Comparison Overview
Orion Engineering

Orion Engineering
Hurksestraat 43, Eindhoven, North Brabant, 5652 AH, NL
Last Update: 24/04/2026
Wie zijn we? Orion Engineering geeft vorm aan carrières in de techniek. Of het nu gaat om het vinden van een opdracht of het vinden van de juiste kandidaat voor de vacature. Orion Engineering weet met haar betrokkenheid én een personal touch de juiste invulling te biede...

Michael Page
PageGroup, Addlestone, Weybridge, GB, KT15 2QW
Last Update: 02/04/2026
Welcome to the Michael Page global company profile. Michael Page has five decades of expertise in professional services recruitment. We were established in London in 1976, and over this period we've grown organically to become one of the best-known and most respected c...
Compliance Ranges Comparison

Orion Engineering







Michael Page






Benchmark & Cyber Underwriting Signals
Incidents vs Staffing and Recruiting Industry Avg (This Year)
No incidents recorded for Orion Engineering in 2026.
Incidents vs Staffing and Recruiting Industry Avg (This Year)
No incidents recorded for Michael Page in 2026.
Incident History - Orion Engineering (X = Date, Y = Severity)
Orion Engineering cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Michael Page (X = Date, Y = Severity)
Michael Page cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Orion Engineering

Michael Page
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).