Vulnerability index

Browse CVEs

177 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-37098EPSS 37% A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. Insight Remote Support 7.15.0.646+ Fix from $1,9502025-07-01 HIGH 7.5 CVE-2025-37097 A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service Insight Remote Support 7.15.0.646+ Fix from $1,9502025-07-01 CRITICAL 9.8 CVE-2025-37095 A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.8 CVE-2025-37096 A command injection remote code execution vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.8 CVE-2025-37090 A server-side request forgery vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.8 CVE-2025-37091 A command injection remote code execution vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.8 CVE-2025-37092 A command injection remote code execution vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.8 CVE-2025-37093 An authentication bypass vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.1 CVE-2025-37094 A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 CRITICAL 9.8 CVE-2025-37089 A command injection remote code execution vulnerability exists in HPE StoreOnce Software. Storeonce System 4.3.11+ Fix from $2,3002025-06-02 HIGH 8.1 CVE-2025-27086 A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. Performance Cluster Manager 1.13+ Fix from $1,9502025-04-21 CRITICAL 9.8 CVE-2024-53676EPSS 52% A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. Insight Remote Support 7.14.0.629+ Fix from $2,3002024-11-27 CRITICAL 9.8 CVE-2024-53673 A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code. Insight Remote Support 7.14.0.629+ Fix from $2,3002024-11-26 HIGH 7.5 CVE-2024-53674EPSS 47% An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. Insight Remote Support 7.14.0.629+ Fix from $1,9502024-11-26 HIGH 7.5 CVE-2024-53675EPSS 84% An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. Insight Remote Support 7.14.0.629+ Fix from $1,9502024-11-26 HIGH 7.5 CVE-2024-11622 An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. Insight Remote Support 7.14.0.629+ Fix from $1,9502024-11-26 MEDIUM 5.5 CVE-2024-42508 This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users. Oneview 9.20.00+ Fix from $1,6002024-10-18 CRITICAL 9.8 CVE-2024-22441 HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass. Cray Parallel Application Launch Service 1.2.14 / 1.3.3+ Fix from $2,3002024-06-13 CRITICAL 9.8 CVE-2023-50272 A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6). The vulnerability … Integrated Lights Out 5 Firmware after 3.00 Fix from $2,3002023-12-19 CRITICAL 9.8 CVE-2023-30912 A remote code execution issue exists in HPE OneView. Oneview 8.60.00+ Fix from $2,3002023-10-25 HIGH 7.5 CVE-2023-30911 HPE Integrated Lights-Out 5, and Integrated Lights-Out 6 using iLOrest may cause denial of service. Integrated Lights Out 5 Firmware 1.53 / 2.98+ Fix from $1,9502023-10-18 MEDIUM 5.4 CVE-2023-30910 HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent interpretation of HTTP requests.  Msa 1060 Storage Firmware Mitigation only Fix from $1,6002023-10-09 CRITICAL 9.8 CVE-2023-39268 A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Succe… Arubaos Switch 16.04.0027 / 16.08.0027+ Fix from $2,3002023-08-29 MEDIUM 6.5 CVE-2023-39267 An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Den… Arubaos Switch 16.04.0027 / 16.08.0027+ Fix from $1,6002023-08-29 MEDIUM 6.1 CVE-2023-39266 A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scriptin… Arubaos Switch 16.04.0027 / 16.08.0027+ Fix from $1,6002023-08-29 HIGH 8.8 CVE-2023-3718 An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results i… Arubaos Cx after 10.11.1010 Fix from $1,9502023-08-01 HIGH 7.8 CVE-2023-30906 The vulnerability could be locally exploited to allow escalation of privilege. Intelligent Provisioning 2.87+ Fix from $1,9502023-07-18 HIGH 7.8 CVE-2023-30905 The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced privilege. Sgi Uv 300 Rmc Firmware after 1.2.7 Fix from $1,9502023-06-16 MEDIUM 5.5 CVE-2023-30904 A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information. Insight Remote Support 7.12.0.545+ Fix from $1,6002023-06-16 MEDIUM 5.5 CVE-2023-28085 An HPE OneView Global Dashboard (OVGD) appliance dump may expose OVGD user account credentials Oneview Global Dashboard 2.72+ Fix from $1,6002023-04-14