Lucene search

K

Hp Security Vulnerabilities

cve
cve

CVE-2020-7174

A soapconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7175

A iccselectdymicparam expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7176

A viewtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
31
cve
cve

CVE-2020-7177

A wmiconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
20
cve
cve

CVE-2020-7178

A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
30
cve
cve

CVE-2020-7179

A thirdpartyperfselecttask expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
25
cve
cve

CVE-2020-7180

A ictexpertdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
28
cve
cve

CVE-2020-7181

A smsrulesdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7182

A sshconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
26
cve
cve

CVE-2020-7183

A forwardredirect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7184

A viewbatchtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
23
cve
cve

CVE-2020-7185

A tvxlanlegend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
26
cve
cve

CVE-2020-7186

A powershellconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7187

A reportpage index expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9.1AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7188

A userselectpagingcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
25
cve
cve

CVE-2020-7189

A faultflasheventselectfact expression language injectionremote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

8.8AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7190

A deviceselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
47
cve
cve

CVE-2020-7191

A devsoftsel expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
23
cve
cve

CVE-2020-7192

A devicethresholdconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
50
cve
cve

CVE-2020-7193

A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
19
cve
cve

CVE-2020-7194

A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
41
cve
cve

CVE-2020-7195

A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

8.8CVSS

9AI Score

0.002EPSS

2020-10-19 06:15 PM
22
cve
cve

CVE-2020-7196

The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the u...

6.5CVSS

6.4AI Score

0.001EPSS

2020-10-26 04:15 PM
24
cve
cve

CVE-2020-7197

SSMC3.7.0.0 is vulnerable to remote authentication bypass. HPE StoreServ Management Console (SSMC) 3.7.0.0 is an off node multiarray manager web application and remains isolated from data on the managed arrays. HPE has provided an update to HPE StoreServ Management Console (SSMC) software 3.7.0.0* ...

9.8CVSS

9.5AI Score

0.005EPSS

2020-10-26 04:15 PM
16
cve
cve

CVE-2020-7198

There is a remote escalation of privilege possible for a malicious user that has a OneView account in OneView and Synergy Composer. HPE has provided updates to Oneview and Synergy Composer: Update to version 5.5 of OneView, Composer, or Composer2.

8.8CVSS

9AI Score

0.004EPSS

2020-11-06 03:15 PM
28
cve
cve

CVE-2020-7199

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access...

9.8CVSS

9.6AI Score

0.006EPSS

2020-12-02 01:15 AM
69
cve
cve

CVE-2020-7200

A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.

9.8CVSS

9.5AI Score

0.695EPSS

2020-12-18 11:15 PM
162
22
cve
cve

CVE-2020-7201

A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).

8.8CVSS

8.6AI Score

0.001EPSS

2020-12-18 11:15 PM
43
3
cve
cve

CVE-2020-7202

A potential security vulnerability has been identified in HPE Integrated Lights-Out 5 (iLO 5) and Integrated Lights-Out 4 (iLO 4) firmware. The vulnerability could be remotely exploited to disclose the serial number and other information.

5.3CVSS

5.2AI Score

0.001EPSS

2021-01-05 03:15 PM
33
2
cve
cve

CVE-2020-7203

A potential security vulnerability has been identified in HPE iLO Amplifier Pack server version 1.70. The vulnerability could be exploited to allow remote code execution.

9.8CVSS

9.6AI Score

0.006EPSS

2020-12-18 11:15 PM
50
3
cve
cve

CVE-2020-7206

HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.

9.8CVSS

9.6AI Score

0.002EPSS

2020-07-17 10:15 PM
29
cve
cve

CVE-2020-7207

A local elevation of privilege using physical access security vulnerability was found in HPE Proliant Gen10 Servers using Intel Innovation Engine (IE). This attack requires a physical attack to the server motherboard. To mitigate this issue, ensure your server is always physically secured. HPE will...

6.8CVSS

6.4AI Score

0.001EPSS

2020-11-05 09:15 PM
57
cve
cve

CVE-2020-7208

LinuxKI v6.0-1 and earlier is vulnerable to an XSS which is resolved in release 6.0-2.

6.1CVSS

5.9AI Score

0.001EPSS

2020-02-13 12:15 AM
71
cve
cve

CVE-2020-7209

LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

9.8CVSS

9.5AI Score

0.972EPSS

2020-02-13 12:15 AM
166
In Wild
2
cve
cve

CVE-2021-24533

The Maintenance WordPress plugin before 4.03 does not sanitise or escape some of its settings, allowing high privilege users such as admin to se Cross-Site Scripting payload in them (even when the unfiltered_html capability is disallowed), which will be triggered in the frontend

4.8CVSS

4.7AI Score

0.001EPSS

2021-08-23 12:15 PM
25
cve
cve

CVE-2021-24950

The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in the insight_customizer_options_import (available to any authenticated user), does not validate user input before passing it to unserialize(), nor sanitise and escape it before outputting it in the respo...

5.4CVSS

5.3AI Score

0.001EPSS

2022-03-14 03:15 PM
65
cve
cve

CVE-2021-25139

A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulner...

9.8CVSS

9.7AI Score

0.006EPSS

2021-02-09 05:15 PM
24
4
cve
cve

CVE-2021-25140

A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to setup and configure an HPE Moonshot 1500 chassis. This vulner...

9.8CVSS

9.5AI Score

0.006EPSS

2021-02-09 05:15 PM
20
4
cve
cve

CVE-2021-26582

A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).

6.1CVSS

6AI Score

0.001EPSS

2021-04-15 06:15 PM
31
4
cve
cve

CVE-2021-26583

A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.

9.8CVSS

9.7AI Score

0.006EPSS

2021-05-10 01:15 PM
16
4
cve
cve

CVE-2021-26584

A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).

6.1CVSS

6.3AI Score

0.001EPSS

2021-06-03 11:15 AM
20
2
cve
cve

CVE-2021-26586

A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made software updates available to resolve the v...

7.5CVSS

7.3AI Score

0.003EPSS

2021-08-05 09:15 PM
43
cve
cve

CVE-2021-29201

A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s):...

4.8CVSS

5.1AI Score

0.001EPSS

2021-05-25 02:15 PM
23
2
cve
cve

CVE-2021-29202

A local buffer overflow vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H ...

6.7CVSS

6.6AI Score

0.0004EPSS

2021-05-25 02:15 PM
20
2
cve
cve

CVE-2021-29203

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, ga...

9.8CVSS

9.6AI Score

0.956EPSS

2021-05-06 09:15 PM
97
4
cve
cve

CVE-2021-29204

A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s):...

4.8CVSS

5.1AI Score

0.001EPSS

2021-05-25 02:15 PM
22
2
cve
cve

CVE-2021-29205

A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s):...

4.8CVSS

5.1AI Score

0.001EPSS

2021-05-25 02:15 PM
19
4
cve
cve

CVE-2021-29206

A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s):...

4.8CVSS

5.1AI Score

0.001EPSS

2021-05-25 02:15 PM
20
2
cve
cve

CVE-2021-29207

A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380 Gen10 H version(s):...

4.8CVSS

5.1AI Score

0.001EPSS

2021-05-25 02:15 PM
15
2
cve
cve

CVE-2021-29208

A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrated Lights-Out 5 (iLO 5) for HPE Gen10 Servers; HPE SimpliVity 380 Gen10; HPE SimpliVity 2600; HPE SimpliVity 380 Gen10 G; HPE SimpliVity 325; HPE SimpliVity 380...

4.8CVSS

5.3AI Score

0.001EPSS

2021-05-25 03:15 PM
22
2
Total number of security vulnerabilities2181