Skip to content
Noroxi

HPE records

277 published records for vendor hpe.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

277 records
  • An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (A

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    intel · active management technology firmwareMay 2, 2017

  • A remote code execution issue exists in HPE OneView.

    CriticalCVSS 9.8KEVWeaponizedEPSS 90%

    hpe · oneviewDec 16, 2025

  • CVE-2020-7136
    63This week

    A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access.

    CriticalCVSS 9.8Proof of conceptEPSS 80%

    hpe · smart update managerApr 30, 2020

  • A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.

    CriticalCVSS 9.8No exploitEPSS 56%

    hpe · insight remote supportNov 26, 2024

  • An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    HighCVSS 7.5No exploitEPSS 84%

    hpe · insight remote supportNov 26, 2024

  • The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

    HighCVSS 7.5Proof of conceptEPSS 53%

    ntp · ntpJan 13, 2017

  • An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    HighCVSS 7.5No exploitEPSS 47%

    hpe · insight remote supportNov 26, 2024

  • A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

    HighCVSS 7.5No exploitEPSS 40%

    hpe · insight remote supportJul 1, 2025

  • SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

    CriticalCVSS 9.8No exploitEPSS 4%

    sas · web infrastructure platformJan 16, 2019

  • Unathenticated directory traversal in the ReceiverServlet class doPost() method can lead to arbitrary remote code execution in HPE Pay Per U

    CriticalCVSS 9.8No exploitEPSS 3%

    hpe · utility computing service meterSep 23, 2020

  • A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    hpe · officeconnect 1820 j9979a firmwareDec 12, 2022

  • A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Stora

    CriticalCVSS 9.8No exploitEPSS 2%

    hpe · msa 1040 firmwareApr 17, 2020

  • A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Array

    CriticalCVSS 9.8No exploitEPSS 2%

    hpe · nimbleosMay 20, 2022

  • A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmwar

    CriticalCVSS 9.8No exploitEPSS 2%

    hpe · 3par osOct 11, 2021

  • A remote authentication bypass vulnerability  exists in HPE AutoPass License Server (APLS).

    CriticalCVSS 10.0No exploitEPSS 1%

    hpe · autopass license serverMar 2, 2026

  • A remote authentication bypass vulnerability was discovered in HPE Cray Legacy Shasta System Solutions; HPE Slingshot; and HPE Cray EX super

    CriticalCVSS 9.8No exploitEPSS 2%

    hpe · slingshot firmwareJun 24, 2022

  • Potential security vulnerabilities have been identified with HPE Nimble Storage systems in multi array group configurations.

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · nimbleosNov 7, 2019

  • A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · smart update managerJun 5, 2019

  • A remote code execution issue exists in HPE OneView.

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · oneviewOct 25, 2023

  • A command injection remote code execution vulnerability exists in HPE StoreOnce Software.

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · storeonce systemJun 2, 2025

  • A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem co

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · tezJan 18, 2022

  • An authentication bypass vulnerability exists in HPE StoreOnce Software.

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · storeonce systemJun 2, 2025

  • Unauthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateways

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · edgeconnect operating systemSep 15, 2026

  • Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection.

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · icewall sso certdJul 8, 2022

  • Memory Corruption Vulnerability in ArubaOS-Switch

    CriticalCVSS 9.8No exploitEPSS 1%

    hpe · arubaos-switchAug 29, 2023