TCS-CERT (Thales Cyber Solutions Customer’s CERT)

First CVE: Dec 1, 2025Active for: 1 year
11
CVEs Published
More CVEs Published than 28% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
6.6
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2025
7 months ago
Most Recent CVE
Jul 15, 2026
9 days ago

Top CVEs

All CVEs published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) as a CNA, regardless of affected vendor or product.

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to per
Dec 2, 20259.132NONO
Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to upload files on behalf of the connected users and then acce
Dec 2, 20258.827NONO
Incorrect Authorization vulnerability in Data Illusion Zumbrunn NGSurvey allows any logged-in user to obtain the private information of any other user. Critical information ret
Dec 1, 20258.627NONO
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS).  S
Jul 15, 20265.525NONO
A vulnerability in Plunet Plunet BusinessManager allows unauthorized actions being performed on behalf of privileged users.This issue affects Plunet BusinessManager: 10.15.1
Feb 11, 20268.625NONO
A vulnerability in Plunet Plunet BusinessManager allows session hijacking, data theft, unauthorized actions on behalf of the user.This issue affects Plunet BusinessManager: 10.15.1
Feb 11, 20268.725NONO
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenD
May 4, 20265.324NONO
Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. This issue affects OpenConcerto: 1.7.5.
May 4, 20264.823NONO
Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application allows an attacker to inject arbitrary JavaScript code, which
Dec 2, 20255.420NONO
Stored cross-site scripting (XSS, CWE-79) in the survey content and administration functionality in Data Illusion Zumbrunn NGSurvey Enterprise Edition 3.6.4 on all supported platfo
Jan 7, 20265.419NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA11 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (18.2%)
Network9 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (36.4%)
Unknown0 (0.0%)
Required3 (27.3%)
Privileges Required
Low7 (63.6%)
High0 (0.0%)
None4 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by TCS-CERT (Thales Cyber Solutions Customer’s CERT) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs