Hewlett Packard Enterprise (HPE)
Self-Reporting Analysis
Of all the CVEs published by Hewlett Packard Enterprise (HPE) as a CNA, 12.6% affect products that Hewlett Packard Enterprise (HPE) develops as a vendor.
Of all the CVEs published that affect products developed by Hewlett Packard Enterprise (HPE), 88.0% are self-published by Hewlett Packard Enterprise (HPE) as a CNA.
Trends Over Time
The number and severity of CVEs published by Hewlett Packard Enterprise (HPE) over time
Top CVEs
All CVEs published by Hewlett Packard Enterprise (HPE) as a CNA, regardless of affected vendor or product.
1,336 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-37164CRITICAL A remote code execution issue exists in HPE OneView. | Dec 16, 2025 | 9.8 | 98 | YES | YES |
CVE-2017-9822HIGH DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites." | Jul 20, 2017 | 8.8 | 98 | YES | YES |
CVE-2017-12542CRITICAL A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | Feb 15, 2018 | 10.0 | 95 | NO | YES |
CVE-2020-7209CRITICAL LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Feb 13, 2020 | 9.8 | 94 | NO | YES |
CVE-2017-5816CRITICAL A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Feb 15, 2018 | 9.8 | 89 | NO | YES |
CVE-2017-5817CRITICAL A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found. | Feb 15, 2018 | 9.8 | 84 | NO | YES |
CVE-2017-12557CRITICAL A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found. | Feb 15, 2018 | 9.8 | 83 | NO | YES |
CVE-2020-7200CRITICAL A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerability could be exploited to allow remote code execution. | Dec 18, 2020 | 9.8 | 82 | NO | YES |
CVE-2020-7136CRITICAL A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update | Apr 30, 2020 | 9.8 | 79 | NO | YES |
CVE-2021-29203CRITICAL A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The v | May 6, 2021 | 9.8 | 78 | NO | YES |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (1336 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Hewlett Packard Enterprise (HPE) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Hewlett Packard Enterprise (HPE) as a CNA — matched by CVE ID, not by organization name.