CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-37164CRITICAL | Hewlett Packard Enterprise (HPE) OneView Code Injection VulnerabilityA remote code execution issue exists in HPE OneView. | CVSS10.0v3.1 | EPSS90.2% | PoCs4 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-42508MEDIUM | This vulnerability could be exploited, leading to unauthorized disclosure of information to authenticated users. CWE-200Oct 18, 2024 | CVSS5.5v3.1 | EPSS0.162% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30912HIGH | A remote code execution issue exists in HPE OneView. CWE-94Oct 25, 2023 | CVSS7.2v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30909CRITICAL | A remote authentication bypass issue exists in some OneView APIs. | CVSS9.8v3.1 | EPSS1.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-30908CRITICAL | A remote authentication bypass issue exists in a OneView API. Sep 7, 2023 | CVSS9.8v3.1 | EPSS1.22% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28090MEDIUM | An HPE OneView appliance dump may expose SNMPv3 read credentials CWE-522Apr 25, 2023 | CVSS5.5v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28089HIGH | An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules CWE-522Apr 25, 2023 | CVSS7.1v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28088HIGH | An HPE OneView appliance dump may expose SAN switch administrative credentials CWE-522Apr 25, 2023 | CVSS7.8v3.1 | EPSS0.172% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28087MEDIUM | An HPE OneView appliance dump may expose OneView user accounts CWE-522Apr 25, 2023 | CVSS5.5v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28086MEDIUM | An HPE OneView appliance dump may expose proxy credential settings CWE-522Apr 25, 2023 | CVSS5.5v3.1 | EPSS0.17% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-28091MEDIUM | HPE OneView virtual appliance "Migrate server hardware" option may expose sensitive information in an HPE OneView support dump Apr 14, 2023 | CVSS5.5v3.1 | EPSS0.192% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |