HP Inc. maintains a dominant portfolio spanning enterprise computing systems, printers, and management software, presenting one of the largest and most heterogeneous attack surfaces in the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability; the exposure crosses operating systems such as HP-UX and a broad range of management and network-operations applications. The recurring weakness classes reflect HP's varied codebase and deployment contexts, centering on input-handling flaws including cross-site scripting, improper input validation, and memory-safety issues that arise across web interfaces, system utilities, and network management products. Defenders should treat HP advisories as broadly applicable given the vendor's wide embedded presence in enterprise infrastructure and give priority to internet-facing management platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by HP Inc. over time
Of all the CVEs published by HP Inc. as a CNA, 95.3% affect products that HP Inc. develops as a vendor.
Of all the CVEs published that affect products developed by HP Inc., 34.5% are self-published by HP Inc. as a CNA.
Signals from CVEs in this vendor scope (2517 CVEs).
2,517 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5638CRITICAL The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attem | Mar 11, 2017 | 9.8 | 99 | YES | YES |
CVE-2012-1823CRITICAL sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) | May 11, 2012 | 9.8 | 99 | YES | YES |
CVE-2015-3113CRITICAL Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack | Jun 23, 2015 | 9.8 | 98 | YES | YES |
CVE-2005-2773CRITICAL HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, ( | Sep 2, 2005 | 9.8 | 97 | YES | YES |
CVE-2013-4810CRITICAL HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code | Sep 16, 2013 | 9.8 | 96 | YES | YES |
CVE-2017-12542CRITICAL A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. | Feb 15, 2018 | 10.0 | 95 | NO | YES |
CVE-2020-7209CRITICAL LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. | Feb 13, 2020 | 9.8 | 94 | NO | YES |
CVE-2016-2004CRITICAL HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. | Apr 21, 2016 | 9.8 | 93 | NO | YES |
CVE-2015-8651HIGH Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adob | Dec 28, 2015 | 8.8 | 92 | YES | NO |
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
Signals from CVEs in this vendor scope (2517 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by HP Inc..
Media articles that mention a CVE ID that affects a product developed by HP Inc. — matched by CVE ID, not by vendor name.