Comparison Overview
Cloud4C Korea

Cloud4C Korea
강남구 도산대로37길 26 2층, 서울시, undefined, 06024, KR
Last Update: 04/04/2026
기업용 글로벌 클라우드 솔루션 MSP (Managed Service Provider)인 클라우드포씨 코리아입니다. Cloud4C는 일반 클라우드(공공, 민간, 하이브리드)와 커뮤니티 클라우드 (뱅킹 커뮤니티 클라우드, SAP 커뮤니티 클라우드) 서비스를 비롯하여, AWS, MS Azure, Google Cloud 같은 하이퍼스케일러에서 클라우드 이동, 포괄적인 관리 서비스, 재난 복구 서비스, 관리 보안 서비스 등 엔드투엔드 서비스를 고객에게 제공합니다. 싱가폴 본사를 기반으...

Persistent Systems
Bhageerath, 402 E, Senapati Bapat Road, Pune, Maharashtra, IN, 411016
Last Update: 02/04/2026
We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what’s next. Our offerings and proven solutions create a unique competitive advantage fo...
Compliance Ranges Comparison

Cloud4C Korea







Persistent Systems






Benchmark & Cyber Underwriting Signals
Incidents vs IT Services and IT Consulting Industry Avg (This Year)
No incidents recorded for Cloud4C Korea in 2026.
Incidents vs IT Services and IT Consulting Industry Avg (This Year)
No incidents recorded for Persistent Systems in 2026.
Incident History - Cloud4C Korea (X = Date, Y = Severity)
Cloud4C Korea cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Persistent Systems (X = Date, Y = Severity)
Persistent Systems cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Cloud4C Korea

Persistent Systems
FAQ
Latest Global CVEs
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
- https://github.com/NginxProxyManager/nginx-proxy-manager
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28
- https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908
- https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
- https://github.com/NginxProxyManager/nginx-proxy-manager
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908
- https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
- https://github.com/cle-b/httpdbg
- https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97
- https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302
- https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3
- https://github.com/cle-b/httpdbg/issues/220
- https://github.com/cle-b/httpdbg/pull/222
- https://github.com/cle-b/httpdbg/releases/tag/v2.2.1
- https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
- https://github.com/amir20/dozzle
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/container/docker/client.go#L610-L614
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/web/download.go#L141-L146
- https://github.com/amir20/dozzle/commit/bc07db73dd84ce2cb939b744e983a8cfdf29c644
- https://github.com/amir20/dozzle/pull/5242
- https://github.com/amir20/dozzle/releases/tag/v11.1.2
- https://www.vulncheck.com/advisories/dozzle-before-11.1.2-path-traversal-via-log-zip-download
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.