Thales Group

First CVE: Dec 20, 2021Active for: 5 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
3.0
Avg CVEs / Year
More Avg CVEs / Year than 19% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 17% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Thales Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2021
4 years ago
Most Recent CVE
Jul 13, 2026
12 days ago

Top CVEs

All CVEs published by Thales Group as a CNA, regardless of affected vendor or product.

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrarily overwrite writable applicati
Jul 13, 20269.239NONO
Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve information from the server allowing an offline brute-force att
May 7, 20267.527NONO
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.
Feb 27, 20247.825NONO
A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a privileged user on a system where the agent is installed.
Jan 19, 20227.825NONO
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue aff
Mar 27, 20267.024NONO
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.
Dec 20, 20217.824NONO
A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted r
Apr 28, 20264.923NONO
A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.
Feb 27, 20247.823NONO
A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
Feb 27, 20247.822NONO
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the unde
Jun 10, 20226.522NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA18 CVEs
Severity distribution among all CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local8 (44.4%)
Network10 (55.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (83.3%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low9 (50.0%)
High3 (16.7%)
None6 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Thales Group as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Thales Group as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs