Hewlett Packard Enterprise (HPE) operates as a major infrastructure and enterprise-systems vendor whose vulnerability footprint spans a large portfolio of server hardware, storage, and management platforms deployed across data centers and enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, particularly across its ProLiant server line, where exposures center on memory-safety issues, path-traversal weaknesses, and command-injection flaws in management and firmware components. The recurring products—principally the ProLiant DL-series server platforms—and the durable weakness classes reflect the complexity of embedded firmware, BIOS interfaces, and system-management stacks that sit in privileged positions within deployed infrastructure. Defenders should treat HPE infrastructure advisories as high-priority for inventory and patching cycles, particularly where server management interfaces are network-accessible; current exploitation status and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hewlett Packard Enterprise (HPE) over time
Of all the CVEs published by Hewlett Packard Enterprise (HPE) as a CNA, 12.6% affect products that Hewlett Packard Enterprise (HPE) develops as a vendor.
Of all the CVEs published that affect products developed by Hewlett Packard Enterprise (HPE), 88.0% are self-published by Hewlett Packard Enterprise (HPE) as a CNA.
Signals from CVEs in this vendor scope (191 CVEs).
191 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5689CRITICAL An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (IS | May 2, 2017 | 9.8 | 99 | YES | YES |
CVE-2025-37164CRITICAL A remote code execution issue exists in HPE OneView. | Dec 16, 2025 | 9.8 | 98 | YES | YES |
CVE-2020-7136CRITICAL A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update | Apr 30, 2020 | 9.8 | 79 | NO | YES |
CVE-2024-53675HIGH An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | Nov 26, 2024 | 7.5 | 70 | NO | NO |
CVE-2016-7434HIGH The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query. | Jan 13, 2017 | 7.5 | 65 | NO | YES |
CVE-2024-53676CRITICAL A directory traversal vulnerability in Hewlett Packard Enterprise Insight Remote Support may allow remote code execution. | Nov 27, 2024 | 9.8 | 61 | NO | NO |
CVE-2024-53674HIGH An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. | Nov 26, 2024 | 7.5 | 47 | NO | NO |
CVE-2022-37932CRITICAL A potential security vulnerability has been identified in Hewlett Packard Enterprise OfficeConnect 1820, 1850, and 1920S Network switches. The vulnerability could be remotely explo | Dec 12, 2022 | 9.8 | 44 | NO | YES |
CVE-2002-20001HIGH The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-s | Nov 11, 2021 | 7.5 | 38 | NO | NO |
CVE-2025-37098HIGH A path traversal vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646. | Jul 1, 2025 | 7.5 | 37 | NO | NO |
Signals from CVEs in this vendor scope (191 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hewlett Packard Enterprise (HPE).
Media articles that mention a CVE ID that affects a product developed by Hewlett Packard Enterprise (HPE) — matched by CVE ID, not by vendor name.