Comparison Overview
SEB Varahaldus

SEB Varahaldus
Tornimäe 2, Maakri, Harju maakond, 10117, EE
Last Update: 10/12/2025
SEB Varahalduse tooted ja teenused on suunatud eraisikutele. Peamiseks tegevusvaldkonnaks on pensionifondide valitsemine.

Capital Group
333 South Hope Street, Los Angeles, CA, US, 90071
Last Update: 01/04/2026
Capital Group was established in 1931 in Los Angeles, California, and now has 31 offices around the globe. For over 90 years we've provided carefully researched investment solutions and services to financial professionals. *** We've been made aware of an employment sca...
Compliance Ranges Comparison

SEB Varahaldus







Capital Group






Benchmark & Cyber Underwriting Signals
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for SEB Varahaldus in 2026.
Incidents vs Financial Services Industry Avg (This Year)
No incidents recorded for Capital Group in 2026.
Incident History - SEB Varahaldus (X = Date, Y = Severity)
SEB Varahaldus cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Capital Group (X = Date, Y = Severity)
Capital Group cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

SEB Varahaldus

Capital Group
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).