Skip to main content

Vendor archive

hpe CVEs

Beta · best-effort

190 CVEs tagged to vendor hpe21 Critical, 105 High, 63 Medium, 1 Low, 0 Unrated.

CVE-2025-37096

Published Jun 2, 2025

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-37095

Published Jun 2, 2025

A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-37094

Published Jun 2, 2025

A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-37093

Published Jun 2, 2025

An authentication bypass vulnerability exists in HPE StoreOnce Software.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-37092

Published Jun 2, 2025

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-37091

Published Jun 2, 2025

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-37090

Published Jun 2, 2025

A server-side request forgery vulnerability exists in HPE StoreOnce Software.

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-37089

Published Jun 2, 2025

A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27086

Published Apr 21, 2025

A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-53675

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53674

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53673

Published Nov 26, 2024

A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11622

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42508

Published Oct 18, 2024

This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39268

Published Aug 29, 2023

A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vul…

CVSS 4.5 · Medium

CVE-2023-39267

Published Aug 29, 2023

An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition…

CVSS 6.6 · Medium

CVE-2023-39266

Published Aug 29, 2023

A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user…

CVSS 8.3 · High
Showing 26-50 of 190 CVEsPage 2 of 8