Hp
hp
2,335 CVEs • 17,248 products
Products (17,248)
Click to collapseToggle
Products (17,248)
Click to collapse
CVEs (2,335)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. |
2Adobe Hp4Coldfusion Livecycle Data ServicesXp7 Command View Advanced Edition+1 moreMay 6, 2026 Nov 18, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, an...Show more |
5Apple CanonicalDebian+2 more9Debian Linux Icewall Federation AgentIcewall File Manager+6 moreMay 6, 2026 Nov 18, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out...Show more |
1Hp 2Archsight Management Center Arcsight LoggerMay 6, 2026 Nov 12, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in HP ArcSight Management Center before 2.1 and ArcSight Logger before 6.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2Hp Microfocus7Arcsight Command Center Arcsight Connector ApplianceArcsight Connectors+4 moreMay 6, 2026 Nov 4, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute files owned by the arcsight user, which might allow local users to gain...Show more |
HP ArcSight Logger before 6.0 P2 does not limit attempts to authenticate to the SOAP interface, which makes it easier for remote attackers to obtain access via a brute-force approach. |
The CWSAPI SOAP service in HP ArcSight SmartConnectors before 7.1.6 has a hardcoded password, which makes it easier for remote attackers to obtain administrative access by leveraging knowledge of this password. |
HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devices and obtain sensitive information via a crafted certificate. |
1Hp 1Smart Profile Server Data Analytics Layer May 6, 2026 Oct 18, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors. |
1Hp 2Integrated Lights Out 3 Firmware Integrated Lights Out 4 FirmwareMay 6, 2026 Sep 30, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 3 before 1.85 and 4 before 2.22 allows remote authenticated users to cause a denial of service via unknown vectors. |
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors. |
1Hp 1Universal Configuration Management Database May 6, 2026 Sep 16, 2015 N/A· v4 N/A· v3 4.9 MEDIUM· v2 HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors. |
HP ArcSight Logger before 6.0 P2 allows remote authenticated users to bypass the intended authorization policy via unspecified vectors. |
Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756. |
Unspecified vulnerability in HP Intelligent Provisioning 1.00 through 1.62(a), 2.00, and 2.10 allows remote attackers to execute arbitrary code via unknown vectors. |
1Hp 39Elite X2 1010 G2 Elitebook 1040 G1Elitebook 1040 G2+36 moreMay 6, 2026 Aug 27, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows remote attackers to modify data or cause a denial...Show more |
1Hp 39Elite X2 1010 G2 Elitebook 1040 G1Elitebook 1040 G2+36 moreMay 6, 2026 Aug 27, 2015 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin Client devices allows local users to gain privileges via unspecified vec...Show more |
1Hp 1Virtual Connect Enterprise Manager Sdk May 6, 2026 Aug 27, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticated users to obtain sensitive information via unspecified...Show more |
1Hp 1Virtual Connect Enterprise Manager Sdk May 6, 2026 Aug 27, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 HP Virtual Connect Enterprise Manager (VCEM) SDK before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote attackers to obtain sensitive information or modify data via unspec...Show more |