Comparison Overview
Tata Consultancy Services - Research

Tata Consultancy Services - Research
Mumbai, 400001, IN
Last Update: 03/04/2026
TCS Research believes in the power of inspiration and invention to build greater futures. Our world-class researchers apply scientific rigor and a collaborative mindset to solve problems faced by industry and society. We aspire to transform the world we live in by power...

The University of Edinburgh
Old College, South Bridge, Edinburgh, GB, EH8 9YL
Last Update: 01/04/2026
Imagine what you could do at a world-leading university that is globally recognised for its teaching, research and innovation. The University of Edinburgh has been providing students with world-class teaching for more than 425 years, unlocking the potential of some o...
Compliance Ranges Comparison

Tata Consultancy Services - Research







The University of Edinburgh






Benchmark & Cyber Underwriting Signals
Incidents vs Research Services Industry Avg (This Year)
No incidents recorded for Tata Consultancy Services - Research in 2026.
Incidents vs Research Services Industry Avg (This Year)
No incidents recorded for The University of Edinburgh in 2026.
Incident History - Tata Consultancy Services - Research (X = Date, Y = Severity)
Tata Consultancy Services - Research cyber incidents detection timeline including parent company and subsidiaries.
Incident History - The University of Edinburgh (X = Date, Y = Severity)
The University of Edinburgh cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Tata Consultancy Services - Research

The University of Edinburgh
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.