Is your technology putting patient data at risk?
Type in something your practice uses. We will tell you what we know.
Try · ·
Technology goes bad after you buy it
The firewall that was fine in 2023 is on an exploited-vulnerability list today. Nothing on your end changed.
How the lookup works
Tell us what you use. We identify the product, check it against current vendor and government intelligence, and show you the sources we used.
We do not guess
If we cannot identify something, we say so rather than inventing an answer. And no result means “safe” — we always tell you how much of a product we cover.
Browse The Naughty List
Every published finding, each with the vendor or government advisory it rests on. 23 published, 4 critical.
- CVE-2025-49113 affecting Roundcube WebmailActively exploited by attackers · RoundcubeHIGH
- CVE-2024-53704 affecting SonicOSActively exploited by attackers · SonicWallHIGH
- CVE-2013-2251 affecting Apache Struts (+4 related CVEs)Actively exploited by attackers · Apache Software FoundationHIGH
- CVE-2024-3400 affecting PAN-OS (+3 related CVEs)Actively exploited by attackers · Palo Alto NetworksHIGH
- CVE-2024-1709 affecting ConnectWise ScreenConnect (+1 related CVEs)Actively exploited by attackers · ConnectWiseHIGH
- CVE-2019-11510 affecting Ivanti Connect Secure (+1 related CVEs)Actively exploited by attackers · IvantiHIGH
- CVE-2023-34362 affecting MOVEit TransferActively exploited by attackers · Progress SoftwareHIGH
- CVE-2019-9670 affecting Zimbra Collaboration Suite (+3 related CVEs)Actively exploited by attackers · ZimbraHIGH
- CVE-2010-3962 affecting Internet ExplorerActively exploited by attackers · MicrosoftHIGH
- CVE-2015-3113 affecting Adobe Flash Player (+4 related CVEs)Actively exploited by attackers · AdobeHIGH
- CVE-2013-2465 affecting Oracle Java SE (+2 related CVEs)Actively exploited by attackers · OracleHIGH
- CVE-2023-29300 affecting Adobe ColdFusion (+7 related CVEs)Actively exploited by attackers · AdobeHIGH
- CVE-2018-17463 affecting Google Chrome (+2 related CVEs)Actively exploited by attackers · GoogleHIGH
- CVE-2017-12617 affecting Apache Tomcat (+4 related CVEs)Actively exploited by attackers · Apache Software FoundationHIGH
- CVE-2020-14882 affecting Oracle WebLogic Server (+8 related CVEs)Actively exploited by attackers · OracleHIGH
- CVE-2021-22005 affecting VMware vCenter Server (+3 related CVEs)Actively exploited by attackers · VMwareHIGH
- CVE-2016-7200 affecting Microsoft Edge (+1 related CVEs)Actively exploited by attackers · MicrosoftHIGH
- CVE-2021-34523 affecting Microsoft Exchange Server (+9 related CVEs)Actively exploited by attackers · MicrosoftHIGH
- CVE-2017-11882 affecting Microsoft Office (+13 related CVEs)Actively exploited by attackers · MicrosoftCRITICAL
- CVE-2018-13379 affecting FortiOS (+2 related CVEs)Actively exploited by attackers · FortinetCRITICAL
- CVE-2026-53362 affecting Linux Kernel (+1 related CVEs)Actively exploited by attackers · LinuxCRITICAL
- CVE-2026-55040 affecting Microsoft SharePoint Server (+8 related CVEs)Actively exploited by attackers · MicrosoftCRITICAL
- Windows 10, version 22H2 (General Availability servicing) — security support endedNo longer receives security updates · MicrosoftHIGH
Information provided by Patient Protect's Technology Risk Ledger (“The Naughty List”) is sourced from official vendor and government advisories and is provided “as is” for informational purposes only. Inclusion on The Naughty List identifies a documented technology-security risk based on available evidence at the time of publication; it is not a finding of wrongdoing, negligence, or fault by any vendor. Patient Protect does not warrant the completeness, accuracy, or timeliness of the information. Users are solely responsible for verifying applicability to their specific environment and for their own remediation decisions. Patient Protect disclaims all liability for damages arising from the use of this information.
Looking one thing up is useful. Watching everything is the job.
A practice runs dozens of systems, and any of them can become a documented risk on a day nobody was looking. Patient Protect keeps your actual inventory under continuous watch, so the change finds you.
See how it worksPart of the HIPAA Foundation · Free tools & resources
See the full collectionTrack the threat landscape
The lookup answers one item at a time and knows nothing about your office. The platform is where the systems a practice actually runs are recorded, so a documented finding arrives attached to the system it concerns and to the work it implies — rather than depending on someone thinking to type it in.
Next in the sequence
ePHI Data Flow MapperThe Breach Dashboard, HIPAA Response, Signal, and the open dataset provide different views of the same healthcare compliance and security landscape.
