
Plumbase
Strong
Plumbase is a national Plumber's merchant supplying heating, plumbing, bathrooms, renewables and boiler spares to professional trade installers.
Strong
Plumbase is a national Plumber's merchant supplying heating, plumbing, bathrooms, renewables and boiler spares to professional trade installers.
Excellent
Headquartered in Rotterdam, The Netherlands. Hunter Douglas Group was founded in 1919 in Dโยบsseldorf, Germany. The Group mainly engages in the manufacturing, marketing, and service of architectural products and window covering products, as well as the metal fabrication, precision machinery production, futures exchange of metal and more. Hunter Douglas Group is comprised of 136 companies and 47 manufacturing bases with activity in more than 100 countries for five operational regions throughout the world, including Europe, North America, Latin America, Asia and Australia. Over 100 years, Hunter Douglas, as a market leader in the industry, has been fortunate enough to help turn countless innovative sketches into innovative buildings. Architects, designers, investors and contractors from around the world have taken advantage of Hunter Douglas' unmatched product development, service and support. We've contributed to thousands of high-profile projects. Not only are the world's architects and designers our partners, they're our inspiration. As they continue to raise the bar for excellence, we're creating products to bring their visions to life. The strong brands of Hunter Douglas Luxalon Architectural Products that include Metal Ceilings, Facades and Sun Control have been strengthen further with NBK Terracotta Faโรade and HeartFelt Ceiling and Wall, will continue providing the Architects and Designers with extensive range of building finishes for their projects, be it new or refurbishments projects.
Security & Compliance Standards Overview
No incidents recorded for Plumbase in 2025.
No incidents recorded for Hunter Douglas Asia in 2025.
Plumbase cyber incidents detection timeline including parent company and subsidiaries
Hunter Douglas Asia cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the tokenโs signature, expiration, issuer, or audience. If an attacker learns the victimโs actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victimโs password. This issue has been patched in version 4.0.1.
Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victimโs browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victimโs cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".