Vulnerability index

Browse CVEs

177 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Insight Remote Support HIGH 7.5
CVE-2025-37098EPSS 37%

A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

Fix: 7.15.0.646+
Fix from $1,950 2025-07-01
Insight Remote Support HIGH 7.5
CVE-2025-37097

A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service

Fix: 7.15.0.646+
Fix from $1,950 2025-07-01
Storeonce System CRITICAL 9.8
CVE-2025-37095

A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37096

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37090

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37091

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37092

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37093

An authentication bypass vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.1
CVE-2025-37094

A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Storeonce System CRITICAL 9.8
CVE-2025-37089

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

Fix: 4.3.11+
Fix from $2,300 2025-06-02
Performance Cluster Manager HIGH 8.1
CVE-2025-27086

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

Fix: 1.13+
Fix from $1,950 2025-04-21
Insight Remote Support CRITICAL 9.8
CVE-2024-53676EPSS 52%

A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

Fix: 7.14.0.629+
Fix from $2,300 2024-11-27
Insight Remote Support CRITICAL 9.8
CVE-2024-53673

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

Fix: 7.14.0.629+
Fix from $2,300 2024-11-26
Insight Remote Support HIGH 7.5
CVE-2024-53674EPSS 47%

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Fix: 7.14.0.629+
Fix from $1,950 2024-11-26
Insight Remote Support HIGH 7.5
CVE-2024-53675EPSS 84%

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Fix: 7.14.0.629+
Fix from $1,950 2024-11-26
Insight Remote Support HIGH 7.5
CVE-2024-11622

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Fix: 7.14.0.629+
Fix from $1,950 2024-11-26
Oneview MEDIUM 5.5
CVE-2024-42508

This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

Fix: 9.20.00+
Fix from $1,600 2024-10-18
Cray Parallel Application Launch Service CRITICAL 9.8
CVE-2024-22441

HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.

Fix: 1.2.14 / 1.3.3+
Fix from $2,300 2024-06-13
Integrated Lights Out 5 Firmware CRITICAL 9.8
CVE-2023-50272

A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability …

Fix: after 3.00
Fix from $2,300 2023-12-19
Oneview CRITICAL 9.8
CVE-2023-30912

A remote code execution issue exists in HPE OneView.

Fix: 8.60.00+
Fix from $2,300 2023-10-25
Integrated Lights Out 5 Firmware HIGH 7.5
CVE-2023-30911

HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service.

Fix: 1.53 / 2.98+
Fix from $1,950 2023-10-18
Msa 1060 Storage Firmware MEDIUM 5.4
CVE-2023-30910

HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP requests. 

Mitigation only
Fix from $1,600 2023-10-09
Arubaos Switch CRITICAL 9.8
CVE-2023-39268

A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Succe…

Fix: 16.04.0027 / 16.08.0027+
Fix from $2,300 2023-08-29
Arubaos Switch MEDIUM 6.5
CVE-2023-39267

An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Den…

Fix: 16.04.0027 / 16.08.0027+
Fix from $1,600 2023-08-29
Arubaos Switch MEDIUM 6.1
CVE-2023-39266

A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scriptin…

Fix: 16.04.0027 / 16.08.0027+
Fix from $1,600 2023-08-29
Arubaos Cx HIGH 8.8
CVE-2023-3718

An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results i…

Fix: after 10.11.1010
Fix from $1,950 2023-08-01
Intelligent Provisioning HIGH 7.8
CVE-2023-30906

The vulnerability could be locally exploited to allow escalation of privilege.

Fix: 2.87+
Fix from $1,950 2023-07-18
Sgi Uv 300 Rmc Firmware HIGH 7.8
CVE-2023-30905

The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege.

Fix: after 1.2.7
Fix from $1,950 2023-06-16
Insight Remote Support MEDIUM 5.5
CVE-2023-30904

A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.

Fix: 7.12.0.545+
Fix from $1,600 2023-06-16
Oneview Global Dashboard MEDIUM 5.5
CVE-2023-28085

An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials

Fix: 2.72+
Fix from $1,600 2023-04-14