Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

HP Inc.

First CVE: Dec 31, 1990Active for: 36 yearsTotal CVEs: 2,517
59.0
VTI Score
TOP TARGET

HP Inc. maintains a dominant portfolio spanning enterprise computing systems, printers, and management software, presenting one of the largest and most heterogeneous attack surfaces in the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability; the exposure crosses operating systems such as HP-UX and a broad range of management and network-operations applications. The recurring weakness classes reflect HP's varied codebase and deployment contexts, centering on input-handling flaws including cross-site scripting, improper input validation, and memory-safety issues that arise across web interfaces, system utilities, and network management products. Defenders should treat HP advisories as broadly applicable given the vendor's wide embedded presence in enterprise infrastructure and give priority to internet-facing management platforms; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
2,517
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by HP Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 1990
35 years ago
Most Recent CVE
May 20, 2026
65 days ago

Self-Reporting Analysis

Of all the CVEs published by HP Inc. as a CNA, 95.3% affect products that HP Inc. develops as a vendor.

95.3%
Self-reported: 869 (95.3%)
Third-party: 43 (4.7%)

Of all the CVEs published that affect products developed by HP Inc., 34.5% are self-published by HP Inc. as a CNA.

34.5%
65.5%
Self-published: 869 (34.5%)
Other CNAs: 1,648 (65.5%)

Products(17,234 total)

Top CVEs

Signals from CVEs in this vendor scope (2517 CVEs).

2,517 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5638CRITICAL
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem
Mar 11, 20179.899YESYES
CVE-2012-1823CRITICAL
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign)
May 11, 20129.899YESYES
CVE-2015-3113CRITICAL
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack
Jun 23, 20159.898YESYES
CVE-2005-2773CRITICAL
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (
Sep 2, 20059.897YESYES
CVE-2013-4810CRITICAL
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code
Sep 16, 20139.896YESYES
CVE-2017-12542CRITICAL
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
Feb 15, 201810.095NOYES
CVE-2020-7209CRITICAL
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
Feb 13, 20209.894NOYES
CVE-2016-2004CRITICAL
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication.
Apr 21, 20169.893NOYES
CVE-2015-8651HIGH
Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adob
Dec 28, 20158.892YESNO
CVE-2019-5736HIGH
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
View all 2,517 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products2,517 CVEs
36%
50%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local216 (8.6%)
Network945 (37.5%)
Unknown1,313 (52.2%)
Physical22 (0.9%)
Adjacent Network21 (0.8%)
Attack Complexity
Low1,099 (43.7%)
High105 (4.2%)
Unknown1,313 (52.2%)
User Interaction
None1,025 (40.7%)
Unknown1,313 (52.2%)
Required179 (7.1%)
Privileges Required
Low495 (19.7%)
High78 (3.1%)
None631 (25.1%)
Unknown1,313 (52.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (2517 CVEs).

CISA KEV
6 CVEs
0.2% of CVEs· 99th percentile
Metasploit
100 CVEs
4.0% of CVEs· 98th percentile
Nuclei
10 CVEs
0.4% of CVEs· 95th percentile
ExploitDB
233 CVEs
9.3% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by HP Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by HP Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For HP Inc.'s Products

View all 25 CNAs →

Top CWEs