Vulnerabilities
Summary — last 7 days
New vulnerabilities2,666▼ 407 vs. last week
Critical / high1,266▼ 215 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)215▼ 115 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Low (3.7) | 0.73% | — | Carestream VUE RIS | 10/4/2018 | 6/17/2026 | Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP 500 error, leaking technical information an attacker could use to initiate a more elaborate attack. |