Vulnerabilities > HPE > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-11-27 CVE-2024-53676 Path Traversal vulnerability in HPE Insight Remote Support 7.12/7.12.0.529/7.12.0.545
A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution.
network
low complexity
hpe CWE-22
critical
9.8
2024-11-26 CVE-2024-53673 Deserialization of Untrusted Data vulnerability in HPE Insight Remote Support 7.12/7.12.0.529/7.12.0.545
A java deserialization vulnerability in HPE Remote Insight Support may allow an unauthenticated attacker to execute code.
network
low complexity
hpe CWE-502
critical
9.8
2024-06-13 CVE-2024-22441 Improper Authentication vulnerability in HPE Cray Parallel Application Launch Service
HPE Cray Parallel Application Launch Service (PALS) is subject to an authentication bypass.
network
low complexity
hpe CWE-287
critical
9.8
2023-12-19 CVE-2023-50272 Unspecified vulnerability in HPE products
A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 6 (iLO 6).
network
low complexity
hpe
critical
9.8
2023-10-25 CVE-2023-30912 Unspecified vulnerability in HPE Oneview 8.30.01
A remote code execution issue exists in HPE OneView.
network
low complexity
hpe
critical
9.8
2023-08-29 CVE-2023-39268 Out-of-bounds Write vulnerability in HPE Arubaos-Switch
A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets.
network
low complexity
hpe CWE-787
critical
9.8
2023-03-01 CVE-2022-37936 Deserialization of Untrusted Data vulnerability in HPE Serviceguard for Linux
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
network
low complexity
hpe CWE-502
critical
9.8
2023-03-01 CVE-2022-37937 Out-of-bounds Write vulnerability in HPE Serviceguard for Linux
Pre-auth memory corruption in HPE Serviceguard
network
low complexity
hpe CWE-787
critical
9.8
2023-03-01 CVE-2022-37938 Server-Side Request Forgery (SSRF) vulnerability in HPE Serviceguard for Linux
Unauthenticated server side request forgery in HPE Serviceguard Manager
network
low complexity
hpe CWE-918
critical
9.8
2022-12-12 CVE-2022-37932 Unspecified vulnerability in HPE products
A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches.
network
low complexity
hpe
critical
9.8