← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Operations Orchestration
May 6, 2026
Nov 23, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
2Adobe
Hp
4Coldfusion
Livecycle Data ServicesXp7 Command View Advanced Edition+1 more
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, an...Show more
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.Show less
5Apple
CanonicalDebian+2 more
9Debian Linux
Icewall Federation AgentIcewall File Manager+6 more
May 6, 2026
Nov 18, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out...Show more
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.Show less
1Hp
2Archsight Management Center
Arcsight Logger
May 6, 2026
Nov 12, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
2Hp
Microfocus
7Arcsight Command Center
Arcsight Connector ApplianceArcsight Connectors+4 more
May 6, 2026
Nov 4, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain...Show more
HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain privileges by leveraging arcsight account access.Show less
1Hp
1Arcsight Logger
May 6, 2026
Nov 4, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach.
1Hp
1Arcsight Smartconnectors
May 6, 2026
Nov 4, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password.
1Hp
1Arcsight Smartconnectors
May 6, 2026
Nov 4, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate.
1Hp
1Smart Profile Server Data Analytics Layer
May 6, 2026
Oct 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Hp
13par Service Processor Sp
May 6, 2026
Oct 12, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Hp
2Integrated Lights Out 3 Firmware
Integrated Lights Out 4 Firmware
May 6, 2026
Sep 30, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors.
1Hp
1Software Update
May 6, 2026
Sep 29, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.
1Hp
1Universal Configuration Management Database
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.
1Hp
1Arcsight Logger
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors.
1Hp
1Loadrunner
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.
1Hp
1Intelligent Provisioning
May 6, 2026
Aug 31, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in HP Intelligent Provisioning 1.00 through 1.62(a), 2.00, and 2.10 allows remote attackers to execute arbitrary code via unknown vectors.
1Hp
39Elite X2 1010 G2
Elitebook 1040 G1Elitebook 1040 G2+36 more
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial...Show more
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial of service, or execute arbitrary code, via unspecified vectors.Show less
1Hp
39Elite X2 1010 G2
Elitebook 1040 G1Elitebook 1040 G2+36 more
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vec...Show more
The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vectors.Show less
1Hp
1Virtual Connect Enterprise Manager Sdk
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified...Show more
HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified vectors.Show less
1Hp
1Virtual Connect Enterprise Manager Sdk
May 6, 2026
Aug 27, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspec...Show more
HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspecified vectors.Show less