Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

OraOra
VS
SanofiSanofi
Ora

Ora

138 Haverhill St, Andover, 01810, US

Last Update: 04/04/2026

View Profile
Between 700 and 749
http://www.oraclinical.com
713/1000Moderate

Ora is the world's leading full-service ophthalmic drug and device development firm with offices in the United States, United Kingdom, Australia, and Asia. For over 45 years, we have proudly helped our clients earn more than 85 product approvals. We support a wide array...

NAICS:3254
NAICS Definition:Pharmaceutical and Medicine Manufacturing
Employees:690
Subsidiaries:0
12-month incidents
0
Known data breaches
1
Attack type number
1
Sanofi

Sanofi

46 Avenue de la Grande-Armée, Paris, France, FR, 75017

Last Update: 20/05/2026

View Profile
Between 800 and 849
http://www.sanofi.com
824/1000Good

We are an R&D driven, AI-powered biopharma company committed to improving people’s lives and delivering compelling growth. We apply our deep understanding of the immune system to invent medicines and vaccines that treat and protect millions of people around the world,...

NAICS:3254
NAICS Definition:Pharmaceutical and Medicine Manufacturing
Employees:91,571
Subsidiaries:5
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Ranges Comparison

Based On Specific Ai Models Category
Ora

Ora

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Sanofi

Sanofi

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)

No incidents recorded for Ora in 2026.

Incidents

Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)

No incidents recorded for Sanofi in 2026.

Incidents

Incident History - Ora (X = Date, Y = Severity)

Ora cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Sanofi (X = Date, Y = Severity)

Sanofi cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
Ora

Ora

Incidents
🔒 Incident : Breach
ORA315072625
Sanofi

Sanofi

Incidents
No explicit notable incidents reported.

FAQ

Between Ora company and Sanofi company, which one has the best AI Cybersecurity Score ?
Between Ora company and Sanofi company, which one has experienced more cyber incidents in the past ?
Between Ora company and Sanofi company, which one has experienced more cyber incidents this year ?
Between Ora company and Sanofi company, which one has experienced at least one ransomware attack ?
Between Ora company and Sanofi company, which one has experienced at least one data breach ?
Between Ora company and Sanofi company, which one has experienced at least one targeted cyberattack ?
Between Ora company and Sanofi company, which one has experienced at least one vulnerability ?
Between Ora company and Sanofi company, which one holds the most compliance certifications ?
Between Ora company and Sanofi company, which one holds the fewest compliance certifications ?
Between Ora company and Sanofi company, which one has the most subsidiaries ?
Between Ora company and Sanofi company, which one has the largest number of employees ?
Between Ora and Sanofi, which company holds both SOC 2 Type 1 certifications ?
Between Ora and Sanofi, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - Ora or Sanofi ?
Which company is PCI DSS compliant - Ora or Sanofi ?
Between Ora and Sanofi, which company complies with HIPAA regulations for healthcare data ?
Between Ora and Sanofi, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-19961
SUMMARY

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-16
UPDATED
Date2026-08-16
RISK INFORMATION (Score: 9.9)
CVSS2
Base Score: 9.0
Complexity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Base Score: 9.9
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS4
Base Score: 8.6
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
6
EXPLOITABILITY
3.1
CVE-2026-19960
SUMMARY

A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-16
UPDATED
Date2026-08-16
RISK INFORMATION (Score: 7.4)
CVSS2
Base Score: 6.5
Complexity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Base Score: 7.4
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS4
Base Score: 2.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.7
EXPLOITABILITY
3.1
CVE-2026-19959
SUMMARY

A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

PUBLISHED
Date2026-08-16
UPDATED
Date2026-08-16
RISK INFORMATION (Score: 9.9)
CVSS2
Base Score: 9.0
Complexity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Base Score: 9.9
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS4
Base Score: 8.6
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
6
EXPLOITABILITY
3.1
CVE-2026-19958
SUMMARY

A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the component execute Tool. The manipulation results in code injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Date2026-08-16
UPDATED
Date2026-08-16
RISK INFORMATION (Score: 6.3)
CVSS2
Base Score: 6.5
Complexity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Base Score: 6.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 2.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
2.8
CVE-2026-19957
SUMMARY

A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

PUBLISHED
Date2026-08-16
UPDATED
Date2026-08-16
RISK INFORMATION (Score: 6.3)
CVSS2
Base Score: 6.5
Complexity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
CVSS3
Base Score: 6.3
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 2.1
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
2.8