Comparison Overview
KPMGジャパン/KPMG Japan

KPMGジャパン/KPMG Japan
大手町1丁目9番7号, 千代田区, 東京都, 100-0004, JP
Last Update: 26/12/2025
KPMGジャパンは、KPMGインターナショナルの日本におけるメンバーファームの総称であり、監査、税務、アドバイザリーの3つの分野にわたる7つのプロフェッショナルファームによって構成されています。 KPMGジャパンのメンバーファーム: 各分野のプロフェッショナルが専門的知識やスキルを活かして連携し、KPMGのグローバルネットワークも活用しながらサービスを提供しています。 ・あずさ監査法人 ・KPMG税理士法人 ・KPMGコンサルティング ・KPMG FAS ・KPMGあずさサステナビリティ ・KPMGヘルスケアジャパン ・KPMG社...

Applus+
C/Campezo 1, Edificio 3, Madrid, 28022, ES
Last Update: 13/09/2026
Applus+ is a worldwide leader in the testing, inspection, and certification sector. We are a trusted partner, enhancing the quality and safety of our clients’ assets and infrastructures while safeguarding their operations and improving their environmental performance. O...
Compliance Ranges Comparison

KPMGジャパン/KPMG Japan







Applus+






Benchmark & Cyber Underwriting Signals
Incidents vs Business Consulting and Services Industry Avg (This Year)
No incidents recorded for KPMGジャパン/KPMG Japan in 2026.
Incidents vs Business Consulting and Services Industry Avg (This Year)
No incidents recorded for Applus+ in 2026.
Incident History - KPMGジャパン/KPMG Japan (X = Date, Y = Severity)
KPMGジャパン/KPMG Japan cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Applus+ (X = Date, Y = Severity)
Applus+ cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

KPMGジャパン/KPMG Japan

Applus+
FAQ
Latest Global CVEs
vLLM through 0.29.0 fails to properly clean up decode-side metadata for rejected inference requests in prefill/decode disaggregated deployments. Remote attackers can submit requests with max_tokens=0 to exhaust decode-worker memory without bound until the worker restarts.
- https://github.com/vllm-project/vllm
- https://github.com/vllm-project/vllm/blob/v0.29.0/vllm/distributed/kv_transfer/kv_connector/v1/nixl/push_worker.py#L162-L181
- https://github.com/vllm-project/vllm/pull/55677
- https://www.vulncheck.com/advisories/vllm-through-0.29.0-memory-exhaustion-via-rejected-requests
redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious Redis endpoints to crash the client process through unbounded recursion on nested arrays. Attackers can send crafted RESP byte streams with repeated array headers that exhaust the V8 call stack, causing an uncaught RangeError that terminates the Node.js process without triggering error handling callbacks.
- https://github.com/NodeRedis/node-redis-parser
- https://github.com/NodeRedis/node-redis-parser/blob/701655430f5f7d9ca00892a02f7eefcbc1193a98/lib/parser.js#L204-L213
- https://github.com/NodeRedis/node-redis-parser/blob/701655430f5f7d9ca00892a02f7eefcbc1193a98/lib/parser.js#L291-L306
- https://github.com/redis/ioredis/issues/2108
- https://www.vulncheck.com/advisories/redis-parser-through-3.0.0-denial-of-service-via-unbounded-recursion
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.