H500s
Vendor:
First CVE: Jul 30, 2019 · Active for 6 years
315
Total CVEs
More Total CVEs than 100% of tracked products
45.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
3.2%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact H500s over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2019
6 years ago
Most Recent CVE
Mar 11, 2025
503 days ago
CVE Severity & Scoring
H500s315 CVEs
29%
63%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local166 (52.7%)
Network141 (44.8%)
Unknown0 (0.0%)
Physical4 (1.3%)
Adjacent Network4 (1.3%)
Attack Complexity
Low246 (78.1%)
High69 (21.9%)
Unknown0 (0.0%)
User Interaction
None286 (90.8%)
Unknown0 (0.0%)
Required29 (9.2%)
Privileges Required
Low165 (52.4%)
High12 (3.8%)
None138 (43.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (315 CVEs).
315 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4911HIGH A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us | Oct 3, 2023 | 7.8 | 98 | YES | YES |
CVE-2022-0847HIGH A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker | Mar 10, 2022 | 7.8 | 98 | YES | YES |
CVE-2021-22555HIGH A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory | Jul 7, 2021 | 7.8 | 96 | YES | YES |
CVE-2020-11023MEDIUM In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's | Apr 29, 2020 | 6.1 | 95 | YES | YES |
CVE-2019-2215HIGH A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploi | Oct 11, 2019 | 7.8 | 92 | YES | YES |
CVE-2024-54085CRITICAL AMI’s SPx contains
a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation
of this vulnerabili | Mar 11, 2025 | 9.8 | 91 | YES | NO |
CVE-2020-11022MEDIUM In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append | Apr 29, 2020 | 6.1 | 83 | NO | YES |
CVE-2022-0492HIGH A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the | Mar 3, 2022 | 7.8 | 79 | YES | YES |
CVE-2023-0386HIGH A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a u | Mar 22, 2023 | 7.8 | 78 | YES | YES |
CVE-2022-0185HIGH A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters | Feb 11, 2022 | 8.4 | 77 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (315 CVEs).
CISA KEV
10 CVEs
3.2% of CVEs· 97th percentile
Metasploit
8 CVEs
2.5% of CVEs· 96th percentile
Nuclei
1 CVE
0.3% of CVEs· 96th percentile
ExploitDB
7 CVEs
2.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (315 CVEs).
Media Mentions
Signals from CVEs in this product scope (315 CVEs).
Top CNAs Publishing CVEs For H500s
Top CWEs
Versions
No cataloged versions.