VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2018-7119HigMay 10, 2019
    risk 0.46cvss 7.0epss 0.00

    A Local Disclosure of Sensitive Information vulnerability was identified in HPE NonStop Safeguard earlier than version SPR T9750L01^AIC or T9750H05^AIH, and later versions when the PASSWORD-PROMPT configuration attribute is not set to BLIND; all versions on H-series.…

  • CVE-2019-3481HigMar 25, 2019
    risk 0.46cvss 7.1epss 0.02

    Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.

  • CVE-2019-3474MedFeb 20, 2019
    risk 0.46cvss 6.5epss 0.09

    A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.

  • CVE-2018-7691MedDec 13, 2018
    risk 0.46cvss 6.5epss 0.07

    A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access

  • CVE-2018-7690MedDec 13, 2018
    risk 0.46cvss 6.5epss 0.07

    A potential Remote Unauthorized Access in Micro Focus Fortify Software Security Center (SSC), versions 17.10, 17.20, 18.10 this exploitation could allow Remote Unauthorized Access

  • CVE-2018-6499HigAug 30, 2018
    risk 0.46cvss 7.1epss 0.02

    Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management…

  • CVE-2016-2015HigMay 14, 2016
    risk 0.46cvss 7.1epss 0.01

    HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.

  • CVE-2026-17639MedAug 17, 2026
    risk 0.45cvss —epss 0.00

    Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to cause the device to become unavailable by sending multiple concurrent HTTP requests.

  • CVE-2024-9432MedJan 30, 2026
    risk 0.45cvss —epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in OpenText™ Vertica allows Retrieve Embedded Sensitive Data.   The vulnerability could read Vertica agent plaintext apikey.This issue affects Vertica versions: 23.X, 24.X, 25.X.

  • CVE-2018-2634MedJan 18, 2018
    risk 0.45cvss 6.8epss 0.05

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151. Difficult to exploit vulnerability allows unauthenticated attacker with network…

  • CVE-2025-11998MedOct 30, 2025
    risk 0.44cvss —epss 0.00

    The following HP Card Readers B Models (X3D03B & Y7C05B) are potentially vulnerable to information disclosure, allowing prior user identity to be inherited under certain conditions —e.g., when an NFC device (such as a smartphone/smartwatches) is in proximity during a card…

  • CVE-2025-43487MedJul 23, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update.

  • CVE-2025-43020MedJul 22, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.

  • CVE-2022-37020MedJun 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

  • CVE-2022-37019MedJun 10, 2024
    risk 0.44cvss 6.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.

  • CVE-2024-5143MedMay 23, 2024
    risk 0.44cvss 6.8epss 0.00

    A user with device administrative privileges can change existing SMTP server settings on the device, without having to re-enter SMTP server credentials. By redirecting send-to-email traffic to the new server, the original SMTP server credentials may potentially be exposed.

  • CVE-2024-27460MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.02

    A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

  • CVE-2023-5409MedOct 13, 2023
    risk 0.44cvss 6.8epss 0.00

    HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended…

  • CVE-2022-37934MedJan 5, 2023
    risk 0.44cvss 6.8epss 0.02

    A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerability could be remotely exploited to allow remote directory traversal in HPE OfficeConnect 1820 switch series version PT.02.17 and below, HPE OfficeConnect 1850…

  • CVE-2021-22521MedJul 30, 2021
    risk 0.44cvss 6.7epss 0.00

    A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.

  • CVE-2021-29202MedMay 25, 2021
    risk 0.44cvss 6.7epss 0.00

    A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE…

  • CVE-2020-7207MedNov 5, 2020
    risk 0.44cvss 6.8epss 0.01

    A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always…

  • CVE-2020-15596MedAug 12, 2020
    risk 0.44cvss 6.7epss 0.00

    The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.

  • CVE-2019-18913MedJan 31, 2020
    risk 0.44cvss 6.8epss 0.01

    A potential security vulnerability with pre-boot DMA may allow unauthorized UEFI code execution using open-case attacks. This industry-wide issue requires physically accessing internal expansion slots with specialized hardware and software tools to modify UEFI code in memory.…

  • CVE-2019-18910MedNov 22, 2019
    risk 0.44cvss 6.8epss 0.01

    The Citrix Receiver wrapper function does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with local user privileges.

  • CVE-2019-16287MedNov 22, 2019
    risk 0.44cvss 6.8epss 0.01

    In HP ThinPro Linux 6.2, 6.2.1, 7.0 and 7.1, an attacker may be able to leverage the application filter bypass vulnerability to gain privileged access to create a file on the local file system whose presence puts the device in Administrative Mode, which will allow the attacker…

  • CVE-2019-16286MedNov 22, 2019
    risk 0.44cvss 6.8epss 0.01

    An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands.

  • CVE-2019-6333MedOct 11, 2019
    risk 0.44cvss 6.7epss 0.01

    A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute arbitrary code via an HP Touchpoint Analytics system…

  • CVE-2019-6322MedMay 29, 2019
    risk 0.44cvss 6.8epss 0.01

    HP has identified a security vulnerability with some versions of Workstation BIOS (UEFI Firmware) where the runtime BIOS code could be tampered with if the TPM is disabled. This vulnerability relates to Workstations whose TPM is enabled by default.

  • CVE-2018-18591MedNov 13, 2018
    risk 0.44cvss 6.8epss 0.01

    A potential unauthorized disclosure of data vulnerability has been identified in Micro Focus Service Manager versions: 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51. The vulnerability could be exploited to release unauthorized disclosure of data.

  • CVE-2016-8527MedAug 6, 2018
    risk 0.44cvss 6.1epss 0.14

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative…

  • CVE-1999-0517MedJan 1, 1997
    risk 0.44cvss 5.9epss 0.27

    An SNMP community name is the default (e.g. public), null, or missing.

  • CVE-2019-12000MedJul 17, 2020
    risk 0.43cvss 6.6epss 0.01

    HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the…

  • CVE-2014-7301MedJan 27, 2020
    risk 0.43cvss 6.6epss 0.01

    SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.

  • CVE-2019-11135MedNov 14, 2019
    risk 0.43cvss 6.5epss 0.03

    TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

  • CVE-2019-3482MedMar 25, 2019
    risk 0.43cvss 6.5epss 0.05

    Mitigates a directory traversal issue in ArcSight Logger versions prior to 6.7.

  • CVE-2018-18593MedDec 31, 2018
    risk 0.43cvss 6.5epss 0.09

    Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05,…

  • CVE-2018-7113MedDec 3, 2018
    risk 0.43cvss 6.6epss 0.01

    A security vulnerability in HPE Integrated Lights-Out 5 (iLO 5) prior to v1.37 could be locally exploited to bypass the security restrictions for firmware updates.

  • CVE-2017-5798MedFeb 15, 2018
    risk 0.43cvss 6.1epss 0.10

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

  • CVE-2017-5795MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.02

    A Local Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) version PLAT 7.2 E0403P06 was found.

  • CVE-2017-12555MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.03

    A remote arbitrary file download and disclosure of information vulnerability in HPE Intelligent Management Center (iMC) Service Operation Management (SOM) version IMC SOM 7.3 E0501 was found.

  • CVE-2016-8521MedFeb 15, 2018
    risk 0.43cvss 6.5epss 0.03

    A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found.

  • CVE-2018-2582MedJan 18, 2018
    risk 0.43cvss 6.5epss 0.05

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 8u152 and 9.0.1; Java SE Embedded: 8u151. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2016-1605MedAug 1, 2016
    risk 0.43cvss 6.5epss 0.04

    Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.

  • CVE-2016-2775MedJul 19, 2016
    risk 0.43cvss 5.9epss 0.63

    ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

  • CVE-2025-3508MedJul 25, 2025
    risk 0.42cvss 6.5epss 0.01

    Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensitive print job information.

  • CVE-2021-22533MedSep 12, 2024
    risk 0.42cvss 6.5epss 0.00

    Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ eDirectory 9.2.4.0000.

  • CVE-2024-6359MedAug 6, 2024
    risk 0.42cvss 6.4epss 0.00

    Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.

  • CVE-2024-29080MedJul 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

  • CVE-2024-24970MedJul 19, 2024
    risk 0.42cvss 6.5epss 0.00

    Potential vulnerabilities have been identified in the HP Display Control software component within the HP Application Enabling Software Driver which might allow escalation of privilege.

Page 20 of 56