Vulnerability index

Browse CVEs

96 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hue Bridge V2 Firmware HIGH 8.8
CVE-2026-3560

Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.8
CVE-2026-3562

Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.0
CVE-2026-3561

Philips Hue Bridge hk_hap characteristics Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.1
CVE-2026-3559

Philips Hue Bridge HomeKit Accessory Protocol Static Nonce Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.8
CVE-2026-3556

Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent atta…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.1
CVE-2026-3558

Philips Hue Bridge HomeKit Accessory Protocol Transient Pairing Mode Authentication Bypass Vulnerability. This vulnerability allows network-adjacent …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.0
CVE-2026-3555

Philips Hue Bridge Zigbee Stack Custom Command Handler Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows netw…

Fix: 1975170000+
Fix from $1,950 2026-03-16
Hue Bridge V2 Firmware HIGH 8.0
CVE-2026-3557

Philips Hue Bridge hap_pair_verify_handler Sub-TLV Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows …

Fix: 1975170000+
Fix from $1,950 2026-03-16
Clinical Collaboration Platform MEDIUM 6.5
CVE-2025-27954

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the user…

Mitigation only
Fix from $1,600 2025-06-02
Clinical Collaboration Platform MEDIUM 6.5
CVE-2025-27955

Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to …

Mitigation only
Fix from $1,600 2025-06-02
Clinical Collaboration Platform MEDIUM 6.5
CVE-2025-27953

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the sess…

Mitigation only
Fix from $1,600 2025-06-02
Vue Pacs CRITICAL 9.8
CVE-2023-40704

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the …

Fix: 12.2.8.410+
Fix from $2,300 2024-07-18
Encoreanywhere HIGH 7.5
CVE-2018-8863

The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.

Fix: after 2.36.3.3
Fix from $1,950 2023-11-09
Myvue MEDIUM 6.5
CVE-2021-39369

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access fil…

Fix: after 12.2.1.5
Fix from $1,600 2022-12-26
Interoperability Solution Xds HIGH 7.5
CVE-2021-32966

Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive info…

Fix: after 2021-1
Fix from $1,950 2022-05-25
E Alert Firmware MEDIUM 6.5
CVE-2022-0922

The software does not perform any authentication for critical system functionality.

Fix: 2.7+
Fix from $1,600 2022-04-01
Myvue HIGH 7.5
CVE-2021-33018

The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the ex…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,950 2022-04-01
Myvue HIGH 7.5
CVE-2021-33020

Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,950 2022-04-01
Myvue HIGH 7.5
CVE-2021-33022

Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffe…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,950 2022-04-01
Myvue HIGH 7.5
CVE-2021-33024

Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthoriz…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,950 2022-04-01
Myvue CRITICAL 9.8
CVE-2021-27497

Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directe…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $2,300 2022-04-01
Myvue CRITICAL 9.8
CVE-2021-27501

Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $2,300 2022-04-01
Myvue MEDIUM 6.5
CVE-2021-27493

Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain secu…

Fix: 12.2.1.5 / 12.2.8.0+
Fix from $1,600 2022-04-01
Intellibridge Ec40 Firmware HIGH 8.8
CVE-2021-32993

IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its …

Mitigation only
Fix from $1,950 2021-12-27
Intellibridge Ec40 Firmware HIGH 8.8
CVE-2021-33017

The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or …

Mitigation only
Fix from $1,950 2021-12-27
Patient Information Center Ix MEDIUM 6.5
CVE-2021-43548

Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input h…

Mitigation only
Fix from $1,600 2021-12-27
Patient Information Center Ix MEDIUM 6.5
CVE-2021-43550

The use of a broken or risky cryptographic algorithm is an unnecessary risk that may result in the exposure of sensitive information, which affects t…

Mitigation only
Fix from $1,600 2021-12-27
Patient Information Center Ix MEDIUM 5.5
CVE-2021-43552

The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from the Patient Information Center…

Mitigation only
Fix from $1,600 2021-12-27
Mri 1.5t Firmware MEDIUM 5.5
CVE-2021-42744

Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Fix: 6.0.0+
Fix from $1,600 2021-11-19
Mri 3t Firmware MEDIUM 5.5
CVE-2021-26248

Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Fix: 6.0.0+
Fix from $1,600 2021-11-19