HP Inc.

First CVE: Nov 17, 2009Active for: 17 years
912
CVEs Published
More CVEs Published than 90% of tracked CNAs
50.7
Avg CVEs / Year
More Avg CVEs / Year than 84% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 79% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by HP Inc. as a CNA, 95.3% affect products that HP Inc. develops as a vendor.

95.3%
Self-reported: 869Third-party: 43

Of all the CVEs published that affect products developed by HP Inc., 34.5% are self-published by HP Inc. as a CNA.

34.5%
65.5%
Self-published: 869Published by other CNAs: 1,648

Trends Over Time

The number and severity of CVEs published by HP Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2009
16 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Top CVEs

All CVEs published by HP Inc. as a CNA, regardless of affected vendor or product.

912 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code
Sep 16, 20139.896YESYES
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.
Jul 18, 201410.090NOYES
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow remote attackers to execute arbitrary code via a request con
Jul 1, 201110.089NOYES
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exp
Jan 23, 20189.888NOYES
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attacker
Feb 2, 201110.087NOYES
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680.
Jun 6, 201310.086NOYES
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload att
Nov 24, 200910.086NOYES
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attack
Jul 28, 201010.085NOYES
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.
May 7, 201010.085NOYES
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a
Jan 13, 201110.084NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA912 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local127 (13.9%)
Network114 (12.5%)
Unknown636 (69.7%)
Physical16 (1.8%)
Adjacent Network16 (1.8%)
Attack Complexity
Low249 (27.3%)
High27 (3.0%)
Unknown636 (69.7%)
User Interaction
None235 (25.8%)
Unknown636 (69.7%)
Required37 (4.1%)
Privileges Required
Low107 (11.7%)
High39 (4.3%)
None130 (14.3%)
Unknown636 (69.7%)

Exploit Exposure

Signals from CVEs in this cna scope (912 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 79th percentile
Metasploit
57 CVEs
6.2% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
66 CVEs
7.2% of CVEs· 98th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by HP Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by HP Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs