CVE List - Benelux

  • Belgium
  • Netherlands
  • Cybersecurity
  • Type Cyber Threat Research

Emergency
To report an incident, call us at (24/7):

+352 262 039 64 708
or send an email to (Business hours only):

<emergency(at)tcs-cert.com>

ProductScoreCVECreatedVersion
Plunet BusinessManager8.6CVE-2026-23442026/02/1210.15.1
Plunet BusinessManager8.7CVE-2026-23372026/02/1210.15.1
Data Illusion Zumbrunn - NGSurvey5.1CVE-2025-154792026/01/080 to 3.6.16
Data Illusion Zumbrunn - NGSurvey8.6CVE-2025-138292025/12/050 to 3.6.16
ObjectPlanet - Opinio4.8CVE-2025-138732025/12/057.26 rev12562
ObjectPlanet - Opinio2.1CVE-2025-138722025/12/057.26 rev12562
ObjectPlanet - Opinio2.3CVE-2025-138712025/12/037.26 rev12562
PeopleSoft Enterprise HCM Talent Acquisition Manager5.4CVE-2025-307132025/04/288.61.06
Vmware4.3CVE-2024-388152024/10/25"NSX – 4.x NSX-T – 3.x Cloud Foundation (NSX) – 5.x Cloud Foundation (NSX-T) – 4.x"
APIRIS2.4CVE-2024-280602024/05/23Kafeo – 6.4.4
APIRIS8.5CVE-2024-280612024/05/23Kafeo – 6.4.4
Microsoft Business Central4.1XLM-2024-62032024/05/13W1 21.3
Microsoft Teams3.5XLM-2024-64822024/05/13Android : 1416/1.0.0.2023183501
ViewerJS4.7CVE-2024-256762024/04/260.5.8
APSAL4.6CVE-2023-260982024/04/243.14.2022.235 b
SQL Manager for Oracle3.1CVE-2023-517102024/04/183.6.2 (build 55333)
Credential.net5.3CVE-2023-508722024/03/04N/A
Innovaphone PBX5.4CVE-2024-247202024/02/08prior to 14r1
Innovaphone PBX5.4CVE-2024-247212024/02/08prior to 14r1
Archibus iOS application4.4CVE-2023-486452024/01/31V4.0.3
Archibus iOS application5.4CVE-2023-486442024/01/30V4.0.3
Regipay Client2.4CVE-2023-517112024/01/224.5.1.0
Microsoft Teams6.4XLM-2024-64842023/11/28iOS: 5.18.1
Interact Software5.4CVE-2023-411032023/08/247.9.79.5
Network Configuration Manager4.3CVE-2023-295052023/08/0312.6.165
Intella connect6.1CVE-2023-357912023/07/272.6.0.3
Intella connect5.4CVE-2023-357922023/07/272.6.0.3
Dradis Pro8.7CVE-2023-312232023/05/09V4.7.0
APSAL7.1CVE-2023-260972023/04/243.14.2022.235 b
APSAL4.4CVE-2023-260992023/04/243.14.2022.235 b
JDOF5.3CVE-2023-281502023/03/171.1.100
JSpreadSheet5.3CVE-2023-281512023/03/171.1.100
PD4ML java library6.5CVE-2023-275652023/03/174.0.15fx1
Jword5.3CVE-2023-281522023/03/171.1.100
A4N (Aremis 4 Nomad) Android mobile application8.2CVE-2022-349082023/02/241.5.0
A4N (Aremis 4 Nomad) Android mobile application7.7CVE-2022-349092023/02/241.5.0
A4N (Aremis 4 Nomad) Android mobile application4.1CVE-2022-349102023/02/241.5.0
Microsoft Teams6.4XLM-2024-64832023/02/20iOS: 5.18.1
Archibus Web Central4.3CVE-2022-451642022/11/302022.03.01.107
Archibus Web Central6.5CVE-2022-451652022/11/302022.03.01.107
Archibus Web Central6.5CVE-2022-451662022/11/302022.03.01.107
Archibus Web Central4.3CVE-2022-451672022/11/302022.03.01.107
Zebra Enterprise Home Screen7.1CVE-2022-364422022/11/304.1.19
Zebra Enterprise Home Screen4.4CVE-2022-364432022/11/304.1.19
Zebra Enterprise Home Screen7.7CVE-2022-364412022/11/304.1.19
Mega HOPEX4.3CVE-2022-384822022/10/3115.2.0.6110
HOPEX6.1CVE-2022-384812022/10/2815.2.0.6110
ISAMS6.5CVE-2022-370282022/09/2622.2.3.2
PAN-OS 10.2 PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.18.6CVE-2022-00282022/08/24< 10.2.2-h2 < 10.1.6-h6 < 10.0.11-h1 < 9.1.14-h4 < 9.0.16-h3 < 8.1.23-h1
Raytion6.1CVE-2022-299312022/06/207.2.0
NIMBUS6.5CVE-2022-249672022/05/253.4.0
Talend Administration Center5.3CVE-2022-303322022/05/257.3.1.20200219
Incapptic9.1CVE-2022-218282022/04/04Incapptic Connect versions 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3.
Incapptic8.1CVE-2022-225712022/03/28All incapptic Connect versions.
Incapptic6.5CVE-2022-225722022/03/28All incapptic Connect versions.
Zoho ManageEngine Key Manager4.3CVE-2022-244462022/02/216.1.6
Zoho ManageEngine Key Manager5.4CVE-2022-244472022/02/216.1.6
TeamMate Audit Solutions4.4CVE-2021-440352021/12/13TeamMate AM 12.4 Update 1
Allegro Windows7.8CVE-2021-421102021/11/293.3.4152.0 and under
Popsy Windows (older name) / Allegro Windows7.1CVE-2021-439782021/11/293.2.4008.2 / 3.3.4152.0 and under
OpenOTP iOS Mobile Application5.5CVE-2021-421112021/11/101.4.13 and 1.4.14
Wallstreet Suite5.5CVE-2021-413202021/10/137.4.83 (64-bit edition)
GFOS Workforce Management7.4CVE-2021-386182021/10/044.8.272.1
Eigen NLP6.3CVE-2021-386152021/09/013.10.1
Eigen NLP7.6CVE-2021-386162021/09/013.10.1
Eigen NLP8.8CVE-2021-386172021/09/013.10.1
Access Unit 2.04.6CVE-2021-313992021/08/12Firmware 2.31.0.40.5
JUMP AMS5.4CVE-2021-320162021/07/303.6.0.04.009-2487
JUMP AMS5.4CVE-2021-320172021/07/303.6.0.04.009-2487
JUMP AMS5.4CVE-2021-320182021/07/303.6.0.04.009-2487
ServiceDesk Plus MSP5.3CVE-2021-315312021/07/1910.5 Build 10517 – Edition MSPEnterprise
ServiceDesk Plus MSP7.5CVE-2021-311602021/07/1910.5 Build 10517 – Edition MSPEnterprise
ServiceDesk Plus MSP7.5CVE-2021-315302021/07/1910.5 Build 10517 – Edition MSPEnterprise
TYPO3 CMS4.9CVE-2021-317772021/04/2810.4.13
DualShield5.4CVE-2020-289182021/02/095.9.8.0821
Star Practice Management Web6.5CVE-2020-284012021/01/202019.2.0.6
Star Practice Management Web5.4CVE-2020-284022021/01/202019.2.0.6
Star Practice Management Web8CVE-2020-284032021/01/202019.2.0.6
Star Practice Management Web6.5CVE-2020-284042021/01/202019.2.0.6
Star Practice Management Web8.8CVE-2020-284052021/01/202019.2.0.6
Star Practice Management Web6.5CVE-2020-284062021/01/202019.2.0.6
Qradar XLM-2020-13472020/11/187.3.0 and higher
fuelcms9.1CVE-2020-261672020/11/0411.4.12 and before
HelpDeskZ7.5CVE-2020-265462020/09/201.0.2
Application Control Plus4.3CVE-2020-155942020/09/097.3.0 and higher
Application Control Plus4.3CVE-2020-155952020/09/0910.0.510
Halvotec Raquest3.6CVE-2019-196102020/06/1010.23.10801.0
Halvotec Raquest8.1CVE-2019-196112020/06/1010.23.10801.0
Halvotec Raquest5.4CVE-2019-196122020/06/1010.23.10801.0
Halvotec Raquest4.3CVE-2019-196132020/06/1010.23.10801.0
Halvotec Raquest4.8CVE-2019-196142020/06/1010.23.10801.0
Remote Access Plus4.3CVE-2019-204742020/02/1910.0.447
Remote Access Plus4.3CVE-2020-84222020/01/3010.0.447
Microsoft Power BI Report Server4.3XLM-2019-7122019/12/0915.0.1102.299
DataSecurity Plus4.3CVE-2019-171122019/10/075.0.1 Build 5011 and previous versions
MISP7.7CVE-2019-162022019/09/10Versions: <= 2.4.114
AssetExplorer5CVE-2019-129592019/08/066.2.0
AssetExplorer4.1CVE-2019-129942019/08/066.2.0
AssetExplorer8.5CVE-2019-146932019/08/066.2.0
Product DH-IPC-HFW1XXX, IPC-HFW2XXX, IPC-HDW1XXX7.8CVE-2019-96762019/06/10build before November 2018
Travely Android application7.1XLM-2019-6722019/04/251.3.3
EasyToRecruit6.1CVE-2019-110322019/04/152.10
Moodle CMS5CVE-2019-69702019/04/15prior 3.1.x
Confluence3.1CVE-2018-202372019/02/286.12.0
WSO2 API Manager3.8CVE-2019-65132019/02/282.6.0
WSO2 API Manager4.1CVE-2019-65122019/02/212.6.0
WSO2 API Manager4.3CVE-2019-65152019/02/212.6.0
WSO2 Dashboard Server5.8CVE-2019-65162019/02/212.0.0
WSO2 Dashboard Server3.5CVE-2019-65142019/02/212.0.0
Jira5.4XLM-2018-3562019/02/197.12.0
ADSelfService Plus5.3CVE-2019-71612019/02/188.6 Build 5607
ADSelfService Plus5.3CVE-2019-71622019/02/185.6 Build 5607
SecurAccess6.5CVE-2018-184662019/01/309.3.502
WSO2 API Manager2CVE-2018-207362019/01/292.6.0
WSO2 API Manager3.5CVE-2018-207372019/01/292.6.0
ADSelfService Plus7.6CVE-2018-206642019/01/085.6 Build 5607
ADSelfService Plus5.3CVE-2019-39052019/01/085.6 Build 5607
Odoo6.5CVE-2018-156312018/11/2811.0.20180808 (Community Edition) and 10.0+e (Enterprise Edition)
Vaultize Enterprise File Sharing6.1CVE-2018-102072018/04/1817.05.31
Vaultize Enterprise File Sharing6.1CVE-2018-102082018/04/1817.05.31
Vaultize Enterprise File Sharing5.4CVE-2018-102092018/04/1817.05.31
Vaultize Enterprise File Sharing3.7CVE-2018-102102018/04/1817.05.31
Vaultize Enterprise File Sharing3.7CVE-2018-102112018/04/1817.05.31
Vaultize Enterprise File Sharing5.4CVE-2018-102122018/04/1817.05.31
Vaultize Enterprise File Sharing4.1CVE-2018-102132018/04/1817.05.31
Vaultize Enterprise File Sharing7.5CVE-2018-102062018/04/1017.05.31
IBM Content Navigator5.4CVE-2017-13312017/08/04Versions 2.0.3.5, 2.0.3.6, 2.0.3.7, 2.0.3.8, 3.0.0
IBM Content Navigator5.4CVE-2017-12822017/05/26Versions 2.0.3.5, 2.0.3.6, 2.0.3.7, 2.0.3.8, 3.0.0
Drupal security module named SecKit5.3XLM-2016-1212016/10/05Version inferior or equals to SecKit 7.x-1.9
Password Manager Pro6.5CVE-2016-11612016/07/01Versions inferior to 8.5
Password Manager Pro6.5CVE-2016-11592016/03/248.3.0 (Build 8303) and version 8.4.0 (Build 8400,8401,8402)
AXIOM4.9CVE-2015-53842015/09/019.5.3
Lenovo MouseSuite6.9CVE-2015-45962015/08/196.72 and prior
AXIOM6.8CVE-2015-54622015/07/309.5.3
AXIOM9CVE-2015-54632015/07/309.5.3
Linux operating system6.8CVE-2015-56062015/07/237.2.2
     

Security Advisory

CVE Responsible Disclosure Policy

TCS-CERT (Thales Cyber Solutions Customer's CERT) is a certified team of TF-CSIRT Trusted Introducer, member of FIRST, CERT.LU initiative and Belgian Cyber Coalition.

As a Computer Emergency Response Team (CERT), TCS-CERT is committed to share with peers and constituencies the identified vulnerabilities in vendors' products.

Reporting a vulnerability to a vendor is a way to improve cybersecurity globally. It allows users to be notified of the issue and let them perform the appropriate remediation. Conversely, the reporting must be performed with care to avoid giving knowledge of potential victims of attackers.

Whenever a new vulnerability is discovered and reported, TCS-CERT will oversee the public disclosure. TCS-CERT uses a responsible disclosure process to inform the vendors in coordination with the Vendor/Vendor's PSIRT (Product Security Incident Response Team) and the CVE numbering authority.

If requested, during this process, Thales' clients are kept informed of the vendor feedback, the proposed action plan, and the timeline for the mitigation of the issues.

No matter how and who discovered the vulnerability, TCS-CERT will not, in any case, reveal the customer's name from which the finding was made.

If the vendor wishes to publish the CVE by itself, and/or if the vendor is an official CVE Numbering Authorities (CNA), TCS-CERT's would accompany them until the end of the process when the vulnerability is registered and disclosed on the vendor's website, CVE numbering authorities and on Thales Cyber Solutions' website advisory page.

Up to ten (10) days are allowed for the point of contact to acknowledge the finding. After which, TCS-CERT will start the CVE registration process, no matter if the acknowledgment was given.

Any vulnerability will be registered to the CNA So that the vulnerability is associated with a CVE Identifier (CVE ID), formed as follow: "CVE-YYYY-DDDD" (YYYY being the registration's year, and DDDD a number attributed by the CVE numbering authority).

A thirsty (30) days period is allowed for the vendor to work on a fix. This grace period can be extended, on-demand and only if backed-up by strong technical explanations, to ninety (90) days at most.

Any CVE that TCS-CERT reported to a vendor will, once a fix is made available (or the grace period expired) leading to its public disclosed, be referenced on TCS-CERT website advisory page with the CVE ID. Vulnerability registration will be updated with available information from the vendor's PSIRT, if any.

Vendors are kindly asked to refer in their public disclosure:
to this webpage (using the URL https://cds.thalesgroup.com/en/tcs-cert/advisory/<CVE-ID>)

To the finder's name (only when requested).

TCS-CERT never discloses information that could directly help third parties exploiting a vulnerability in a product.

In case the vendors solicitations, the vulnerability will be responsibly disclosed 90 day after TCS-CERT notified incident response teams of the groups to which TCS-CERT belongs.

 

Thales products security advisories.

To report a potential vulnerability that impacts Thales products or services, please contact Thales PSIRT by sending an email to psirt@thalesgroup.com.

Thales products vulnerabilities are published here;

https://www.thalesgroup.com/en/global/group/psirt/thales-product-security-advisories

 

TCS-CERT - Security advisory

On the table below you can find TCS-CERT's published and reported vulnerabilities.