← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Service Manager
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
5.5 MEDIUM· v2
HP Service Manager 9.30 through 9.32 does not properly manage privileges, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
1Hp
1Service Manager
Apr 29, 2026
Oct 16, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
HP Service Manager 9.30 through 9.32 allows remote attackers to execute arbitrary code via an unspecified "injection" approach.
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZDI-CAN...Show more
SQL injection vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZDI-CAN-1664.Show less
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1647.
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass intended access restrictions via unknown vectors, aka ZDI-CAN-...Show more
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass intended access restrictions via unknown vectors, aka ZDI-CAN-1645.Show less
1Hp
2Imc Service Operation Management Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.
1Hp
2Imc Branch Intelligent Management System Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors,...Show more
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.Show less
1Hp
2Imc Branch Intelligent Management System Software Module
Intelligent Management Center
Apr 29, 2026
Oct 13, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZD...Show more
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.Show less
1Hp
20Color Laserjet Cm4540
Color Laserjet Cm4540fColor Laserjet Cm4540fskm+17 more
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
1.5 LOW· v2
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read im...Show more
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices allow local users to read images of arbitrary scanned documents via unspecified vectors.Show less
1Hp
20Color Laserjet Cm4540
Color Laserjet Cm4540fColor Laserjet Cm4540fskm+17 more
Apr 29, 2026
Oct 4, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices do not properly encrypt PDF...Show more
HP LaserJet M4555, M525, and M725; LaserJet flow MFP M525c; LaserJet Enterprise color flow MFP M575c; Color LaserJet CM4540, M575, and M775; and ScanJet Enterprise 8500fn1 FutureSmart devices do not properly encrypt PDF documents, which allows remote attackers to obtain sensitive information via unspecified vectors.Show less
1Hp
1System Management Homepage
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows remote authenticated users to cause a denial of service via unknown vectors.
1Hp
7Icewall Federation Agent
Icewall File ManagerIcewall Java Agent Library+4 more
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 throug...Show more
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.0, and IceWall File Manager 3.0 through SP4 allows remote authenticated users to obtain sensitive information via unknown vectors.Show less
1Hp
1Icewall Sso Agent Option
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in HP IceWall SSO Agent Option 8.0 through 10.0 allows remote authenticated users to obtain sensitive information via unknown vectors.
1Hp
4Icewall File Manager
Icewall Smart Device OptionIcewall Sso Agent+1 more
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, and IceWall File Manager 3.0 through SP4 allows remote attackers to obtain se...Show more
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, and IceWall File Manager 3.0 through SP4 allows remote attackers to obtain sensitive information via unknown vectors.Show less
1Hp
1Icewall Sso Agent Option
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in HP IceWall SSO Agent Option 8.0 through 10.0 allows remote attackers to obtain sensitive information via unknown vectors.
1Hp
1Xp 9000 Command View
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in HP XP P9000 Command View Advanced Edition Suite Software 7.x before 7.5.0-02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Hp
1Linux Imaging And Printing Project
Apr 29, 2026
Sep 23, 2013
N/A· v4
N/A· v3
6.9 MEDIUM· v2
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended...Show more
The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.Show less
1Hp
2Identity Driven Manager
Procurve Manager
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZD...Show more
The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZDI-CAN-1745.Show less
1Hp
2Identity Driven Manager
Procurve Manager
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows...Show more
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.Show less
1Hp
2Identity Driven Manager
Procurve Manager
Apr 29, 2026
Sep 16, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allo...Show more
UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.Show less