Comparison Overview
Carelon Global Solutions Ireland

Carelon Global Solutions Ireland
Limerick, IE
Last Update: 19/03/2026
Carelon Global Solutions makes healthcare operations more practical, effective, and efficient. Our global team of more than 25K innovators drives growth, delivers exceptional support, and develops digital tools specifically for health plans, providers, and systems. Each...

Serco
16 Bartley Wood Business Park, Bartley Way, Hook, RG27 9UY, GB
Last Update: 03/04/2026
We bring together the right people, the right technology and the right partners to create innovative solutions that make positive impact and address some of the most urgent and complex challenges facing the modern world. With a focus on serving governments globally, ...
Compliance Ranges Comparison

Carelon Global Solutions Ireland







Serco






Benchmark & Cyber Underwriting Signals
Incidents vs IT Services and IT Consulting Industry Avg (This Year)
No incidents recorded for Carelon Global Solutions Ireland in 2026.
Incidents vs IT Services and IT Consulting Industry Avg (This Year)
No incidents recorded for Serco in 2026.
Incident History - Carelon Global Solutions Ireland (X = Date, Y = Severity)
Carelon Global Solutions Ireland cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Serco (X = Date, Y = Severity)
Serco cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Carelon Global Solutions Ireland

Serco
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.