • CVE-2024-42395CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.00

    There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete…

  • CVE-2024-42394CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-42393CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-22442CriJul 16, 2024
    risk 0.64cvss 9.8epss 0.01

    The vulnerability could be remotely exploited to bypass authentication.

  • CVE-2024-22441CriJun 13, 2024
    risk 0.64cvss 9.8epss 0.00

    HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

  • CVE-2023-30909CriSep 14, 2023
    risk 0.64cvss 9.8epss 0.02

    A remote authentication bypass issue exists in some OneView APIs.

  • CVE-2023-30908CriSep 7, 2023
    risk 0.64cvss 9.8epss 0.01

    A remote authentication bypass issue exists in a OneView API.

  • CVE-2022-37938CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated server side request forgery in HPE Serviceguard Manager

  • CVE-2022-37937CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Pre-auth memory corruption in HPE Serviceguard

  • CVE-2022-37936CriMar 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Java deserialization vulnerability in Serviceguard Manager

  • CVE-2022-28623CriJul 8, 2022
    risk 0.64cvss 9.8epss 0.01

    Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL…

  • CVE-2022-28620CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX supercomputers versions: Prior to node controller firmware associated with HPE Cray EX liquid cooled blades, and all versions of chassis…

  • CVE-2022-28618CriMay 20, 2022
    risk 0.64cvss 9.8epss 0.02

    A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance. HPE has…

  • CVE-2022-28616CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A remote server-side request forgery (ssrf) vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2022-28617CriMay 17, 2022
    risk 0.64cvss 9.8epss 0.02

    A remote bypass security restrictions vulnerability was discovered in HPE OneView version(s): Prior to 7.0. HPE has provided a software update to resolve this vulnerability in HPE OneView.

  • CVE-2021-29215CriJan 18, 2022
    risk 0.64cvss 9.8epss 0.01

    A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9:…

  • CVE-2021-26588CriOct 11, 2021
    risk 0.64cvss 9.8epss 0.02

    A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts…

  • CVE-2021-26583CriMay 10, 2021
    risk 0.64cvss 9.8epss 0.04

    A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.

  • CVE-2021-25139CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.08

    A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500…

  • CVE-2020-7203CriDec 18, 2020
    risk 0.64cvss 9.8epss 0.05

    A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.

  • CVE-2020-7199CriDec 2, 2020
    risk 0.64cvss 9.8epss 0.10

    A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands,…

  • CVE-2020-7128CriNov 4, 2020
    risk 0.64cvss 9.8epss 0.02

    A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.

  • CVE-2020-7197CriOct 26, 2020
    risk 0.64cvss 9.8epss 0.02

    SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console…

  • CVE-2020-7172CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7171CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7170CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7169CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

  • CVE-2020-7168CriOct 19, 2020
    risk 0.64cvss 9.8epss 0.07

    A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

Page 2 of 22