Search Results (343 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-37148 1 Hpe 1 Arubaos 2026-04-15 6.5 Medium
A vulnerability in the parsing of ethernet frames in AOS-8 Instant and AOS 10 could allow an unauthenticated remote attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to potentially disrupt network services and require manual intervention to restore functionality.
CVE-2025-37147 1 Hpe 1 Arubaos 2026-04-15 7.1 High
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points.
CVE-2025-37146 1 Hpe 1 Arubaos 2026-04-15 7.2 High
A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVE-2025-37108 1 Hpe 1 Telco Service Activator 2026-04-15 3.5 Low
Cross-site scripting vulnerability has been identified in HPE Telco Service Activator product
CVE-2025-37139 1 Hpe 1 Arubaos 2026-04-15 6 Medium
A vulnerability in an AOS firmware binary allows an authenticated malicious actor to permanently delete necessary boot information. Successful exploitation may render the system unbootable, resulting in a Denial of Service that can only be resolved by replacing the affected hardware.
CVE-2025-37122 2 Arubanetworks, Hpe 2 Clearpass Policy Manager, Aruba Networking Clearpass Policy Manager 2026-04-15 6.1 Medium
A vulnerability in the web-based management interface of network access control services could allow an unauthenticated remote attacker to conduct a Reflected Cross-Site Scripting (XSS) attack. Successful exploitation could allow an attacker to execute arbitrary JavaScript code in a victim's browser in the context of the affected interface.
CVE-2025-37110 1 Hpe 1 Telco Network Function Virtual Orchestrator 2026-04-15 6 Medium
A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Telco Network Function Virtual Orchestrator. Successful Exploitation could lead to unauthorized parties gaining access to sensitive system information.
CVE-2025-37149 1 Hpe 1 Proliant Rl300 Gen11 2026-04-15 6 Medium
A potential out-of-bound reads vulnerability in HPE ProLiant RL300 Gen11 Server's UEFI firmware.
CVE-2024-51765 1 Hpe 1 Cray System Management Software 2026-04-15 5.5 Medium
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration, this vulnerability may lead to local/cluster unauthorized access.
CVE-2026-23818 1 Hpe 2 Aruba Networking Private 5g Core, Private 5g Core 2026-04-14 8.8 High
A vulnerability has been identified in the graphical user interface (GUI) of HPE Aruba Networking Private 5G Core On-Prem that could allow an attacker to abuse an open redirect vulnerability in the login flow using a crafted URL. Successful exploitation may redirect an authenticated user to an attacker-controlled server hosting a spoofed login page prompting the unsuspecting victim to give away their credentials, which could then be captured by the attacker, before being redirected back to the legitimate login page.
CVE-2025-37184 2 Arubanetworks, Hpe 2 Edgeconnect Sd-wan Orchestrator, Edgeconnect Sd-wan Orchestrator 2026-03-03 9.8 Critical
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.
CVE-2025-37099 1 Hpe 1 Insight Remote Support 2026-02-26 9.8 Critical
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-37089 1 Hpe 1 Storeonce System 2026-02-26 9.8 Critical
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37091 1 Hpe 1 Storeonce System 2026-02-26 7.2 High
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37092 1 Hpe 1 Storeonce System 2026-02-26 9.8 Critical
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37093 1 Hpe 1 Storeonce System 2026-02-26 9.8 Critical
An authentication bypass vulnerability exists in HPE StoreOnce Software.
CVE-2025-37096 1 Hpe 1 Storeonce System 2026-02-26 9.8 Critical
A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2024-51768 1 Hpe 1 Autopass License Server 2026-02-26 8 High
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
CVE-2025-37105 1 Hpe 1 Autopass License Server 2026-02-26 7.5 High
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
CVE-2025-37132 2 Arubanetworks, Hpe 2 Arubaos, Arubaos 2026-02-26 7.2 High
An arbitrary file write vulnerability exists in the web-based management interface of both the AOS-10 GW and AOS-8 Controller/Mobility Conductor operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files and execute arbitrary commands on the underlying operating system.