Comparison Overview
CCNY School of Education

CCNY School of Education
160 Convent Ave, New York, New York, 10031, US
Last Update: 03/02/2026
At the CCNY School of Education, aspiring and experienced educators join a community of scholars and practitioners who embrace the opportunities for all students that are found in an urban environment. We believe that diversity—among our students, faculty, and staff, ac...

Ghent University
Universiteitsforum (Ufo) Sint-Pietersnieuwstraat 33, Gent, Gent, east flanders, BE, 9000
Last Update: 30/03/2026
Ghent University is a top 100 university and one of the major universities in Belgium, founded in 1817. Our 11 faculties offer a wide range of courses and conduct in-depth research within a wide range of scientific domains. We are a pluralistic university that is open t...
Compliance Ranges Comparison

CCNY School of Education







Ghent University






Benchmark & Cyber Underwriting Signals
Incidents vs Higher Education Industry Avg (This Year)
No incidents recorded for CCNY School of Education in 2026.
Incidents vs Higher Education Industry Avg (This Year)
No incidents recorded for Ghent University in 2026.
Incident History - CCNY School of Education (X = Date, Y = Severity)
CCNY School of Education cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Ghent University (X = Date, Y = Severity)
Ghent University cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

CCNY School of Education

Ghent University
FAQ
Latest Global CVEs
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This issue is fixed in version 2.1.5.
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or overwrite files via MOVE with Overwrite: T. This issue is fixed in version 2.1.4.
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left both SFTP authentication handlers unset and allowed unauthenticated file access. This issue is fixed in version 2.1.4.
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constructs multipart HTTP request bodies by directly concatenating user-supplied filenames and field names into Content-Disposition MIME headers without validating or sanitizing CRLF characters (\r\n). Since MIME headers are delimited by CRLF, an attacker who controls the filename can inject arbitrary MIME headers into the multipart body part. The root cause is that neither the encoder nor the FileUpload implementations' setFilename() methods, which only check for null, neutralize CRLF characters before the filename is embedded into the header. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.