Comparison Overview
Petrol Ofisi

Petrol Ofisi
Libadiye Caddesi 34700, Üsküdar, Istanbul, 34700, TR
Last Update: 19/03/2026
The leader of the fuel and lubricant sectors in Turkey, Petrol Ofisi was founded as the first and national brand of Turkey on February 18, 1941 with a personnel consisting of 9 employees. The World War II marked an era when the problems in the fuel sector peaked, and T...

Anadolu Group
Anadolu Grubu, Fatih Sultan Mehmet Mahallesi, Balkan Caddesi No. 58 Buyaka E Blok Tepeüstü, Ümraniye, ISTANBUL, Türkiye, TR, 34771
Last Update: 01/04/2026
We maintain our activities in 8 industries (retail, soft drinks, beer, agriculture, automotive, stationery, energy and health) and in 20 countries with more than 80 companies, approximately 100 production facilities, 6 R&D centers and 100,000 employees. Our Group, which...
Compliance Ranges Comparison

Petrol Ofisi







Anadolu Group






Benchmark & Cyber Underwriting Signals
Incidents vs Holding Companies Industry Avg (This Year)
No incidents recorded for Petrol Ofisi in 2026.
Incidents vs Holding Companies Industry Avg (This Year)
No incidents recorded for Anadolu Group in 2026.
Incident History - Petrol Ofisi (X = Date, Y = Severity)
Petrol Ofisi cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Anadolu Group (X = Date, Y = Severity)
Anadolu Group cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Petrol Ofisi

Anadolu Group
FAQ
Latest Global CVEs
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #132.
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140.
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.