← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Hp Ux
Apr 29, 2026
Apr 4, 2011
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.
1Hp
1Diagnostics
Apr 29, 2026
Mar 29, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in HP Diagnostics 7.5x and 8.0x before 8.05.54.225 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
1Hp
1Discovery&dependency Mapping Inventory
Apr 29, 2026
Mar 25, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive in...Show more
HP Discovery & Dependency Mapping Inventory (DDMI) 7.50, 7.51, 7.60, 7.61, 7.70, and 9.30 launches the Windows SNMP service with its default configuration, which allows remote attackers to obtain potentially sensitive information or have unspecified other impact by leveraging the public read community.Show less
1Hp
1Client Automation Enterprise
Apr 29, 2026
Mar 16, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in HP Client Automation Enterprise (aka HPCA or Radia Notify) 5.11, 7.2, 7.5, 7.8, and 7.9 allows remote attackers to execute arbitrary code via unknown vectors.
1Hp
1Power Manager
Apr 29, 2026
Mar 14, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2)...Show more
Multiple cross-site scripting (XSS) vulnerabilities in HP Power Manager (HPPM) 4.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the logType parameter to Contents/exportlogs.asp, (2) the Id parameter to Contents/pagehelp.asp, or the (3) SORTORD or (4) SORTCOL parameter to Contents/applicationlogs.asp. NOTE: some of these details are obtained from third party information.Show less
1Hp
1Multifunction Peripheral Digital Sending Software
Apr 29, 2026
Mar 7, 2011
N/A· v4
N/A· v3
2.1 LOW· v2
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via...Show more
HP Multifunction Peripheral (MFP) Digital Sending Software (DSS) 4.91.00 does not properly configure authentication settings of managed devices within device templates, which allows attackers to access these devices via actions that were intended to require authentication.Show less
1Hp
1Web Jetadmin
Apr 29, 2026
Mar 1, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in HP Web Jetadmin 10.2 Service Release 3 and 4 allows local users to bypass intended access restrictions via unknown vectors.
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, a...Show more
The client in HP Data Protector does not verify the contents of files associated with the EXEC_CMD command, which allows remote attackers to execute arbitrary script code by providing this code with a trusted filename, as demonstrated by omni_chk_ds.sh.Show less
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
1Hp
1Data Protector
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by...Show more
crs.exe in the Cell Manager Service in the client in HP Data Protector does not properly validate credentials associated with the hostname, domain, and username, which allows remote attackers to execute arbitrary code by sending unspecified data over TCP, related to the webreporting client, the applet domain, and the java username.Show less
1Hp
1Power Manager
Apr 29, 2026
Feb 9, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in HP Power Manager (HPPM) 4.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative accounts.
1Hp
1Openview Performance Insight
Apr 29, 2026
Feb 2, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPo...Show more
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.Show less
1Hp
1Openview Storage Data Protector
Apr 29, 2026
Jan 28, 2011
N/A· v4
N/A· v3
7.1 HIGH· v2
Unspecified vulnerability in HP OpenView Storage Data Protector 6.0, 6.10, and 6.11 allows remote attackers to cause a denial of service via unknown vectors.
1Hp
1Openview Storage Data Protector Cell Manager
Apr 29, 2026
Jan 25, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in crs.exe in HP OpenView Storage Data Protector Cell Manager 6.11 allows remote attackers to execute arbitrary code via unspecified message types.
1Hp
2Business Availability Center
Business Service Management
Apr 29, 2026
Jan 24, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web...Show more
Cross-site scripting (XSS) vulnerability in HP Business Availability Center (BAC) 7.x through 7.55 and 8.x through 8.05, and Business Service Management (BSM) through 9.01, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Hp
1Data Protector Manager
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash) via a packet with a large data size to TCP port 1530.
1Hp
1Linux Imaging And Printing Project
Apr 29, 2026
Jan 20, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denia...Show more
Stack-based buffer overflow in the hpmud_get_pml function in io/hpmud/pml.c in Hewlett-Packard Linux Imaging and Printing (HPLIP) 1.6.7, 3.9.8, 3.10.9, and probably other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SNMP response with a large length value.Show less
1Hp
1Loadrunner
Apr 29, 2026
Jan 18, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.
1Hp
1Openview Network Node Manager
Apr 29, 2026
Jan 13, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this...Show more
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "command injection vulnerability."Show less