Comparison Overview
Netflights

Netflights
Centurion Way, Preston, PR26 6TX, GB
Last Update: 10/03/2026
We could have called ourselves Netflightsholidayscarhire, but we thought that was a bit long. Our bread and butter? Getting bums on thousands of flights every year for the last thirty of ‘em. But we’ve also got a whopping 40,000 pads to pick from and a bunch of car hire...

MSC Cruises
Avenue Eugene Pittard, Geneva, 1206, CH
Last Update: 20/09/2026
Headquartered in Geneva, Switzerland, MSC Cruises is the world’s third largest cruise lines and the market leader in Europe, South America, the Middle East and Southern Africa, with a strong and growing presence in North America and the Far East. The MSC Cruises fleet ...
Compliance Ranges Comparison

Netflights







MSC Cruises






Benchmark & Cyber Underwriting Signals
Incidents vs Travel Arrangements Industry Avg (This Year)
No incidents recorded for Netflights in 2026.
Incidents vs Travel Arrangements Industry Avg (This Year)
No incidents recorded for MSC Cruises in 2026.
Incident History - Netflights (X = Date, Y = Severity)
Netflights cyber incidents detection timeline including parent company and subsidiaries.
Incident History - MSC Cruises (X = Date, Y = Severity)
MSC Cruises cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Netflights

MSC Cruises
FAQ
Latest Global CVEs
A malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
A vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue. The patch is identified as 89f2916b6a46ff91bd1999ce38158fa0de8b9490. Upgrading the affected component is recommended.
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-07-Unauthenticated-InstallerBypass.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/89f2916b6a46ff91bd1999ce38158fa0de8b9490
- https://github.com/krayin/laravel-crm/pull/2614
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.5
- https://vuldb.com/cve/CVE-2026-100885
- https://vuldb.com/submit/916597
- https://vuldb.com/vuln/410815
- https://vuldb.com/vuln/410815/cti
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.2.6 is sufficient to resolve this issue. The identifier of the patch is 13d6988cda8d69ece45ee1890effc90a7f21cdc1. It is suggested to upgrade the affected component.
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-06-IDOR-Email-Attachment%20Download.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/13d6988cda8d69ece45ee1890effc90a7f21cdc1
- https://github.com/krayin/laravel-crm/issues/2624
- https://github.com/krayin/laravel-crm/pull/2627
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
- https://vuldb.com/cve/CVE-2026-100884
- https://vuldb.com/submit/916218
- https://vuldb.com/vuln/410814
- https://vuldb.com/vuln/410814/cti
A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fix this issue. This patch is called a399404a388d8ad2700a01349d0d98069c8e85a4. The affected component should be upgraded.
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-05-Missing-Function-Level%20Authorization.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/a399404a388d8ad2700a01349d0d98069c8e85a4
- https://github.com/krayin/laravel-crm/issues/2623
- https://github.com/krayin/laravel-crm/pull/2626
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
- https://vuldb.com/cve/CVE-2026-100883
- https://vuldb.com/submit/916128
- https://vuldb.com/vuln/410813
- https://vuldb.com/vuln/410813/cti