Latest CVE Feed
-
10.0
HIGHCVE-2021-26588
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This v... Read more
- EPSS Score: %1.71
- Published: Oct. 11, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26587
A potential DOM-based Cross Site Scripting security vulnerability has been identified in HPE StoreOnce. The vulnerability could be remotely exploited to cause an elevation of privilege leading to partial impact to confidentiality, availability, and integr... Read more
- EPSS Score: %0.51
- Published: Sep. 27, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26586
A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to disclose sensitive information. HPE has made... Read more
- EPSS Score: %0.30
- Published: Aug. 05, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26585
A potential vulnerability has been identified in HPE OneView Global Dashboard release 2.31 which could lead to a local disclosure of privileged information. HPE has provided an update to OneView Global Dashboard. The issue is resolved in 2.32.... Read more
Affected Products : oneview_global_dashboard- EPSS Score: %0.05
- Published: Jun. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26584
A security vulnerability in HPE OneView for VMware vCenter (OV4VC) could be exploited remotely to allow Cross-Site Scripting. HPE has released the following software update to resolve the vulnerability in HPE OneView for VMware vCenter (OV4VC).... Read more
Affected Products : oneview_for_vmware_vcenter- EPSS Score: %0.46
- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26583
A potential security vulnerability was identified in HPE iLO Amplifier Pack. The vulnerabilities could be remotely exploited to allow remote code execution.... Read more
Affected Products : ilo_amplifier_pack- EPSS Score: %2.58
- Published: May. 10, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26582
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).... Read more
- EPSS Score: %0.30
- Published: Apr. 15, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26581
A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be remotely exploited leaving hung connections to the BMC web interface. The monarch BMC must be rebooted to recover from this situation. O... Read more
- EPSS Score: %0.37
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26580
A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS). HPE has provided the following software update to resolve the vulnerability in HPE iLO Amp... Read more
- EPSS Score: %0.32
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26579
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.0 of HPE Unified... Read more
Affected Products : unified_data_management- EPSS Score: %0.05
- Published: Mar. 30, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26578
A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The vulnerability could be remotely exploited with SQL injection.... Read more
Affected Products : network_orchestrator- EPSS Score: %0.35
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26577
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so uploadsshkey function.... Read more
- EPSS Score: %0.07
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26576
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.... Read more
- EPSS Score: %0.12
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26575
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.... Read more
- EPSS Score: %0.12
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26574
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.... Read more
- EPSS Score: %0.12
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26573
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgeneratesslcfg function.... Read more
- EPSS Score: %0.13
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26572
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.... Read more
- EPSS Score: %0.13
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26571
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.... Read more
- EPSS Score: %0.13
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26570
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webifc_setadconfig function.... Read more
- EPSS Score: %0.12
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26559
Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User role to get Airflow Configurations including sensitive information even when `[webserver] expose_config` is set to `False` in `airflow... Read more
Affected Products : airflow- EPSS Score: %0.30
- Published: Feb. 17, 2021
- Modified: Nov. 21, 2024