Philips records
115 published records for vendor philips.
Researcher profile
- Entered KEV
- 2 · 1.7%
- Weaponized
- 2 · 1.7%
- Pre-auth RCE
- 16
- With a fix record
- 1.7%
- Median publish → KEV
- 1680 days
Recurring classes
- CWE-798 Use of Hard-coded Credentials6
- CWE-122 Heap-based Buffer Overflow6
- CWE-20 Improper Input Validation6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-287 Improper Authentication4
The weakness classes this vendor ships most often: where to look.
CWEAll records
115 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
93Now | CVE-2017-0143Weaponized | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | High8.8 | KEV | 93.3% | Mar 16, 2017 |
91Now | CVE-2017-0199Weaponized | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windowsmicrosoft · office | High7.8 | KEV | 99.5% | Apr 12, 2017 |
41Plan | CVE-2018-5474No exploit | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to executphilips · intellispace portal · CWE-20 | Critical9.8 | — | 6.1% | Mar 26, 2018 |
40Plan | CVE-2018-5472No exploit | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to philips · intellispace portal · CWE-264 | Critical9.8 | — | 4.5% | Mar 26, 2018 |
40Plan | CVE-2018-5468No exploit | Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unaphilips · intellispace portal · CWE-264 | Critical9.8 | — | 4.5% | Mar 26, 2018 |
40Plan | CVE-2018-8850No exploit | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-20 | Critical9.8 | — | 3.8% | Sep 26, 2018 |
40Plan | CVE-2018-5451No exploit | In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienphilips · alice 6 firmware · CWE-287 | Critical9.8 | — | 2.6% | Mar 28, 2018 |
39Monitor | CVE-2015-2882No exploit | Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a pphilips · in.sight b120\\37 · CWE-798 | Critical9.8 | — | 1.6% | Apr 9, 2017 |
39Monitor | CVE-2018-8856No exploit | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-798 | Critical9.8 | — | 1.4% | Sep 26, 2018 |
39Monitor | CVE-2021-27501No exploit | Philips Vue PACS Improper Adherence to Coding Standardsphilips · myvue · CWE-710 | Critical9.8 | — | 0.9% | Apr 1, 2022 |
39Monitor | CVE-2021-27497No exploit | Philips Vue PACS Protection Mechanism Failurephilips · myvue · CWE-693 | Critical9.8 | — | 0.8% | Apr 1, 2022 |
39Monitor | CVE-2018-7498No exploit | In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrityphilips · alice 6 firmware · CWE-311 | Critical9.8 | — | 0.6% | Mar 28, 2018 |
38Monitor | CVE-2013-2808No exploit | Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vasculaphilips · xper information management physiomonitoring 5 · CWE-119 | Critical9.3 | — | 4.3% | Oct 5, 2013 |
37Monitor | CVE-2017-9656No exploit | The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a databasephilips · dosewise · CWE-798 | Critical9.1 | — | 2.3% | Apr 24, 2018 |
36Monitor | CVE-2018-8852No exploit | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-384 | High8.8 | — | 1.9% | Sep 26, 2018 |
35Monitor | CVE-2021-39376No exploit | Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSISphilips · tasy electronic medical record · CWE-89 | High8.8 | — | 1.3% | Aug 24, 2021 |
35Monitor | CVE-2021-39375No exploit | Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValuphilips · tasy electronic medical record · CWE-89 | High8.8 | — | 1.3% | Aug 24, 2021 |
35Monitor | CVE-2017-9654No exploit | The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend syphilips · dosewise · CWE-312 | High8.8 | — | 1.0% | Apr 24, 2018 |
35Monitor | CVE-2018-8844No exploit | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-352 | High8.8 | — | 0.9% | Sep 26, 2018 |
35Monitor | CVE-2018-17906No exploit | Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions.philips · intellispace pacs · CWE-521 | High8.8 | — | 0.8% | Nov 19, 2018 |
35Monitor | CVE-2018-8842No exploit | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-319 | High8.8 | — | 0.6% | Sep 26, 2018 |
35Monitor | CVE-2020-16222No exploit | Philips Patient Monitoring Devices Improper Authenticationphilips · patient information center ix · CWE-287 | High8.8 | — | 0.5% | Sep 11, 2020 |
35Monitor | CVE-2026-3556No exploit | Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerabilityphilips · hue bridge v2 firmware · CWE-122 | High8.8 | — | 0.5% | Mar 16, 2026 |
35Monitor | CVE-2026-3560No exploit | Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerabilityphilips · hue bridge v2 firmware · CWE-122 | High8.8 | — | 0.5% | Mar 16, 2026 |
35Monitor | CVE-2021-33017No exploit | Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channelphilips · intellibridge ec40 firmware · CWE-288 | High8.8 | — | 0.5% | Dec 27, 2021 |
- CVE-2017-014393Now
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
HighCVSS 8.8KEVWeaponizedEPSS 93%microsoft · server message blockMar 16, 2017
- CVE-2017-019991Now
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows
HighCVSS 7.8KEVWeaponizedEPSS 99%microsoft · officeApr 12, 2017
- CVE-2018-547441Plan
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execut
CriticalCVSS 9.8No exploitEPSS 6%philips · intellispace portalMar 26, 2018
- CVE-2018-547240Plan
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to
CriticalCVSS 9.8No exploitEPSS 5%philips · intellispace portalMar 26, 2018
- CVE-2018-546840Plan
Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain una
CriticalCVSS 9.8No exploitEPSS 5%philips · intellispace portalMar 26, 2018
- CVE-2018-885040Plan
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
CriticalCVSS 9.8No exploitEPSS 4%philips · e-alert firmwareSep 26, 2018
- CVE-2018-545140Plan
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficien
CriticalCVSS 9.8No exploitEPSS 3%philips · alice 6 firmwareMar 28, 2018
- CVE-2015-288239Monitor
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a p
CriticalCVSS 9.8No exploitEPSS 2%philips · in.sight b120\\37Apr 9, 2017
- CVE-2018-885639Monitor
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
CriticalCVSS 9.8No exploitEPSS 1%philips · e-alert firmwareSep 26, 2018
- CVE-2021-2750139Monitor
Philips Vue PACS Improper Adherence to Coding Standards
CriticalCVSS 9.8No exploitEPSS 1%philips · myvueApr 1, 2022
- CVE-2021-2749739Monitor
Philips Vue PACS Protection Mechanism Failure
CriticalCVSS 9.8No exploitEPSS 1%philips · myvueApr 1, 2022
- CVE-2018-749839Monitor
In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity
CriticalCVSS 9.8No exploitEPSS 1%philips · alice 6 firmwareMar 28, 2018
- CVE-2013-280838Monitor
Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascula
CriticalCVSS 9.3No exploitEPSS 4%philips · xper information management physiomonitoring 5Oct 5, 2013
- CVE-2017-965637Monitor
The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database
CriticalCVSS 9.1No exploitEPSS 2%philips · dosewiseApr 24, 2018
- CVE-2018-885236Monitor
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
HighCVSS 8.8No exploitEPSS 2%philips · e-alert firmwareSep 26, 2018
- CVE-2021-3937635Monitor
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIS
HighCVSS 8.8No exploitEPSS 1%philips · tasy electronic medical recordAug 24, 2021
- CVE-2021-3937535Monitor
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValu
HighCVSS 8.8No exploitEPSS 1%philips · tasy electronic medical recordAug 24, 2021
- CVE-2017-965435Monitor
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend sy
HighCVSS 8.8No exploitEPSS 1%philips · dosewiseApr 24, 2018
- CVE-2018-884435Monitor
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
HighCVSS 8.8No exploitEPSS 1%philips · e-alert firmwareSep 26, 2018
- CVE-2018-1790635Monitor
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions.
HighCVSS 8.8No exploitEPSS 1%philips · intellispace pacsNov 19, 2018
- CVE-2018-884235Monitor
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
HighCVSS 8.8No exploitEPSS 1%philips · e-alert firmwareSep 26, 2018
- CVE-2020-1622235Monitor
Philips Patient Monitoring Devices Improper Authentication
HighCVSS 8.8No exploitEPSS 1%philips · patient information center ixSep 11, 2020
- CVE-2026-355635Monitor
Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%philips · hue bridge v2 firmwareMar 16, 2026
- CVE-2026-356035Monitor
Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%philips · hue bridge v2 firmwareMar 16, 2026
- CVE-2021-3301735Monitor
Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channel
HighCVSS 8.8No exploitEPSS 0%philips · intellibridge ec40 firmwareDec 27, 2021