Comparison Overview
Ecobank Rwanda

Ecobank Rwanda
N/A
Last Update: 02/04/2026
Ecobank Rwanda PLC was established on 6th July 2007. It is licensed and supervised by the National Bank of Rwanda. The Bank has its Head Office located in KN4 Avenue in Kigali, Nyarugenge District, and has 8 other branches, 32 ATMs, 290 Xpress Point agents,2272 merchant...

Rabobank
Croeselaan 18, Utrecht, 3521CB, NL
Last Update: 29/03/2026
Rabobank is a cooperative bank with a mission. Our goal: to help customers realize their ambitions. We serve about 10 million customers in 47 countries. As an international financial institution, we work on the well-being and prosperity of millions of people. In the Net...
Compliance Ranges Comparison

Ecobank Rwanda







Rabobank






Benchmark & Cyber Underwriting Signals
Incidents vs Banking Industry Avg (This Year)
No incidents recorded for Ecobank Rwanda in 2026.
Incidents vs Banking Industry Avg (This Year)
No incidents recorded for Rabobank in 2026.
Incident History - Ecobank Rwanda (X = Date, Y = Severity)
Ecobank Rwanda cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Rabobank (X = Date, Y = Severity)
Rabobank cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Ecobank Rwanda

Rabobank
FAQ
Latest Global CVEs
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
- https://github.com/NginxProxyManager/nginx-proxy-manager
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28
- https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908
- https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
- https://github.com/NginxProxyManager/nginx-proxy-manager
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908
- https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
- https://github.com/cle-b/httpdbg
- https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97
- https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302
- https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3
- https://github.com/cle-b/httpdbg/issues/220
- https://github.com/cle-b/httpdbg/pull/222
- https://github.com/cle-b/httpdbg/releases/tag/v2.2.1
- https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
- https://github.com/amir20/dozzle
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/container/docker/client.go#L610-L614
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/web/download.go#L141-L146
- https://github.com/amir20/dozzle/commit/bc07db73dd84ce2cb939b744e983a8cfdf29c644
- https://github.com/amir20/dozzle/pull/5242
- https://github.com/amir20/dozzle/releases/tag/v11.1.2
- https://www.vulncheck.com/advisories/dozzle-before-11.1.2-path-traversal-via-log-zip-download
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.