Known vulnerabilities in HPE Helion Openstack - page 3

Vendor: SUSE
Software CPE: cpe:2.3:o:suse:hpe_helion_openstack:*:*:*:*:*:*:*:*
Total vulnerabilities: 787
Public exploits: 43
Known exploited (KEV): 18
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting HPE Helion Openstack HPE Helion Openstack is affected by 787 known vulnerabilities: 11 critical, 221 high, 273 medium, 282 low Critical High Medium Low

Vulnerabilities (787)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67588 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2020-1734
CWE-78 High
No
No
- 22.09.2022 SB2022092241
SB2022092242
SB2020041808
and 1 more
#VU66814 - Improper Access Control
CVE-2021-44225
CWE-284 Low
No
No
- 29.08.2022 SB2021112614
SB2022082931
SB2022083038
and 9 more
#VU65287 - Permissions, Privileges, and Access Controls
CVE-2022-29187
CWE-264 Medium
No
No
- 13.07.2022 SB2022071347
SB2022071348
SB2022071350
and 30 more
#VU64905 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-34265
CWE-89 High
Available
No
- 04.07.2022 SB2022070425
SB2022070438
SB2022080147
and 8 more
#VU64573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2015-20107
CWE-78 High
No
No
- 22.06.2022 SB2022062206
SB2022062207
SB2022062436
and 85 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
- 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU64430 - Incorrect Authorization
CVE-2021-41244
CWE-863 Medium
No
No
- 16.06.2022 SB2021111513
SB2022062026
SB2022102094
and 5 more
#VU62830 - Heap-based Buffer Overflow
CVE-2022-24903
CWE-122 High
No
No
- 05.05.2022 SB2022050524
SB2022050920
SB2022052425
and 45 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
- 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU62050 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-28346
CWE-89 High
Available
No
- 11.04.2022 SB2022041110
SB2022041125
SB2022041126
and 14 more
#VU61798 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24790
CWE-444 Medium
No
No
- 01.04.2022 SB2022040112
SB2022052603
SB2022092241
and 12 more
#VU61488 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24761
CWE-444 Medium
No
No
- 21.03.2022 SB2022032107
SB2022040525
SB2022040622
and 12 more
#VU58824 - Improper input validation
CVE-2021-44716
CWE-20 Medium
No
No
- 10.12.2021 SB2021121010
SB2021121011
SB2021121605
and 67 more
#VU57926 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41174
CWE-79 Low
Available
No
- 03.11.2021 SB2021110312
SB2021110517
SB2022062026
and 4 more
#VU57320 - Improper Access Control
CVE-2021-39226
CWE-284 Medium
Available
Exploited
- 12.10.2021 SB2021101262
SB2021101320
SB2021101321
and 22 more
#VU56063 - Memory corruption
CVE-2021-3711
CWE-119 High
No
No
- 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 53 more
#VU55287 - NULL Pointer Dereference
CVE-2021-36222
CWE-476 Medium
No
No
- 25.07.2021 SB2021072501
SB2021072502
SB2021080601
and 24 more
#VU28793 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2020-13757
CWE-327 Medium
No
No
- 08.06.2020 SB2020060820
SB2020081913
SB2020090110
and 11 more
#VU26356 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-10109
CWE-444 Medium
No
No
- 24.03.2020 SB2020031234
SB2020032419
SB2020043028
and 8 more
#VU24218 - Improper input validation
CVE-2019-11287
CWE-20 Medium
No
No
- 13.01.2020 SB2019112307
SB2020011311
SB2021062428
and 5 more


Showing elements 41 - 60 out of 787