VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2026-7539HigJun 24, 2026
    risk 0.47cvss —epss 0.00

    A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow escalation of privilege and/or arbitrary code execution. HP is releasing software updates to mitigate the potential vulnerability.

  • CVE-2026-4667HigApr 15, 2026
    risk 0.47cvss —epss 0.00

    HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.

  • CVE-2023-6215HigOct 7, 2025
    risk 0.47cvss —epss 0.00

    A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is…

  • CVE-2024-5477HigAug 13, 2025
    risk 0.47cvss —epss 0.00

    A potential security vulnerability has been identified in the System BIOS for some HP PC products which may allow escalation of privilege, arbitrary code execution, denial of service, or information disclosure via a physical attack that requires specialized equipment and…

  • CVE-2025-43022HigJul 22, 2025
    risk 0.47cvss 7.2epss 0.00

    A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.

  • CVE-2024-4554HigAug 28, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects Access Manager before 5.0.4.1 and 5.1.

  • CVE-2020-11850HigAug 21, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper Input Validation vulnerability in OpenText Self Service Password Reset allows Cross-Site Scripting (XSS). This issue affects Self Service Password Reset before 4.5.0.2 and 4.4.0.6

  • CVE-2024-31477HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2024-31476HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2023-4464HigDec 29, 2023
    risk 0.47cvss 7.2epss 0.03

    A vulnerability, which was classified as critical, has been found in Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101,…

  • CVE-2023-50271HigDec 17, 2023
    risk 0.47cvss 7.2epss 0.01

    A potential security vulnerability has been identified with HP-UX System Management Homepage (SMH). This vulnerability could be exploited locally or remotely to disclose information.

  • CVE-2023-32268HigDec 6, 2023
    risk 0.47cvss 7.2epss 0.01

    Exposure of Proxy Administrator Credentials An authenticated administrator equivalent Filr user can access the credentials of proxy administrators.

  • CVE-2023-45625HigNov 14, 2023
    risk 0.47cvss 7.2epss 0.02

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2015-2202HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows administrative users to escalate privileges to root on the underlying OS.

  • CVE-2015-2201HigSep 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Aruba AirWave before 7.7.14.2 and 8.x before 8.0.7 allows VisualRF remote OS command execution and file disclosure by administrative users.

  • CVE-2022-4894HigAug 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontrolled Search Path Element.

  • CVE-2023-22790HigMay 8, 2023
    risk 0.47cvss 7.2epss 0.02

    Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating…

  • CVE-2023-22789HigMay 8, 2023
    risk 0.47cvss 7.2epss 0.02

    Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating…

  • CVE-2023-22788HigMay 8, 2023
    risk 0.47cvss 7.2epss 0.02

    Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating…

  • CVE-2022-38758HigJan 26, 2023
    risk 0.47cvss 7.2epss 0.00

    Cross-site Scripting (XSS) vulnerability in NetIQ iManager prior to version 3.2.6 allows attacker to execute malicious scripts on the user's browser. This issue affects: Micro Focus NetIQ iManager NetIQ iManager versions prior to 3.2.6 on ALL.

  • CVE-2022-38757HigDec 23, 2022
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified in Micro Focus ZENworks 2020 Update 3a and prior versions. This vulnerability allows administrators with rights to perform actions (e.g., install a bundle) on a set of managed devices, to be able to exercise these rights on managed devices in…

  • CVE-2022-37931HigNov 22, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in NetBatch-Plus software allows unauthorized access to the application.  HPE has provided a workaround and fix. Please refer to HPE Security Bulletin HPESBNS04388 for details.

  • CVE-2021-29220HigFeb 24, 2022
    risk 0.47cvss 7.2epss 0.02

    Multiple buffer overflow security vulnerabilities have been identified in HPE iLO Amplifier Pack version(s): Prior to 2.12. These vulnerabilities could be exploited by a highly privileged user to remotely execute code that could lead to a loss of confidentiality, integrity, and…

  • CVE-2021-29214HigDec 10, 2021
    risk 0.47cvss 7.2epss 0.01

    A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerability is limited to SSMC. Note: The arrays…

  • CVE-2019-18945HigFeb 26, 2021
    risk 0.47cvss 7.3epss 0.01

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to privilege escalation vulnerability.

  • CVE-2019-16284HigNov 5, 2019
    risk 0.47cvss 7.2epss 0.02

    A potential security vulnerability has been identified in multiple HP products and versions which involves possible execution of arbitrary code during boot services that can result in elevation of privilege. The EFI_BOOT_SERVICES structure might be overwritten by an attacker to…

  • CVE-2019-5406HigAug 9, 2019
    risk 0.47cvss 7.2epss 0.01

    A remote session reuse vulnerability was discovered in HPE 3PAR StoreServ Management and Core Software Media version(s): prior to 3.5.0.1.

  • CVE-2019-6326HigJun 17, 2019
    risk 0.47cvss 7.2epss 0.02

    HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have embedded web server attributes which may be potentially vulnerable to Buffer Overflow.

  • CVE-2019-6321HigMay 29, 2019
    risk 0.47cvss 7.2epss 0.01

    HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is disabled by default.

  • CVE-2018-5927HigMar 27, 2019
    risk 0.47cvss 7.3epss 0.00

    HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.

  • CVE-2018-7105HigSep 27, 2018
    risk 0.47cvss 7.2epss 0.04

    A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers prior to v1.35, HPE Integrated Lights-Out 4 (iLO 4) prior to v2.61, HPE Integrated Lights-Out 3 (iLO 3) prior to v1.90 could be remotely exploited to execute arbitrary code leading to…

  • CVE-2018-7078HigAug 6, 2018
    risk 0.47cvss 7.2epss 0.06

    A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.

  • CVE-2017-14362HigDec 13, 2017
    risk 0.47cvss 7.3epss 0.01

    Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability could be exploited to allow a Cross-Site Forgery attack.

  • CVE-2016-0728HigFeb 8, 2016
    risk 0.47cvss 7.8epss 0.03

    The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted…

  • CVE-2016-0777MedJan 14, 2016
    risk 0.47cvss 6.5epss 0.63

    The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

  • CVE-2026-82346HigAug 31, 2026
    risk 0.46cvss —epss 0.00

    A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

  • CVE-2026-2915HigMar 3, 2026
    risk 0.46cvss 7.1epss 0.00

    HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability was remediated with HP System Event Utility version 3.2.16.

  • CVE-2025-13492HigDec 3, 2025
    risk 0.46cvss 7.0epss 0.00

    A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerability could potentially allow a local attacker to escalate privileges via a race condition when installing packages.

  • CVE-2024-1470HigFeb 29, 2024
    risk 0.46cvss 7.1epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login Extension: 4.6.

  • CVE-2023-38402HigAug 15, 2023
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\SYSTEM. A successful exploit could allow these malicious users to create a Denial-of-Service (DoS) condition affecting…

  • CVE-2023-32265HigJul 20, 2023
    risk 0.46cvss 7.1epss 0.00

    A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used in Enterprise Server, Enterprise Test Server, Enterprise Developer, Visual COBOL, and COBOL Server. An attacker would need to be authenticated into…

  • CVE-2023-26299HigJun 30, 2023
    risk 0.46cvss 7.0epss 0.00

    A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS), which might allow arbitrary code execution. AMI has released updates to mitigate the potential vulnerability.

  • CVE-2022-31642HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31641HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2022-31640HigJun 14, 2023
    risk 0.46cvss 7.0epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.

  • CVE-2023-28089HigApr 25, 2023
    risk 0.46cvss 7.1epss 0.00

    An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules

  • CVE-2022-43779HigFeb 12, 2023
    risk 0.46cvss 7.0epss 0.00

    A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the…

  • CVE-2022-27538HigFeb 1, 2023
    risk 0.46cvss 7.0epss 0.00

    A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential…

  • CVE-2021-22522HigJul 22, 2021
    risk 0.46cvss 7.1epss 0.01

    Reflected Cross-Site Scripting vulnerability in Micro Focus Verastream Host Integrator, affecting version version 7.8 Update 1 and earlier versions. The vulnerability could allow disclosure of confidential data.

  • CVE-2019-11983HigJun 5, 2019
    risk 0.46cvss 7.0epss 0.02

    A remote buffer overflow vulnerability was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than v2.61b for Gen9 servers and Integrated Lights-Out 5 (iLO 5) for Gen10 Servers earlier than version v1.39.

Page 19 of 56