Thales Group
First CVE: Dec 20, 2021Active for: 5 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 17% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Thales Group over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2021
4 years ago
Most Recent CVE
Jul 13, 2026
12 days ago
Top CVEs
All CVEs published by Thales Group as a CNA, regardless of affected vendor or product.
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13014CRITICAL A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable applicati | Jul 13, 2026 | 9.2 | 39 | NO | NO |
CVE-2026-6805HIGH Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force att | May 7, 2026 | 7.5 | 27 | NO | NO |
CVE-2023-5993HIGH A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access. | Feb 27, 2024 | 7.8 | 25 | NO | NO |
CVE-2021-42810HIGH A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed. | Jan 19, 2022 | 7.8 | 25 | NO | NO |
CVE-2026-3457HIGH Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue aff | Mar 27, 2026 | 7.0 | 24 | NO | NO |
CVE-2021-42809HIGH Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | Dec 20, 2021 | 7.8 | 24 | NO | NO |
CVE-2026-5794MEDIUM A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted r | Apr 28, 2026 | 4.9 | 23 | NO | NO |
CVE-2024-0197HIGH A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
| Feb 27, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-7016HIGH A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. | Feb 27, 2024 | 7.8 | 22 | NO | NO |
CVE-2021-42811MEDIUM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the unde | Jun 10, 2022 | 6.5 | 22 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA18 CVEs
11%
44%
39%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (44.4%)
Network10 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low9 (50.0%)
High3 (16.7%)
None6 (33.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Thales Group as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Thales Group as a CNA — matched by CVE ID, not by organization name.