Comparison Overview
Defence Research and Development Canada | Recherche et développement pour la défense Canada

Defence Research and Development Canada | Recherche et développement pour la défense Canada
Major-General George R. Pearkes Building, Ottawa, K1A 0K2, CA
Last Update: 11/03/2026
Defence Research and Development Canada (DRDC) is the national leader in defence and security science and technology. As the science and technology organization of Canada’s Department of National Defence (DND), DRDC provides DND, the Canadian Armed Forces (CAF), other g...

BAE Systems
BAE Systems, London, SW1Y 5AD, GB
Last Update: 01/04/2026
At BAE Systems, we help our customers to stay a step ahead when protecting people and national security, critical infrastructure and vital information. We provide some of the world’s most advanced, technology-led defence, aerospace and security solutions and employ a sk...
Compliance Ranges Comparison

Defence Research and Development Canada | Recherche et développement pour la défense Canada







BAE Systems






Benchmark & Cyber Underwriting Signals
Incidents vs Defense and Space Manufacturing Industry Avg (This Year)
No incidents recorded for Defence Research and Development Canada | Recherche et développement pour la défense Canada in 2026.
Incidents vs Defense and Space Manufacturing Industry Avg (This Year)
No incidents recorded for BAE Systems in 2026.
Incident History - Defence Research and Development Canada | Recherche et développement pour la défense Canada (X = Date, Y = Severity)
Defence Research and Development Canada | Recherche et développement pour la défense Canada cyber incidents detection timeline including parent company and subsidiaries.
Incident History - BAE Systems (X = Date, Y = Severity)
BAE Systems cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Defence Research and Development Canada | Recherche et développement pour la défense Canada

BAE Systems
FAQ
Latest Global CVEs
A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System Clock. The manipulation leads to command injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor explains: "QVidium has now closed its doors and no longer will be able to sell products or provide support." This vulnerability only affects products that are no longer supported by the maintainer.
A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.