hpe
CVE Numbering Authority
Latest CVE published
Overview
hpe is a CVE Numbering Authority that has published 1,273 CVE records since 2016. It is currently classified as active, with 222 CVEs published in the last two years. Its CVE data quality is graded F (54.1% overall completeness).
Among the 370 CNAs tracked here, hpe ranks #34 by CVE volume and reports more complete records than 9% of all CNAs.
Data quality report card
How complete and consistent hpe's CVE records are, scored across vendor, product, CVSS, and CWE coverage.
A CVE record only requires a description to be published. “Completeness” measures how often hpe also fills in the optional — but extremely useful — fields that make a vulnerability actually actionable: the affected vendor and product, a CVSS severity score, and a CWE weakness type. A higher score means more of this CNA’s CVEs include those details, so defenders spend less time enriching records by hand.
Report card grade
54.1%
Overall score
What these scores mean
- Vendor completeness
- The share of this CNA's CVEs that name an affected vendor.
- Product completeness
- The share that name a specific affected product.
- CVSS completeness
- The share that include a CVSS severity score.
- CWE completeness
- The share mapped to a CWE weakness type.
- Update rate
- How often this CNA revises CVE records after first publishing them.
- Vendor diversity
- How many distinct vendors this CNA publishes CVEs for.
Severity and exploitation
How the CVSS severity of hpe's published CVEs breaks down, and how many are known to be exploited in the wild.
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of hpe's CVEs are confirmed exploited in the wild and carry a CISA remediation deadline.
Common weakness types
The CWE weakness categories hpe most often assigns to its CVEs. Follow any weakness to its full explanation.
- CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')68 CVEs
- CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')43 CVEs
- CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')28 CVEs
- CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')25 CVEs
- CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')22 CVEs
- CWE-121Stack-based Buffer Overflow21 CVEs
- CWE-400Uncontrolled Resource Consumption20 CVEs
- CWE-287Improper Authentication20 CVEs
Publishing activity by year
How many CVEs hpe has published each year.
12-month change
How hpe's CVE data quality has shifted over the trailing year.
Previous grade
F
Current grade
C
Score change
44% → 73.3% (+29.3%)
Improved most in CVSS Completeness (+57.6 pts)
Top vendors
The vendors hpe publishes the most CVEs for.
- Hewlett Packard Enterprise957 CVEs
- HP581 CVEs
- arubanetworks554 CVEs
- siemens55 CVEs
- microsoft22 CVEs
- linux13 CVEs
- Red Hat6 CVEs
- apple3 CVEs
Top products
The products hpe publishes the most CVEs for.
- Intelligent Management Center276 CVEs
- ArubaOS247 CVEs
- clearpass_policy_manager126 CVEs
- sd-wan112 CVEs
- Intelligent Management Center (IMC) PLAT95 CVEs
- Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central67 CVEs
- instant60 CVEs
- AOS-CX58 CVEs
Latest CVEs
The most recent CVEs assigned by hpe.
- CVE-2026-73783
Authenticated Stack Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX
Medium · CVSS 4.92026-09-01 - CVE-2026-73782
Unauthenticated Format String Vulnerability leads to Remote Code Execution in AOS-CX
High · CVSS 8.82026-09-01 - CVE-2026-73781
Authenticated Stored Cross-Site Scripting Vulnerability (XSS) in AOS-CX Web-Based Management Interface
High · CVSS 8.42026-09-01 - CVE-2026-73780
Lack of Cross-Site Request Forgery (CSRF) Protections for Certificate-Authenticated Sessions in AOS-CX
High · CVSS 8.32026-09-01 - CVE-2026-73779
Authentication Bypass Vulnerabilities Leading to Information Disclosure, Unauthorized Modification, and Service Disruption in AOS-CX
High · CVSS 8.22026-09-01 - CVE-2026-73778
Credential Manager Vulnerability Allows Unauthorized Administrative Access
High · CVSS 8.12026-09-01 - CVE-2026-73777
Authorization Bypass Vulnerabilities Leading to Privilege Escalation in AOS-CX API Endpoint
High · CVSS 8.12026-09-01 - CVE-2026-73776
Authenticated Signature Verification Bypass Leading to Arbitrary Code Execution in AOS-CX
High · CVSS 7.92026-09-01 - CVE-2026-73775
Authenticated Sensitive Information Disclosure Vulnerabilities in AOS-CX
High · CVSS 7.72026-09-01 - CVE-2026-73774
Unauthenticated Buffer Overflow Vulnerability leads to Sensitive Information Disclosure in AOS-CX
High · CVSS 7.62026-09-01 - CVE-2026-73773
Unauthenticated Denial-of-Service (DoS) Vulnerability in AOS-CX
High · CVSS 7.52026-09-01 - CVE-2026-73772
Unauthenticated Buffer Overflow Vulnerabilities lead to Denial-of-Service in AOS-CX
Medium · CVSS 6.52026-09-01
Track new hpe CVEs as they are published and get AI-written analysis and remediation guidance.
Monitor hpe CVEsOther CNAs
Compare data quality across other CVE Numbering Authorities.
Frequently asked questions
Common questions about the hpe CNA.
- What is the hpe CNA?
- hpe is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 1,273 CVE records since 2016.
- How many CVEs has hpe published?
- hpe has published 1,273 CVE records, including 222 in the last two years.
- What is hpe's CVE data quality grade?
- RadicalNotion.AI grades hpe's CVE data quality as F, with an overall completeness score of 54.1%. This reflects how consistently its CVE records include vendor (56.8%), product (99.5%), CVSS (32%), and CWE (28%) information.
- What products does hpe publish CVEs for?
- hpe most frequently publishes CVEs for Intelligent Management Center, ArubaOS, clearpass_policy_manager, sd-wan, Intelligent Management Center (IMC) PLAT.
- Which vendors does hpe cover?
- hpe publishes CVEs across 10 distinct vendors, most often Hewlett Packard Enterprise, HP, arubanetworks, siemens, microsoft.
- Is hpe actively publishing CVEs?
- hpe is currently active, based on 222 CVEs in the last two years.
- What is the average severity of hpe's CVEs?
- The average CVSS base score across hpe's scored CVEs is 7.0.
- How many critical CVEs has hpe published?
- hpe has published 274 critical-severity CVEs and 743 high-severity CVEs.
- Are any of hpe's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- Yes. 2 of hpe's CVEs are listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, meaning they are confirmed to be exploited in the wild.
- What are the most common weakness types in hpe's CVEs?
- hpe's CVEs most often map to these CWE weakness types: CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')), CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- How does hpe rank among CNAs?
- By total CVE volume, hpe ranks #34 of 370 CNAs, and it reports more complete CVE records than 9% of all CNAs.
References
- Official CVE.org list of CNA partners (opens in a new tab)
- Learn: What is a CNA?
- CWE directory: the weakness types this CNA maps its CVEs to
CNA report-card grades are computed by RadicalNotion.AI from published CVE records. CVE data is sourced from the CVE Program.
Track hpe CVEs
Monitor new vulnerabilities as this CNA publishes them, with AI-written analysis and remediation guidance.