Comparison Overview
CRIF - Czech Credit Bureau, a.s.

CRIF - Czech Credit Bureau, a.s.
Stetkova 18, Praha, 140 00, CZ
Last Update: 21/02/2026
CRIF je globální společnost, která se specializuje na zpracování obchodních informací, outsourcing a úvěrová řešení. Založena byla v roce 1988, a to v italském městě Bologna. V současnosti působí na čtyřech kontinentech (Evropa, Amerika, Afrika a Asie). Posláním společ...

Thoughtworks
200 E Randolph St, 25th Floor, Chicago, IL, US, 60601-6501
Last Update: 02/04/2026
We are a global technology consultancy that delivers extraordinary impact by blending design, engineering and AI expertise. For 30 years, our commitment to design-led thinking, engineering excellence and innovation means we prioritize people, build teams with strong te...
Compliance Ranges Comparison

CRIF - Czech Credit Bureau, a.s.







Thoughtworks






Benchmark & Cyber Underwriting Signals
Incidents vs Information Technology & Services Industry Avg (This Year)
No incidents recorded for CRIF - Czech Credit Bureau, a.s. in 2026.
Incidents vs Information Technology & Services Industry Avg (This Year)
No incidents recorded for Thoughtworks in 2026.
Incident History - CRIF - Czech Credit Bureau, a.s. (X = Date, Y = Severity)
CRIF - Czech Credit Bureau, a.s. cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Thoughtworks (X = Date, Y = Severity)
Thoughtworks cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

CRIF - Czech Credit Bureau, a.s.

Thoughtworks
FAQ
Latest Global CVEs
ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attacker to bypass certificate validation via a certificate with multiple simultaneous faults, enabling a Man-in-the-Middle attack on protected communications.
A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The manipulation results in improper privilege management. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-custom-domain-rewrite.ts. The manipulation leads to server-side request forgery. The attack may be initiated remotely. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The identifier of the patch is 86f370c9c20074c3c3fdec53a359874b8e670fd4. It is suggested to install a patch to address this issue. This issue got fixed with a silent patch.
- https://github.com/openstatusHQ/openstatus/
- https://github.com/openstatusHQ/openstatus/commit/86f370c9c20074c3c3fdec53a359874b8e670fd4
- https://github.com/openstatusHQ/openstatus/pull/2551
- https://vuldb.com/cve/CVE-2026-90486
- https://vuldb.com/submit/888087
- https://vuldb.com/vuln/403074
- https://vuldb.com/vuln/403074/cti
SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle username capitalization differently, which may allow multiple SEP sesam user accounts to be created for the same Active Directory (AD) account. Active Directory treats usernames as case-insensitive, while SEP sesam distinguishes between different letter casing. As a result, the same AD user can be represented by multiple SEP sesam user accounts that differ only in username capitalization. When Active Directory authentication is configured and multi-factor authentication (MFA) is enforced, this behavior may allow an additional OTP Authenticator to be registered for the same AD account, reducing the effectiveness of MFA protection.
A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical IURegistryFilter.sys ships across multiple IObit families. The vendor was contacted early about this disclosure but did not respond in any way.