Vulnerabilities (CVE)

Filtered by vendor Hp Subscribe
Total 2517 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-43486 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 4.8 MEDIUM
A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.
CVE-2025-43485 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 4.5 MEDIUM
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.
CVE-2025-43484 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 6.1 MEDIUM
A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software update.
CVE-2025-43483 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 5.7 MEDIUM
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update.
CVE-2025-43026 1 Hp 1 Support Assistant 2026-06-17 N/A 7.8 HIGH
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.44.18.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
CVE-2025-43025 1 Hp 1 Universal Print Driver 2026-06-17 N/A 7.5 HIGH
HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in versions of UPD 7.4 or older (e.g., v7.3.x, v7.2.x, v7.1.x, etc.).
CVE-2025-43024 1 Hp 1 Thinpro 2026-06-17 N/A 7.5 HIGH
A GUI dialog of an application allows to view what files are in the file system without proper authorization.
CVE-2025-43023 1 Hp 1 Linux Imaging And Printing 2026-06-17 N/A 9.1 CRITICAL
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This potential vulnerability is due to the use of a weak code signing key, Digital Signature Algorithm (DSA).
CVE-2025-43022 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 7.2 HIGH
A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.
CVE-2025-43021 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 5.7 MEDIUM
A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.
CVE-2025-43020 1 Hp 1 Poly Clariti Manager 2026-06-17 N/A 6.8 MEDIUM
A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.
CVE-2025-43019 1 Hp 1 Support Assistant 2026-06-17 N/A 7.8 HIGH
A potential security vulnerability has been identified in the HP Support Assistant, which allows a local attacker to escalate privileges via an arbitrary file deletion.
CVE-2025-43018 1 Hp 34 W1a28a, W1a28a Firmware, W1a29a and 31 more 2026-06-17 N/A 5.3 MEDIUM
Certain HP LaserJet Pro printers may be vulnerable to information disclosure when a non-authenticated user queries a device’s local address book.
CVE-2025-43017 1 Hp 1 Thinpro 2026-06-17 N/A 9.8 CRITICAL
HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.
CVE-2025-3508 1 Hp 146 1vd83a, 1vd83a Firmware, 1vd84a and 143 more 2026-06-17 N/A 6.5 MEDIUM
Certain HP DesignJet products may be vulnerable to information disclosure though printer's web interface allowing unauthenticated users to view sensitive print job information.
CVE-2025-36038 5 Hp, Ibm, Linux and 2 more 8 Hp-ux, Aix, I and 5 more 2026-06-17 N/A 9.0 CRITICAL
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects.
CVE-2025-33142 5 Hp, Ibm, Linux and 2 more 8 Hp-ux, Aix, I and 5 more 2026-06-17 N/A 5.3 MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security for TLS connections.
CVE-2025-33104 5 Hp, Ibm, Linux and 2 more 8 Hp-ux, Aix, I and 5 more 2026-06-17 N/A 4.4 MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2025-2268 1 Hp 108 1y7d4a, 1y7d4a Firmware, 2a129a and 105 more 2026-06-17 N/A 7.5 HIGH
The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).
CVE-2025-27907 5 Hp, Ibm, Linux and 2 more 8 Hp-ux, Aix, I and 5 more 2026-06-17 N/A 4.1 MEDIUM
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.