Hewlett Packard Enterprise (HPE)

First CVE: Oct 28, 2016Active for: 10 years
1,336
CVEs Published
More CVEs Published than 92% of tracked CNAs
121.5
Avg CVEs / Year
More Avg CVEs / Year than 91% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 80% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Hewlett Packard Enterprise (HPE) as a CNA, 12.6% affect products that Hewlett Packard Enterprise (HPE) develops as a vendor.

12.6%
87.4%
Self-reported: 168Third-party: 1,168

Of all the CVEs published that affect products developed by Hewlett Packard Enterprise (HPE), 88.0% are self-published by Hewlett Packard Enterprise (HPE) as a CNA.

88.0%
12.0%
Self-published: 168Published by other CNAs: 23

Trends Over Time

The number and severity of CVEs published by Hewlett Packard Enterprise (HPE) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 28, 2016
9 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Hewlett Packard Enterprise (HPE) as a CNA, regardless of affected vendor or product.

1,336 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A remote code execution issue exists in HPE OneView.
Dec 16, 20259.898YESYES
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Jul 20, 20178.898YESYES
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
Feb 15, 201810.095NOYES
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
Feb 13, 20209.894NOYES
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Feb 15, 20189.889NOYES
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
Feb 15, 20189.884NOYES
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.
Feb 15, 20189.883NOYES
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution.
Dec 18, 20209.882NOYES
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update
Apr 30, 20209.879NOYES
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The v
May 6, 20219.878NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,336 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local148 (11.1%)
Network1,145 (85.7%)
Unknown0 (0.0%)
Physical8 (0.6%)
Adjacent Network35 (2.6%)
Attack Complexity
Low1,273 (95.3%)
High63 (4.7%)
Unknown0 (0.0%)
User Interaction
None1,170 (87.6%)
Unknown0 (0.0%)
Required166 (12.4%)
Privileges Required
Low512 (38.3%)
High280 (21.0%)
None544 (40.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1336 CVEs).

CISA KEV
2 CVEs
0.1% of CVEs· 80th percentile
Metasploit
8 CVEs
0.6% of CVEs· 84th percentile
Nuclei
10 CVEs
0.7% of CVEs· 79th percentile
ExploitDB
25 CVEs
1.9% of CVEs· 88th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Hewlett Packard Enterprise (HPE) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Hewlett Packard Enterprise (HPE) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs