Comparison Overview
Aviva Services Excellence Centre

Aviva Services Excellence Centre
Ul. Inflancka 4b Warszawa, , Mazowieckie, PL, 00-189
Last Update: 04/12/2025
Aviva Service Excellence Centre has been operating in Poland for 15 years and is a rapidly growing center of expertise in the field of actuarial, IT, data science, CISO, finance and risk. Currently, it employs nearly 400 specialists and is constantly growing.

PING AN
No. 5033 Yitian Road, Futian District, Shenzhen, 518046, CN
Last Update: 27/05/2026
This is the official Company Page of Ping An Insurance (Group) Company of China, Ltd. (HKEx: 2318; SSE: 601318; ADR: PNGAY). Ping An strives to become a world leading technology-powered financial services group. We believe the way people receive financial services an...
Compliance Ranges Comparison

Aviva Services Excellence Centre







PING AN






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for Aviva Services Excellence Centre in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for PING AN in 2026.
Incident History - Aviva Services Excellence Centre (X = Date, Y = Severity)
Aviva Services Excellence Centre cyber incidents detection timeline including parent company and subsidiaries.
Incident History - PING AN (X = Date, Y = Severity)
PING AN cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Aviva Services Excellence Centre

PING AN
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).