Comparison Overview
Flextrack Inc

Flextrack Inc
1130 Situs Ct, Raleigh, North Carolina, 27606, US
Last Update: 10/02/2026
Flextrack is here for good - for business, for people, and community. We are the world’s premiere next-gen extended workforce platform powered by Salesforce. Designed by expert contingent workforce practitioners and technologists, Flextrack provides an open approach to...

Dassault Systèmes
10, rue Marcel Dassault, Vélizy-Villacoublay, 78140, FR
Last Update: 02/04/2026
Dassault Systèmes is a catalyst for human progress. Since 1981, the company has pioneered virtual worlds to improve real life for consumers, patients and citizens. With Dassault Systèmes’ 3DEXPERIENCE platform, 370,000 customers of all sizes, in all industries, can co...
Compliance Ranges Comparison

Flextrack Inc







Dassault Systèmes






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Flextrack Inc in 2026.
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Dassault Systèmes in 2026.
Incident History - Flextrack Inc (X = Date, Y = Severity)
Flextrack Inc cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Dassault Systèmes (X = Date, Y = Severity)
Dassault Systèmes cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Flextrack Inc

Dassault Systèmes
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.