Comparison Overview
Thomas Jefferson University

Thomas Jefferson University
4201 Henry Ave, Philadelphia, Pennsylvania, 19144, US
Last Update: 19/03/2026
Thomas Jefferson University is dedicated to reimagining health, education and discovery to create unparalleled value. At Jefferson, our students cross disciplines to discover new possibilities and work with expert faculty who know just what it takes to break the mold....

Texas A&M University
805 Rudder Tower, College Station, TX, US, 77843
Last Update: 02/04/2026
Texas A&M University has a proud history that stretches back to 1876 when The Agricultural and Mechanical College of Texas became the first public institution of higher learning in the state of Texas. Nestled in the heart of the Houston-Dallas-Austin triangle, Texas A&M...
Compliance Ranges Comparison

Thomas Jefferson University







Texas A&M University






Benchmark & Cyber Underwriting Signals
Incidents vs Higher Education Industry Avg (This Year)
No incidents recorded for Thomas Jefferson University in 2026.
Incidents vs Higher Education Industry Avg (This Year)
No incidents recorded for Texas A&M University in 2026.
Incident History - Thomas Jefferson University (X = Date, Y = Severity)
Thomas Jefferson University cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Texas A&M University (X = Date, Y = Severity)
Texas A&M University cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Thomas Jefferson University

Texas A&M University
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.