← Back

Hp

hp

2,335 CVEs • 17,248 products

Products (17,248)

Click to collapse
Toggle
Hp Ux
hp-ux
Instantos
instantos
Tru64
tru64
Loadrunner
loadrunner
Sitescope
sitescope
Openvms
openvms
Oneview
oneview

CVEs (2,335)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
1Intelligent Management Center
Nov 21, 2024
Oct 19, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
1Hp
14Elite X2 1012 G1 Firmware
Elite X2 1012 G2 FirmwareElitebook 1030 G1 Firmware+11 more
Nov 21, 2024
Aug 12, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
3Hp
LenovoSynaptics
112Envy 13t Ah100 Firmware
Envy 13t Aq100 FirmwareEnvy 17t Bw000 Firmware+109 more
Nov 21, 2024
Jul 22, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise c...Show more
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.Show less
3Hp
LenovoSynaptics
133Elite Slice Firmware
Elite X2 1012 G2 FirmwareElite X2 1013 G3 Firmware+130 more
Nov 21, 2024
Jul 22, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the...Show more
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.Show less
1Hp
1Nagios Plugins Hpilo
Nov 21, 2024
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
1Hp
1Mse Msg Gw Application E Ltu
Nov 21, 2024
Jul 17, 2020
N/A· v4
6.6 MEDIUM· v3
5.4 MEDIUM· v2
HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3....Show more
HPE has found a potential Remote Access Restriction Bypass in HPE MSE Msg Gw application E-LTU prior to version 3.2 when HTTPS is used between the USSD and an external USSD service logic application. Update to version 3.2 and update the HTTPS configuration as described in the HPE MSE Messaging Gateway Configuration and Operations Guide.Show less
1Hp
2Icewall Sso Dfw
Icewall Sso Dgfw
Nov 21, 2024
Jul 8, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulner...Show more
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccessShow less
21Asus
BroadcomCanon+18 more
2175020 Z4a69a
5030 M2u92b5030 Z4a70a+214 more
Nov 21, 2024
Jun 8, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.Show less