Comparison Overview
Cua (YC X25)

Cua (YC X25)
San Francisco, US
Last Update: 10/03/2026
Cua is an open-source framework that enables AI agents to control full operating systems within high-performance, lightweight virtual containers. It delivers up to 90% native speed on Apple Silicon and works with any language models. Cua is backed by Y Combinator, and ...

Airbnb
888 Brannan Street, San Francisco, CA, US, 94103
Last Update: 09/08/2026
Airbnb was born in 2007 when two hosts welcomed three guests to their San Francisco home, and has since grown to over 5 million hosts who have welcomed over 2 billion guest arrivals in almost every country across the globe. Every day, hosts offer unique stays, experienc...
Compliance Ranges Comparison

Cua (YC X25)







Airbnb






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
Cua (YC X25) has 6.54% fewer incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Airbnb in 2026.
Incident History - Cua (YC X25) (X = Date, Y = Severity)
Cua (YC X25) cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Airbnb (X = Date, Y = Severity)
Airbnb cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Cua (YC X25)

Airbnb
FAQ
Latest Global CVEs
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the component execute Tool. The manipulation results in code injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.