Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

CORE | OCRECORE | OCRE
VS
South African Revenue Service (SARS)South African Revenue Service (SARS)
CORE | OCRE

CORE | OCRE

N/A

Last Update: 02/04/2026

View Profile
Between 750 and 799
http://core-ombuds.canada.ca
777/1000Fair

The CORE is the office of the Canadian Ombudsperson for Responsible Enterprise. We are a human rights ombudsperson or “ombud.” We review complaints about possible human rights abuses by Canadian companies when those companies work outside Canada in the garment, mining, ...

NAICS:92
NAICS Definition:Public Administration
Employees:None
Subsidiaries:19
12-month incidents
0
Known data breaches
0
Attack type number
0
South African Revenue Service (SARS)

South African Revenue Service (SARS)

Lehae La Sars, Pretoria, 0001, ZA

Last Update: 29/03/2026

View Profile
Between 750 and 799
http://www.sars.gov.za
795/1000Fair

Its main functions are to: collect and administer all national taxes, duties and levies; collect revenue that may be imposed under any other legislation, as agreed on between SARS and an organ of state or institution entitled to the revenue; provide protection a...

NAICS:92
NAICS Definition:Public Administration
Employees:11,341
Subsidiaries:0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Ranges Comparison

Based On Specific Ai Models Category
CORE | OCRE

CORE | OCRE

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
South African Revenue Service (SARS)

South African Revenue Service (SARS)

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Government Administration Industry Avg (This Year)

No incidents recorded for CORE | OCRE in 2026.

Incidents

Incidents vs Government Administration Industry Avg (This Year)

No incidents recorded for South African Revenue Service (SARS) in 2026.

Incidents

Incident History - CORE | OCRE (X = Date, Y = Severity)

CORE | OCRE cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - South African Revenue Service (SARS) (X = Date, Y = Severity)

South African Revenue Service (SARS) cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
CORE | OCRE

CORE | OCRE

Incidents
No explicit notable incidents reported.
South African Revenue Service (SARS)

South African Revenue Service (SARS)

Incidents
No explicit notable incidents reported.

FAQ

Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has the best AI Cybersecurity Score ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has experienced more cyber incidents in the past ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has experienced more cyber incidents this year ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has experienced at least one ransomware attack ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has experienced at least one data breach ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has experienced at least one targeted cyberattack ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has experienced at least one vulnerability ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one holds the most compliance certifications ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one holds the fewest compliance certifications ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has the most subsidiaries ?
Between CORE | OCRE company and South African Revenue Service (SARS) company, which one has the largest number of employees ?
Between CORE | OCRE and South African Revenue Service (SARS), which company holds both SOC 2 Type 1 certifications ?
Between CORE | OCRE and South African Revenue Service (SARS), which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - CORE | OCRE or South African Revenue Service (SARS) ?
Which company is PCI DSS compliant - CORE | OCRE or South African Revenue Service (SARS) ?
Between CORE | OCRE and South African Revenue Service (SARS), which company complies with HIPAA regulations for healthcare data ?
Between CORE | OCRE and South African Revenue Service (SARS), which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-83524
SUMMARY

A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-31
UPDATED
Date2026-08-31
RISK INFORMATION (Score: 9.9)
CVSS2
Base Score: 9.0
Complexity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Base Score: 9.9
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS4
Base Score: 8.6
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
6
EXPLOITABILITY
3.1
CVE-2026-82971
SUMMARY

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.

PUBLISHED
Date2026-08-31
UPDATED
Date2026-08-31
RISK INFORMATION (Score: 10)
CVSS2
Base Score: 10.0
Complexity: LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS3
Base Score: 10.0
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS4
Base Score: 9.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
6
EXPLOITABILITY
3.9
CVE-2026-82957
SUMMARY

A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-31
UPDATED
Date2026-08-31
RISK INFORMATION (Score: 7.3)
CVSS2
Base Score: 7.5
Complexity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Base Score: 7.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 5.5
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
3.9
CVE-2026-82954
SUMMARY

A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-31
UPDATED
Date2026-08-31
RISK INFORMATION (Score: 9.9)
CVSS2
Base Score: 9.0
Complexity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Base Score: 9.9
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS4
Base Score: 8.6
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
6
EXPLOITABILITY
3.1
CVE-2026-82922
SUMMARY

A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-31
UPDATED
Date2026-08-31
RISK INFORMATION (Score: 7.3)
CVSS2
Base Score: 7.5
Complexity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Base Score: 7.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 5.5
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
3.9