Comparison Overview
Oil by S&P Global Energy

Oil by S&P Global Energy
55 Water St, New York, US, 10041
Last Update: 28/04/2026
We produce price assessments, news & analysis for Crude Oil, Fuel oil, Jet, Gasoil, Diesel, Bunker & Refining. They are widely used as benchmarks in physical & futures markets in over 180 countries.

Bharat Petroleum Corporation Limited
Mumbai, IN
Last Update: 07/09/2026
Fortune Global 500 Company, Bharat Petroleum is the second largest Indian Oil Marketing Company and one of the premier integrated energy companies in India, engaged in refining of crude oil and marketing of petroleum products, with a significant presence in the upstream...
Compliance Ranges Comparison

Oil by S&P Global Energy







Bharat Petroleum Corporation Limited






Benchmark & Cyber Underwriting Signals
Incidents vs Oil and Gas Industry Avg (This Year)
No incidents recorded for Oil by S&P Global Energy in 2026.
Incidents vs Oil and Gas Industry Avg (This Year)
No incidents recorded for Bharat Petroleum Corporation Limited in 2026.
Incident History - Oil by S&P Global Energy (X = Date, Y = Severity)
Oil by S&P Global Energy cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Bharat Petroleum Corporation Limited (X = Date, Y = Severity)
Bharat Petroleum Corporation Limited cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Oil by S&P Global Energy

Bharat Petroleum Corporation Limited
FAQ
Latest Global CVEs
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).