VYPR

Vendor CVEs

Microfocus

All CVEs

2,790 total · sorted by risk
  • CVE-2015-5447MedJan 5, 2016
    risk 0.35cvss 5.4epss 0.02

    Cross-site scripting (XSS) vulnerability in HP StoreOnce Backup system software before 3.13.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2015-4000LowMay 21, 2015
    risk 0.35cvss 3.7epss 1.00

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by…

  • CVE-2026-2832MedFeb 20, 2026
    risk 0.34cvss —epss 0.00

    Certain Samsung MultiXpress Multifunction Printers may be vulnerable to information disclosure, potentially exposing address book entries and other device configuration information through specific APIs without proper authorization.

  • CVE-2026-1997MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an…

  • CVE-2026-1996MedFeb 10, 2026
    risk 0.34cvss 5.3epss 0.00

    Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection.

  • CVE-2025-43018MedJul 30, 2025
    risk 0.34cvss 5.3epss 0.00

    Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.

  • CVE-2025-43489MedJul 23, 2025
    risk 0.34cvss 5.2epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. HP has addressed the issue in the latest software update.

  • CVE-2025-1004MedFeb 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Certain HP LaserJet Pro printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer via IPP (Internet Printing Protocol).

  • CVE-2021-22501MedDec 19, 2024
    risk 0.34cvss —epss 0.00

    Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation.  The vulnerability could be exploited to confidential information This issue affects Operations Bridge Manager: 2017.05, 2017.11,…

  • CVE-2024-9423MedOct 2, 2024
    risk 0.34cvss 5.3epss 0.01

    Certain HP LaserJet printers may potentially experience a denial of service when a user sends a raw JPEG file to the printer. The printer displays a “JPEG Unsupported” message which may not clear, potentially blocking queued print jobs.

  • CVE-2021-38132MedSep 12, 2024
    risk 0.34cvss 5.3epss 0.00

    Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact all version before 9.2.6.0000.

  • CVE-2024-42400MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42399MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42398MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42397MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-42396MedAug 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exist in the AP Certificate Management daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilities results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-3970MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.01

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure by directory traversal.

  • CVE-2024-3485MedMay 15, 2024
    risk 0.34cvss 5.3epss 0.00

    Server Side Request Forgery vulnerability has been discovered in OpenText™ iManager 3.2.6.0200. This could lead to senstive information disclosure.

  • CVE-2024-31482MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2024-31481MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-31480MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-31479MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to interrupt the normal operation of the affected service.

  • CVE-2024-31478MedMay 14, 2024
    risk 0.34cvss 5.3epss 0.01

    Multiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful exploitation of these vulnerabilites result in the ability to interrupt the normal operation of the affected Access Point.

  • CVE-2023-4063MedMar 22, 2024
    risk 0.34cvss 5.3epss 0.01

    Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when using an improper eSCL URL GET request.

  • CVE-2021-3441MedOct 29, 2021
    risk 0.34cvss 4.8epss 0.02

    A potential security vulnerability has been identified for the HP OfficeJet 7110 Wide Format ePrinter that enables Cross-Site Scripting (XSS).

  • CVE-2019-6337MedNov 7, 2019
    risk 0.34cvss 5.2epss 0.00

    For the printers listed a maliciously crafted print file might cause certain HP Inkjet printers to assert. Under certain circumstances, the printer produces a core dump to a local device.

  • CVE-2017-8985MedFeb 15, 2018
    risk 0.34cvss 5.3epss 0.01

    HPE XP Storage using Hitachi Global Link Manager (HGLM) has a local authenticated information disclosure vulnerability in HGLM version HGLM 6.3.0-00 to 8.5.2-00.

  • CVE-2026-1578MedFeb 13, 2026
    risk 0.33cvss —epss 0.00

    HP App for Android is potentially vulnerable to cross-site scripting (XSS) when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2021-38120MedAug 28, 2024
    risk 0.33cvss 5.1epss 0.01

    A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled functionality of backup due to improper handling in provided command parameters. This issue affects NetIQ Advance Authentication version before 6.3.5.1.

  • CVE-2021-22510MedApr 8, 2021
    risk 0.33cvss 6.1epss 0.05

    Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affects all version 6.7 and earlier versions.

  • CVE-2019-2745MedJul 23, 2019
    risk 0.33cvss 5.1epss 0.00

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 7u221, 8u212 and 11.0.3. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE…

  • CVE-2019-5394MedJun 5, 2019
    risk 0.33cvss 5.1epss 0.00

    The HPE Nonstop Maintenance Entity family of products are vulnerable to local disclosure of information, such as system layout and configuration.

  • CVE-2018-19644MedMar 27, 2019
    risk 0.33cvss 5.0epss 0.01

    Reflected cross site script issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

  • CVE-2018-19642MedMar 27, 2019
    risk 0.33cvss 5.1epss 0.01

    Denial of service issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.

  • CVE-2018-7673MedMar 26, 2018
    risk 0.33cvss 5.1epss 0.01

    The NetIQ Identity Manager communication channel, in versions prior to 4.7, is susceptible to a DoS attack.

  • CVE-2017-17556MedDec 15, 2017
    risk 0.33cvss 5.1epss 0.01

    A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.

  • CVE-2025-14432MedDec 16, 2025
    risk 0.32cvss 4.9epss 0.00

    In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not…

  • CVE-2025-12784MedNov 13, 2025
    risk 0.32cvss 4.9epss 0.00

    Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering the scan/send destination address and/or modifying the LDAP Server.

  • CVE-2022-26322MedSep 12, 2024
    risk 0.32cvss 4.9epss 0.00

    Possible Insertion of Sensitive Information into Log File Vulnerability in Identity Manager has been discovered in OpenText™ Identity Manager REST Driver. This impact version before 1.1.2.0200.

  • CVE-2024-31483MedMay 14, 2024
    risk 0.32cvss 4.9epss 0.00

    An authenticated sensitive information disclosure vulnerability exists in the CLI service accessed via the PAPI protocol. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.

  • CVE-2021-22535MedSep 28, 2021
    risk 0.32cvss 4.9epss 0.01

    Unauthorized information security disclosure vulnerability on Micro Focus Directory and Resource Administrator (DRA) product, affecting all DRA versions prior to 10.1 Patch 1. The vulnerability could lead to unauthorized information disclosure.

  • CVE-2021-22526MedSep 13, 2021
    risk 0.32cvss 4.9epss 0.00

    Open Redirection vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4

  • CVE-2019-18944MedFeb 26, 2021
    risk 0.32cvss 4.9epss 0.00

    Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to reflected XSS.

  • CVE-2018-2599MedJan 18, 2018
    risk 0.32cvss 4.8epss 0.04

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to exploit vulnerability allows…

  • CVE-2025-43488MedJul 23, 2025
    risk 0.31cvss 4.8epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update.

  • CVE-2025-43486MedJul 23, 2025
    risk 0.31cvss 4.8epss 0.00

    A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.

  • CVE-2024-5532MedOct 28, 2024
    risk 0.31cvss 4.8epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Operations Agent.  The XSS vulnerability could allow an attacker with local admin permissions to manipulate the content of the internal status page of the…

  • CVE-2024-7427MedAug 23, 2024
    risk 0.31cvss —epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in OpenText™ Network Node Manager i (NNMi) could allow Cross-Site Scripting (XSS).This issue affects Network Node Manager i (NNMi): 2022.11, 2023.05, 23.4, 24.2.

  • CVE-2021-22515MedJul 12, 2021
    risk 0.31cvss 4.8epss 0.01

    Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in NetIQ Advanced Authentication versions prior to 6.3 SP4 Patch 1.

  • CVE-2021-29211MedMay 25, 2021
    risk 0.31cvss 4.8epss 0.01

    A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380…

Page 27 of 56