CVE List - Benelux
Emergency
To report an incident, call us at (24/7):
+352 262 039 64 708
or send an email to (Business hours only):
<emergency(at)tcs-cert.com>
| Product | Score | CVE | Created | Version |
|---|---|---|---|---|
| Plunet BusinessManager | 8.6 | CVE-2026-2344 | 2026/02/12 | 10.15.1 |
| Plunet BusinessManager | 8.7 | CVE-2026-2337 | 2026/02/12 | 10.15.1 |
| Data Illusion Zumbrunn - NGSurvey | 5.1 | CVE-2025-15479 | 2026/01/08 | 0 to 3.6.16 |
| Data Illusion Zumbrunn - NGSurvey | 8.6 | CVE-2025-13829 | 2025/12/05 | 0 to 3.6.16 |
| ObjectPlanet - Opinio | 4.8 | CVE-2025-13873 | 2025/12/05 | 7.26 rev12562 |
| ObjectPlanet - Opinio | 2.1 | CVE-2025-13872 | 2025/12/05 | 7.26 rev12562 |
| ObjectPlanet - Opinio | 2.3 | CVE-2025-13871 | 2025/12/03 | 7.26 rev12562 |
| PeopleSoft Enterprise HCM Talent Acquisition Manager | 5.4 | CVE-2025-30713 | 2025/04/28 | 8.61.06 |
| Vmware | 4.3 | CVE-2024-38815 | 2024/10/25 | "NSX – 4.x NSX-T – 3.x Cloud Foundation (NSX) – 5.x Cloud Foundation (NSX-T) – 4.x" |
| APIRIS | 2.4 | CVE-2024-28060 | 2024/05/23 | Kafeo – 6.4.4 |
| APIRIS | 8.5 | CVE-2024-28061 | 2024/05/23 | Kafeo – 6.4.4 |
| Microsoft Business Central | 4.1 | XLM-2024-6203 | 2024/05/13 | W1 21.3 |
| Microsoft Teams | 3.5 | XLM-2024-6482 | 2024/05/13 | Android : 1416/1.0.0.2023183501 |
| ViewerJS | 4.7 | CVE-2024-25676 | 2024/04/26 | 0.5.8 |
| APSAL | 4.6 | CVE-2023-26098 | 2024/04/24 | 3.14.2022.235 b |
| SQL Manager for Oracle | 3.1 | CVE-2023-51710 | 2024/04/18 | 3.6.2 (build 55333) |
| Credential.net | 5.3 | CVE-2023-50872 | 2024/03/04 | N/A |
| Innovaphone PBX | 5.4 | CVE-2024-24720 | 2024/02/08 | prior to 14r1 |
| Innovaphone PBX | 5.4 | CVE-2024-24721 | 2024/02/08 | prior to 14r1 |
| Archibus iOS application | 4.4 | CVE-2023-48645 | 2024/01/31 | V4.0.3 |
| Archibus iOS application | 5.4 | CVE-2023-48644 | 2024/01/30 | V4.0.3 |
| Regipay Client | 2.4 | CVE-2023-51711 | 2024/01/22 | 4.5.1.0 |
| Microsoft Teams | 6.4 | XLM-2024-6484 | 2023/11/28 | iOS: 5.18.1 |
| Interact Software | 5.4 | CVE-2023-41103 | 2023/08/24 | 7.9.79.5 |
| Network Configuration Manager | 4.3 | CVE-2023-29505 | 2023/08/03 | 12.6.165 |
| Intella connect | 6.1 | CVE-2023-35791 | 2023/07/27 | 2.6.0.3 |
| Intella connect | 5.4 | CVE-2023-35792 | 2023/07/27 | 2.6.0.3 |
| Dradis Pro | 8.7 | CVE-2023-31223 | 2023/05/09 | V4.7.0 |
| APSAL | 7.1 | CVE-2023-26097 | 2023/04/24 | 3.14.2022.235 b |
| APSAL | 4.4 | CVE-2023-26099 | 2023/04/24 | 3.14.2022.235 b |
| JDOF | 5.3 | CVE-2023-28150 | 2023/03/17 | 1.1.100 |
| JSpreadSheet | 5.3 | CVE-2023-28151 | 2023/03/17 | 1.1.100 |
| PD4ML java library | 6.5 | CVE-2023-27565 | 2023/03/17 | 4.0.15fx1 |
| Jword | 5.3 | CVE-2023-28152 | 2023/03/17 | 1.1.100 |
| A4N (Aremis 4 Nomad) Android mobile application | 8.2 | CVE-2022-34908 | 2023/02/24 | 1.5.0 |
| A4N (Aremis 4 Nomad) Android mobile application | 7.7 | CVE-2022-34909 | 2023/02/24 | 1.5.0 |
| A4N (Aremis 4 Nomad) Android mobile application | 4.1 | CVE-2022-34910 | 2023/02/24 | 1.5.0 |
| Microsoft Teams | 6.4 | XLM-2024-6483 | 2023/02/20 | iOS: 5.18.1 |
| Archibus Web Central | 4.3 | CVE-2022-45164 | 2022/11/30 | 2022.03.01.107 |
| Archibus Web Central | 6.5 | CVE-2022-45165 | 2022/11/30 | 2022.03.01.107 |
| Archibus Web Central | 6.5 | CVE-2022-45166 | 2022/11/30 | 2022.03.01.107 |
| Archibus Web Central | 4.3 | CVE-2022-45167 | 2022/11/30 | 2022.03.01.107 |
| Zebra Enterprise Home Screen | 7.1 | CVE-2022-36442 | 2022/11/30 | 4.1.19 |
| Zebra Enterprise Home Screen | 4.4 | CVE-2022-36443 | 2022/11/30 | 4.1.19 |
| Zebra Enterprise Home Screen | 7.7 | CVE-2022-36441 | 2022/11/30 | 4.1.19 |
| Mega HOPEX | 4.3 | CVE-2022-38482 | 2022/10/31 | 15.2.0.6110 |
| HOPEX | 6.1 | CVE-2022-38481 | 2022/10/28 | 15.2.0.6110 |
| ISAMS | 6.5 | CVE-2022-37028 | 2022/09/26 | 22.2.3.2 |
| PAN-OS 10.2 PAN-OS 10.1 PAN-OS 10.0 PAN-OS 9.1 PAN-OS 9.0 PAN-OS 8.1 | 8.6 | CVE-2022-0028 | 2022/08/24 | < 10.2.2-h2 < 10.1.6-h6 < 10.0.11-h1 < 9.1.14-h4 < 9.0.16-h3 < 8.1.23-h1 |
| Raytion | 6.1 | CVE-2022-29931 | 2022/06/20 | 7.2.0 |
| NIMBUS | 6.5 | CVE-2022-24967 | 2022/05/25 | 3.4.0 |
| Talend Administration Center | 5.3 | CVE-2022-30332 | 2022/05/25 | 7.3.1.20200219 |
| Incapptic | 9.1 | CVE-2022-21828 | 2022/04/04 | Incapptic Connect versions 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3. |
| Incapptic | 8.1 | CVE-2022-22571 | 2022/03/28 | All incapptic Connect versions. |
| Incapptic | 6.5 | CVE-2022-22572 | 2022/03/28 | All incapptic Connect versions. |
| Zoho ManageEngine Key Manager | 4.3 | CVE-2022-24446 | 2022/02/21 | 6.1.6 |
| Zoho ManageEngine Key Manager | 5.4 | CVE-2022-24447 | 2022/02/21 | 6.1.6 |
| TeamMate Audit Solutions | 4.4 | CVE-2021-44035 | 2021/12/13 | TeamMate AM 12.4 Update 1 |
| Allegro Windows | 7.8 | CVE-2021-42110 | 2021/11/29 | 3.3.4152.0 and under |
| Popsy Windows (older name) / Allegro Windows | 7.1 | CVE-2021-43978 | 2021/11/29 | 3.2.4008.2 / 3.3.4152.0 and under |
| OpenOTP iOS Mobile Application | 5.5 | CVE-2021-42111 | 2021/11/10 | 1.4.13 and 1.4.14 |
| Wallstreet Suite | 5.5 | CVE-2021-41320 | 2021/10/13 | 7.4.83 (64-bit edition) |
| GFOS Workforce Management | 7.4 | CVE-2021-38618 | 2021/10/04 | 4.8.272.1 |
| Eigen NLP | 6.3 | CVE-2021-38615 | 2021/09/01 | 3.10.1 |
| Eigen NLP | 7.6 | CVE-2021-38616 | 2021/09/01 | 3.10.1 |
| Eigen NLP | 8.8 | CVE-2021-38617 | 2021/09/01 | 3.10.1 |
| Access Unit 2.0 | 4.6 | CVE-2021-31399 | 2021/08/12 | Firmware 2.31.0.40.5 |
| JUMP AMS | 5.4 | CVE-2021-32016 | 2021/07/30 | 3.6.0.04.009-2487 |
| JUMP AMS | 5.4 | CVE-2021-32017 | 2021/07/30 | 3.6.0.04.009-2487 |
| JUMP AMS | 5.4 | CVE-2021-32018 | 2021/07/30 | 3.6.0.04.009-2487 |
| ServiceDesk Plus MSP | 5.3 | CVE-2021-31531 | 2021/07/19 | 10.5 Build 10517 – Edition MSPEnterprise |
| ServiceDesk Plus MSP | 7.5 | CVE-2021-31160 | 2021/07/19 | 10.5 Build 10517 – Edition MSPEnterprise |
| ServiceDesk Plus MSP | 7.5 | CVE-2021-31530 | 2021/07/19 | 10.5 Build 10517 – Edition MSPEnterprise |
| TYPO3 CMS | 4.9 | CVE-2021-31777 | 2021/04/28 | 10.4.13 |
| DualShield | 5.4 | CVE-2020-28918 | 2021/02/09 | 5.9.8.0821 |
| Star Practice Management Web | 6.5 | CVE-2020-28401 | 2021/01/20 | 2019.2.0.6 |
| Star Practice Management Web | 5.4 | CVE-2020-28402 | 2021/01/20 | 2019.2.0.6 |
| Star Practice Management Web | 8 | CVE-2020-28403 | 2021/01/20 | 2019.2.0.6 |
| Star Practice Management Web | 6.5 | CVE-2020-28404 | 2021/01/20 | 2019.2.0.6 |
| Star Practice Management Web | 8.8 | CVE-2020-28405 | 2021/01/20 | 2019.2.0.6 |
| Star Practice Management Web | 6.5 | CVE-2020-28406 | 2021/01/20 | 2019.2.0.6 |
| Qradar | XLM-2020-1347 | 2020/11/18 | 7.3.0 and higher | |
| fuelcms | 9.1 | CVE-2020-26167 | 2020/11/04 | 11.4.12 and before |
| HelpDeskZ | 7.5 | CVE-2020-26546 | 2020/09/20 | 1.0.2 |
| Application Control Plus | 4.3 | CVE-2020-15594 | 2020/09/09 | 7.3.0 and higher |
| Application Control Plus | 4.3 | CVE-2020-15595 | 2020/09/09 | 10.0.510 |
| Halvotec Raquest | 3.6 | CVE-2019-19610 | 2020/06/10 | 10.23.10801.0 |
| Halvotec Raquest | 8.1 | CVE-2019-19611 | 2020/06/10 | 10.23.10801.0 |
| Halvotec Raquest | 5.4 | CVE-2019-19612 | 2020/06/10 | 10.23.10801.0 |
| Halvotec Raquest | 4.3 | CVE-2019-19613 | 2020/06/10 | 10.23.10801.0 |
| Halvotec Raquest | 4.8 | CVE-2019-19614 | 2020/06/10 | 10.23.10801.0 |
| Remote Access Plus | 4.3 | CVE-2019-20474 | 2020/02/19 | 10.0.447 |
| Remote Access Plus | 4.3 | CVE-2020-8422 | 2020/01/30 | 10.0.447 |
| Microsoft Power BI Report Server | 4.3 | XLM-2019-712 | 2019/12/09 | 15.0.1102.299 |
| DataSecurity Plus | 4.3 | CVE-2019-17112 | 2019/10/07 | 5.0.1 Build 5011 and previous versions |
| MISP | 7.7 | CVE-2019-16202 | 2019/09/10 | Versions: <= 2.4.114 |
| AssetExplorer | 5 | CVE-2019-12959 | 2019/08/06 | 6.2.0 |
| AssetExplorer | 4.1 | CVE-2019-12994 | 2019/08/06 | 6.2.0 |
| AssetExplorer | 8.5 | CVE-2019-14693 | 2019/08/06 | 6.2.0 |
| Product DH-IPC-HFW1XXX, IPC-HFW2XXX, IPC-HDW1XXX | 7.8 | CVE-2019-9676 | 2019/06/10 | build before November 2018 |
| Travely Android application | 7.1 | XLM-2019-672 | 2019/04/25 | 1.3.3 |
| EasyToRecruit | 6.1 | CVE-2019-11032 | 2019/04/15 | 2.10 |
| Moodle CMS | 5 | CVE-2019-6970 | 2019/04/15 | prior 3.1.x |
| Confluence | 3.1 | CVE-2018-20237 | 2019/02/28 | 6.12.0 |
| WSO2 API Manager | 3.8 | CVE-2019-6513 | 2019/02/28 | 2.6.0 |
| WSO2 API Manager | 4.1 | CVE-2019-6512 | 2019/02/21 | 2.6.0 |
| WSO2 API Manager | 4.3 | CVE-2019-6515 | 2019/02/21 | 2.6.0 |
| WSO2 Dashboard Server | 5.8 | CVE-2019-6516 | 2019/02/21 | 2.0.0 |
| WSO2 Dashboard Server | 3.5 | CVE-2019-6514 | 2019/02/21 | 2.0.0 |
| Jira | 5.4 | XLM-2018-356 | 2019/02/19 | 7.12.0 |
| ADSelfService Plus | 5.3 | CVE-2019-7161 | 2019/02/18 | 8.6 Build 5607 |
| ADSelfService Plus | 5.3 | CVE-2019-7162 | 2019/02/18 | 5.6 Build 5607 |
| SecurAccess | 6.5 | CVE-2018-18466 | 2019/01/30 | 9.3.502 |
| WSO2 API Manager | 2 | CVE-2018-20736 | 2019/01/29 | 2.6.0 |
| WSO2 API Manager | 3.5 | CVE-2018-20737 | 2019/01/29 | 2.6.0 |
| ADSelfService Plus | 7.6 | CVE-2018-20664 | 2019/01/08 | 5.6 Build 5607 |
| ADSelfService Plus | 5.3 | CVE-2019-3905 | 2019/01/08 | 5.6 Build 5607 |
| Odoo | 6.5 | CVE-2018-15631 | 2018/11/28 | 11.0.20180808 (Community Edition) and 10.0+e (Enterprise Edition) |
| Vaultize Enterprise File Sharing | 6.1 | CVE-2018-10207 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 6.1 | CVE-2018-10208 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 5.4 | CVE-2018-10209 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 3.7 | CVE-2018-10210 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 3.7 | CVE-2018-10211 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 5.4 | CVE-2018-10212 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 4.1 | CVE-2018-10213 | 2018/04/18 | 17.05.31 |
| Vaultize Enterprise File Sharing | 7.5 | CVE-2018-10206 | 2018/04/10 | 17.05.31 |
| IBM Content Navigator | 5.4 | CVE-2017-1331 | 2017/08/04 | Versions 2.0.3.5, 2.0.3.6, 2.0.3.7, 2.0.3.8, 3.0.0 |
| IBM Content Navigator | 5.4 | CVE-2017-1282 | 2017/05/26 | Versions 2.0.3.5, 2.0.3.6, 2.0.3.7, 2.0.3.8, 3.0.0 |
| Drupal security module named SecKit | 5.3 | XLM-2016-121 | 2016/10/05 | Version inferior or equals to SecKit 7.x-1.9 |
| Password Manager Pro | 6.5 | CVE-2016-1161 | 2016/07/01 | Versions inferior to 8.5 |
| Password Manager Pro | 6.5 | CVE-2016-1159 | 2016/03/24 | 8.3.0 (Build 8303) and version 8.4.0 (Build 8400,8401,8402) |
| AXIOM | 4.9 | CVE-2015-5384 | 2015/09/01 | 9.5.3 |
| Lenovo MouseSuite | 6.9 | CVE-2015-4596 | 2015/08/19 | 6.72 and prior |
| AXIOM | 6.8 | CVE-2015-5462 | 2015/07/30 | 9.5.3 |
| AXIOM | 9 | CVE-2015-5463 | 2015/07/30 | 9.5.3 |
| Linux operating system | 6.8 | CVE-2015-5606 | 2015/07/23 | 7.2.2 |
Security Advisory
CVE Responsible Disclosure Policy
TCS-CERT (Thales Cyber Solutions Customer's CERT) is a certified team of TF-CSIRT Trusted Introducer, member of FIRST, CERT.LU initiative and Belgian Cyber Coalition.
As a Computer Emergency Response Team (CERT), TCS-CERT is committed to share with peers and constituencies the identified vulnerabilities in vendors' products.
Reporting a vulnerability to a vendor is a way to improve cybersecurity globally. It allows users to be notified of the issue and let them perform the appropriate remediation. Conversely, the reporting must be performed with care to avoid giving knowledge of potential victims of attackers.
Whenever a new vulnerability is discovered and reported, TCS-CERT will oversee the public disclosure. TCS-CERT uses a responsible disclosure process to inform the vendors in coordination with the Vendor/Vendor's PSIRT (Product Security Incident Response Team) and the CVE numbering authority.
If requested, during this process, Thales' clients are kept informed of the vendor feedback, the proposed action plan, and the timeline for the mitigation of the issues.
No matter how and who discovered the vulnerability, TCS-CERT will not, in any case, reveal the customer's name from which the finding was made.
If the vendor wishes to publish the CVE by itself, and/or if the vendor is an official CVE Numbering Authorities (CNA), TCS-CERT's would accompany them until the end of the process when the vulnerability is registered and disclosed on the vendor's website, CVE numbering authorities and on Thales Cyber Solutions' website advisory page.
Up to ten (10) days are allowed for the point of contact to acknowledge the finding. After which, TCS-CERT will start the CVE registration process, no matter if the acknowledgment was given.
Any vulnerability will be registered to the CNA So that the vulnerability is associated with a CVE Identifier (CVE ID), formed as follow: "CVE-YYYY-DDDD" (YYYY being the registration's year, and DDDD a number attributed by the CVE numbering authority).
A thirsty (30) days period is allowed for the vendor to work on a fix. This grace period can be extended, on-demand and only if backed-up by strong technical explanations, to ninety (90) days at most.
Any CVE that TCS-CERT reported to a vendor will, once a fix is made available (or the grace period expired) leading to its public disclosed, be referenced on TCS-CERT website advisory page with the CVE ID. Vulnerability registration will be updated with available information from the vendor's PSIRT, if any.
Vendors are kindly asked to refer in their public disclosure:
to this webpage (using the URL https://cds.thalesgroup.com/en/tcs-cert/advisory/<CVE-ID>)
To the finder's name (only when requested).
TCS-CERT never discloses information that could directly help third parties exploiting a vulnerability in a product.
In case the vendors solicitations, the vulnerability will be responsibly disclosed 90 day after TCS-CERT notified incident response teams of the groups to which TCS-CERT belongs.
Thales products security advisories.
To report a potential vulnerability that impacts Thales products or services, please contact Thales PSIRT by sending an email to psirt@thalesgroup.com.
Thales products vulnerabilities are published here;
https://www.thalesgroup.com/en/global/group/psirt/thales-product-security-advisories
TCS-CERT - Security advisory
On the table below you can find TCS-CERT's published and reported vulnerabilities.