ZeroHour

Vulnerabilities

111 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3556
Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability.

Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Philips Hue Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hk_hap_pair_storage_put function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the HomeKit service. Was ZDI-CAN-28326.

NVD description · AI analysis pending
8.8
group max
<1%
  • philips hue bridge v2 firmware
CVE-2025-27953
+2 in the same advisory: …27954 …27955
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session managem

An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.

NVD description · AI analysis pending
6.5<1%
  • philips clinical collaboration platform
CVE-2023-40704
The product does not require unique and complex passwords to be created during installation.

The product does not require unique and complex passwords to be created during installation. Using Philips's default password could jeopardize the PACS system if the password was hacked or leaked. An attacker could gain access to the database impacting system availability and data integrity.

NVD description · AI analysis pending
5.7<1%
  • philips vue pacs
CVE-2018-8863
The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.

The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.

NVD description · AI analysis pending
7.5<1%
  • philips encoreanywhere
CVE-2021-39369
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored o

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

NVD description · AI analysis pending
6.5<1%
  • philips myvue
  • philips speech
  • philips vue motion
  • +1 more
CVE-2021-32966
Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information whe

Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to remotely read LDAP system credentials.

NVD description · AI analysis pending
7.5<1%
  • philips interoperability solution xds
CVE-2022-0922
The software does not perform any authentication for critical system functionality.

The software does not perform any authentication for critical system functionality.

NVD description · AI analysis pending
6.5<1%
  • philips e-alert firmware
CVE-2021-27501
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severi

Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.

NVD description · AI analysis pending
9.8
group max
<1%
  • philips myvue
  • philips speech
  • philips vue motion
  • +1 more
CVE-2021-23173
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.

The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.

NVD description · AI analysis pending
4.3<1%
  • philips engage
CVE-2021-43548
+2 in the same advisory: …43550 …43552
Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the prop

Patient Information Center iX (PIC iX) Versions C.02 and C.03 receives input or data, but does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

NVD description · AI analysis pending
6.5
group max
<1%
  • philips patient information center ix
CVE-2021-33017
+1 in the same advisory: …32993
The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel tha

The standard access path of the IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) requires authentication, but the product has an alternate path or channel that does not require authentication.

NVD description · AI analysis pending
8.8<1%
  • philips intellibridge ec40 firmware
  • philips intellibridge ec80 firmware
CVE-2021-42744
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

NVD description · AI analysis pending
5.9<1%
  • philips mri 1.5t firmware
  • philips mri 3t firmware
CVE-2021-26262
+1 in the same advisory: …26248
Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

NVD description · AI analysis pending
5.9<1%
  • philips mri 3t firmware
  • philips mri 1.5t firmware
CVE-2021-39376
+1 in the same advisory: …39375
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONV

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIST or CD_USUARIO_CONVENIO parameter.

NVD description · AI analysis pending
8.81% PoC
  • philips tasy electronic medical record
CVE-2020-27298
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (R

Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an upstream component but does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when sent to a downstream component.

NVD description · AI analysis pending
6.5<1%
  • philips coronary tools
  • philips dynamic coronary roadmap
  • philips interventional workspot
  • +1 more
CVE-2018-7580
Philips Hue is vulnerable to a Denial of Service attack.

Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.

NVD description · AI analysis pending
7.52% PoC ×3
  • philips hue firmware
CVE-2020-16247
+4 in the same advisory: …16200 …16198 …14506 …14525
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropria

Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

NVD description · AI analysis pending
7.1
group max
<1%
  • philips clinical collaboration platform
CVE-2020-16222
In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity

In Patient Information Center iX (PICiX) Version B.02, C.02, C.03, and PerformanceBridge Focal Point Version A.01, when an actor claims to have a given identity, the software does not prove or insufficiently proves the claim is correct.

NVD description · AI analysis pending
8.8
group max
<1%
  • philips patient information center ix
  • philips performancebridge focal point
CVE-2020-11618
THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the

THOMSON THT741FTA 2.2.1 and Philips DTR3502BFTA DVB-T2 2.2.1 set-top boxes have their TELNET service hardcoded to start on boot, which allows an attacker on the local network to achieve root access via the TELNET protocol.

NVD description · AI analysis pending
7.8<1% PoC
  • thomsonstb tht741fta firmware
  • thomsonstb dtr3502bfta dvb-t2 firmware