
Settlement Matters, LLC
Excellent
None
Excellent
None
Excellent
A GARANTIA DE SER LOPES A Lopes é a maior empresa de soluções integradas de intermediação, consultoria e promoção de financiamentos de imóveis do Brasil. Está presente em 10 estados - São Paulo, Rio de Janeiro, Minas Gerais, Espírito Santo, Rio Grande do Sul, Paraná, Santa Catarina, Bahia, Pernambuco e Ceará - além do Distrito Federal. Líder em intermediação de venda e compra de lançamentos imobiliários, a Lopes atua também nos segmentos de imóveis usados, com a bandeira Pronto! e financiamento imobiliário, com a CrediPronto! Além disso, possui uma empresa especializada em comercialização de imóveis de até 200 mil reais: a HabitCasa. Sua missão é atender com excelência e segurança todos os clientes, pessoas ou empresas, atingindo e superando as expectativas de cada um deles. Dessa forma, a Lopes garante a qualidade do seu serviço e a satisfação de compradores, incorporadores e acionistas, além de atratividade aos corretores de imóveis parceiros ou associados. Símbolo de inovação e vanguardismo no mercado imobiliário, a Lopes trabalha com a filosofia de que nenhuma empresa pode se considerar grande, bem-sucedida ou experiente o bastante quando o assunto é a busca de aprendizado e aprimoramento. Por isso, usa os seus mais de 70 anos de experiência como lastro para a constante superação de novos desafios.
Security & Compliance Standards Overview
No incidents recorded for Settlement Matters, LLC in 2025.
No incidents recorded for Lopes Consultoria de Imóveis in 2025.
Settlement Matters, LLC cyber incidents detection timeline including parent company and subsidiaries
Lopes Consultoria de Imóveis cyber incidents detection timeline including parent company and subsidiaries
Last 3 Security & Risk Events by Company
Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verification. This vulnerability stems from a token validation routine that only decodes JWTs (jwt.decode) without verifying their signatures. Both the email verification token login path and the password reset server action use the same validator, which does not check the token’s signature, expiration, issuer, or audience. If an attacker learns the victim’s actual user.id, they can craft an arbitrary JWT with an alg: "none" header and use it to authenticate and reset the victim’s password. This issue has been patched in version 4.0.1.
Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Prior to Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3, a cross-site request forgery (CSRF) vulnerability was identified. The vulnerability arises from missing origin validation in the client-side code that handles window.postMessage events. A malicious website can send forged messages to the embedding page, causing the victim’s browser to execute arbitrary GraphQL queries or mutations against their GraphQL server while authenticated with the victim’s cookies. This issue has been patched in Apollo Sandbox version 2.7.2 and Apollo Explorer version 3.7.3.
A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public and may be exploited. It is advisable to upgrade the affected component. The vendor responds: "We have confirmed that the issue mentioned in the report does not exist in the latest releases".