HPE records
277 published records for vendor hpe.
Researcher profile
- Entered KEV
- 2 · 0.7%
- Weaponized
- 2 · 0.7%
- Pre-auth RCE
- 27
- With a fix record
- 13%
- Median publish → KEV
- 877 days
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')35
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')18
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')18
- CWE-287 Improper Authentication16
- CWE-400 Uncontrolled Resource Consumption14
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')13
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
277 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2017-5689Weaponized | An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (Aintel · active management technology firmware · CWE-269 | Critical9.8 | KEV | 92.2% | May 2, 2017 |
96Now | CVE-2025-37164Weaponized | A remote code execution issue exists in HPE OneView.hpe · oneview · CWE-94 | Critical9.8 | KEV | 90.2% | Dec 16, 2025 |
63This week | CVE-2020-7136Proof of concept | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.hpe · smart update manager | Critical9.8 | — | 79.5% | Apr 30, 2020 |
56Plan | CVE-2024-53676No exploit | A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.hpe · insight remote support · CWE-552 | Critical9.8 | — | 56.3% | Nov 26, 2024 |
55Plan | CVE-2024-53675No exploit | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | High7.5 | — | 83.6% | Nov 26, 2024 |
46Plan | CVE-2016-7434Proof of concept | The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.ntp · ntp · CWE-20 | High7.5 | — | 52.9% | Jan 13, 2017 |
44Plan | CVE-2024-53674No exploit | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | High7.5 | — | 46.7% | Nov 26, 2024 |
42Plan | CVE-2025-37098No exploit | A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.hpe · insight remote support · CWE-22 | High7.5 | — | 40.0% | Jul 1, 2025 |
40Plan | CVE-2018-20732No exploit | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.sas · web infrastructure platform · CWE-502 | Critical9.8 | — | 4.0% | Jan 16, 2019 |
40Plan | CVE-2020-24626No exploit | Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per Uhpe · utility computing service meter · CWE-22 | Critical9.8 | — | 3.0% | Sep 23, 2020 |
40Plan | CVE-2022-37932Proof of concept | A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.hpe · officeconnect 1820 j9979a firmware | Critical9.8 | — | 2.7% | Dec 12, 2022 |
40Plan | CVE-2019-12002No exploit | A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storahpe · msa 1040 firmware | Critical9.8 | — | 2.2% | Apr 17, 2020 |
40Plan | CVE-2022-28618No exploit | A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrayhpe · nimbleos · CWE-77 | Critical9.8 | — | 1.8% | May 20, 2022 |
40Plan | CVE-2021-26588No exploit | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwarhpe · 3par os | Critical9.8 | — | 1.8% | Oct 11, 2021 |
40Plan | CVE-2026-23600No exploit | A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).hpe · autopass license server · CWE-287 | Critical10.0 | — | 1.0% | Mar 2, 2026 |
39Monitor | CVE-2022-28620No exploit | A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX superhpe · slingshot firmware | Critical9.8 | — | 1.5% | Jun 24, 2022 |
39Monitor | CVE-2019-11996No exploit | Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.hpe · nimbleos | Critical9.8 | — | 1.5% | Nov 7, 2019 |
39Monitor | CVE-2019-11988No exploit | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.hpe · smart update manager | Critical9.8 | — | 1.4% | Jun 5, 2019 |
39Monitor | CVE-2023-30912No exploit | A remote code execution issue exists in HPE OneView.hpe · oneview · CWE-94 | Critical9.8 | — | 1.2% | Oct 25, 2023 |
39Monitor | CVE-2025-37091No exploit | A command injection remote code execution vulnerability exists in HPE StoreOnce Software.hpe · storeonce system · CWE-77 | Critical9.8 | — | 1.2% | Jun 2, 2025 |
39Monitor | CVE-2021-29215No exploit | A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem cohpe · tez | Critical9.8 | — | 1.2% | Jan 18, 2022 |
39Monitor | CVE-2025-37093No exploit | An authentication bypass vulnerability exists in HPE StoreOnce Software.hpe · storeonce system · CWE-287 | Critical9.8 | — | 1.1% | Jun 2, 2025 |
39Monitor | CVE-2026-76674No exploit | Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gatewayshpe · edgeconnect operating system · CWE-120 | Critical9.8 | — | 1.0% | Sep 15, 2026 |
39Monitor | CVE-2022-28623No exploit | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.hpe · icewall sso certd · CWE-89 | Critical9.8 | — | 0.9% | Jul 8, 2022 |
39Monitor | CVE-2023-39268No exploit | Memory Corruption Vulnerability in ArubaOS-Switchhpe · arubaos-switch · CWE-787 | Critical9.8 | — | 0.8% | Aug 29, 2023 |
- CVE-2017-568997Now
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A
CriticalCVSS 9.8KEVWeaponizedEPSS 92%intel · active management technology firmwareMay 2, 2017
- CVE-2025-3716496Now
A remote code execution issue exists in HPE OneView.
CriticalCVSS 9.8KEVWeaponizedEPSS 90%hpe · oneviewDec 16, 2025
- CVE-2020-713663This week
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.
CriticalCVSS 9.8Proof of conceptEPSS 80%hpe · smart update managerApr 30, 2020
- CVE-2024-5367656Plan
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
CriticalCVSS 9.8No exploitEPSS 56%hpe · insight remote supportNov 26, 2024
- CVE-2024-5367555Plan
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
HighCVSS 7.5No exploitEPSS 84%hpe · insight remote supportNov 26, 2024
- CVE-2016-743446Plan
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
HighCVSS 7.5Proof of conceptEPSS 53%ntp · ntpJan 13, 2017
- CVE-2024-5367444Plan
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
HighCVSS 7.5No exploitEPSS 47%hpe · insight remote supportNov 26, 2024
- CVE-2025-3709842Plan
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
HighCVSS 7.5No exploitEPSS 40%hpe · insight remote supportJul 1, 2025
- CVE-2018-2073240Plan
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
CriticalCVSS 9.8No exploitEPSS 4%sas · web infrastructure platformJan 16, 2019
- CVE-2020-2462640Plan
Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per U
CriticalCVSS 9.8No exploitEPSS 3%hpe · utility computing service meterSep 23, 2020
- CVE-2022-3793240Plan
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.
CriticalCVSS 9.8Proof of conceptEPSS 3%hpe · officeconnect 1820 j9979a firmwareDec 12, 2022
- CVE-2019-1200240Plan
A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Stora
CriticalCVSS 9.8No exploitEPSS 2%hpe · msa 1040 firmwareApr 17, 2020
- CVE-2022-2861840Plan
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Array
CriticalCVSS 9.8No exploitEPSS 2%hpe · nimbleosMay 20, 2022
- CVE-2021-2658840Plan
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwar
CriticalCVSS 9.8No exploitEPSS 2%hpe · 3par osOct 11, 2021
- CVE-2026-2360040Plan
A remote authentication bypass vulnerability exists in HPE AutoPass License Server (APLS).
CriticalCVSS 10.0No exploitEPSS 1%hpe · autopass license serverMar 2, 2026
- CVE-2022-2862039Monitor
A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX super
CriticalCVSS 9.8No exploitEPSS 2%hpe · slingshot firmwareJun 24, 2022
- CVE-2019-1199639Monitor
Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.
CriticalCVSS 9.8No exploitEPSS 1%hpe · nimbleosNov 7, 2019
- CVE-2019-1198839Monitor
A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
CriticalCVSS 9.8No exploitEPSS 1%hpe · smart update managerJun 5, 2019
- CVE-2023-3091239Monitor
A remote code execution issue exists in HPE OneView.
CriticalCVSS 9.8No exploitEPSS 1%hpe · oneviewOct 25, 2023
- CVE-2025-3709139Monitor
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CriticalCVSS 9.8No exploitEPSS 1%hpe · storeonce systemJun 2, 2025
- CVE-2021-2921539Monitor
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem co
CriticalCVSS 9.8No exploitEPSS 1%hpe · tezJan 18, 2022
- CVE-2025-3709339Monitor
An authentication bypass vulnerability exists in HPE StoreOnce Software.
CriticalCVSS 9.8No exploitEPSS 1%hpe · storeonce systemJun 2, 2025
- CVE-2026-7667439Monitor
Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways
CriticalCVSS 9.8No exploitEPSS 1%hpe · edgeconnect operating systemSep 15, 2026
- CVE-2022-2862339Monitor
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.
CriticalCVSS 9.8No exploitEPSS 1%hpe · icewall sso certdJul 8, 2022
- CVE-2023-3926839Monitor
Memory Corruption Vulnerability in ArubaOS-Switch
CriticalCVSS 9.8No exploitEPSS 1%hpe · arubaos-switchAug 29, 2023