Comparison Overview
BlueCross BlueShield of Tennessee

BlueCross BlueShield of Tennessee
1 Cameron Hill Circle, Chattanooga, 37402-2555, US
Last Update: 02/04/2026
As Tennessee's largest health plan, we've been helping Tennesseans find their own unique paths to good health for more than 70 years. More than that, we're your neighbors and friends – fellow Tennesseans with deep roots of caring tradition, a focused approach to physica...

Mapfre
Carretera de Pozuelo, 52, Majadahonda, Community of Madrid, ES, 28220
Last Update: 02/04/2026
At Mapfre, we’ve spent more than 90 years supporting people and businesses around the world, taking care of what matters most to them. We offer insurance, financial, and service solutions that evolve with you. Our experience and commitment, combined with a constant focu...
Compliance Ranges Comparison

BlueCross BlueShield of Tennessee







Mapfre






Benchmark & Cyber Underwriting Signals
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for BlueCross BlueShield of Tennessee in 2026.
Incidents vs Insurance Industry Avg (This Year)
No incidents recorded for Mapfre in 2026.
Incident History - BlueCross BlueShield of Tennessee (X = Date, Y = Severity)
BlueCross BlueShield of Tennessee cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Mapfre (X = Date, Y = Severity)
Mapfre cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

BlueCross BlueShield of Tennessee

Mapfre
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).