Vulnerabilities (CVE)

Total 398490 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-37112 2026-06-17 N/A 6.0 MEDIUM
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
CVE-2025-37111 2026-06-17 N/A 6.0 MEDIUM
A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
CVE-2025-37110 2026-06-17 N/A 6.0 MEDIUM
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
CVE-2025-37109 2026-06-17 N/A 3.5 LOW
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-37108 2026-06-17 N/A 3.5 LOW
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-37107 1 Hpe 1 Autopass License Server 2026-06-17 N/A 7.3 HIGH
An authentication bypass vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37106 1 Hpe 1 Autopass License Server 2026-06-17 N/A 7.3 HIGH
An authentication bypass and disclosure of information vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37105 1 Hpe 1 Autopass License Server 2026-06-17 N/A 7.5 HIGH
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37104 2026-06-17 N/A 7.1 HIGH
A security vulnerability has been identified in HPE Telco Service Orchestrator software. The vulnerability could allow authenticated clients to to perform a SQL Injection attack when sending a service request, and potentially exfiltrate the database's vendor name to unauthorized authenticated clients.
CVE-2025-37103 2026-06-17 N/A 9.8 CRITICAL
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.
CVE-2025-37102 2026-06-17 N/A 7.2 HIGH
An authenticated command injection vulnerability exists in the Command line interface of HPE Networking Instant On Access Points. A successful exploitation could allow a remote attacker with elevated privileges to execute arbitrary commands on the underlying operating system as a highly privileged user.
CVE-2025-37101 2026-06-17 N/A 8.7 HIGH
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).
CVE-2025-37100 2026-06-17 N/A 7.7 HIGH
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users. A successful exploitation could allow an attacker to iteratively navigate through the filesystem and ultimately download protected system files containing sensitive information.
CVE-2025-37099 1 Hpe 1 Insight Remote Support 2026-06-17 N/A 9.8 CRITICAL
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-37098 1 Hpe 1 Insight Remote Support 2026-06-17 N/A 7.5 HIGH
A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-37097 1 Hpe 1 Insight Remote Support 2026-06-17 N/A 7.5 HIGH
A vulnerability in HPE Insight Remote Support (IRS) prior to v7.15.0.646 may allow an unauthenticated denial of service
CVE-2025-37096 1 Hpe 1 Storeonce System 2026-06-17 N/A 9.8 CRITICAL
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37095 1 Hpe 1 Storeonce System 2026-06-17 N/A 9.8 CRITICAL
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
CVE-2025-37094 1 Hpe 1 Storeonce System 2026-06-17 N/A 5.5 MEDIUM
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
CVE-2025-37093 1 Hpe 1 Storeonce System 2026-06-17 N/A 9.8 CRITICAL
An authentication bypass vulnerability exists in HPE StoreOnce Software.