Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download

Comparison Overview

SGVSH - Sparkassen- und Giroverband für Schleswig-HolsteinSGVSH - Sparkassen- und Giroverband für Schleswig-Holstein
VS
WestpacWestpac
SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein

SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein

Faluner Weg 6, Kiel, 24109, DE

Last Update: 03/04/2026

View Profile
Between 750 and 799
www.sgvsh.de
752/1000Fair

Der Sparkassen- und Giroverband für Schleswig-Holstein vertritt die Positionen und Interessen der elf schleswig-holsteinischen Sparkassen. Er berät die Sparkassen in rechtlichen, vertrieblichen und strategischen Themen und koordiniert die Aktivitäten im Verbund der Spar...

NAICS:52211
NAICS Definition:Commercial Banking
Employees:28
Subsidiaries:63
12-month incidents
0
Known data breaches
0
Attack type number
0
Westpac

Westpac

Head Office: 200 Barangaroo Avenue, Sydney, 2000, AU

Last Update: 29/03/2026

View Profile
Between 750 and 799
http://www.westpac.com.au
769/1000Fair

To turn doing into done, it takes a little Westpac. From rescue helicopters and signing the Equator Principles, to paying super during parental leave and initiatives like Westpac SaferPay and SafeCall that help protect customers from scams... we have a proud history of...

NAICS:52211
NAICS Definition:Commercial Banking
Employees:15,882
Subsidiaries:15
12-month incidents
0
Known data breaches
0
Attack type number
1

Compliance Ranges Comparison

Based On Specific Ai Models Category
SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein

SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA
Westpac

Westpac

-
ISO 27001Not verified
ISO 27001
-
SOC2 Type 1Not verified
SOC2 Type 1
-
SOC2 Type 2Not verified
SOC2 Type 2
-
GDPRNot verified
GDPR
-
PCI DSSNot verified
PCI DSS
-
HIPAANot verified
HIPAA

Benchmark & Cyber Underwriting Signals

Incidents vs Banking Industry Avg (This Year)

No incidents recorded for SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein in 2026.

Incidents

Incidents vs Banking Industry Avg (This Year)

No incidents recorded for Westpac in 2026.

Incidents

Incident History - SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein (X = Date, Y = Severity)

SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein cyber incidents detection timeline including parent company and subsidiaries.

No timeline data available
R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Incident History - Westpac (X = Date, Y = Severity)

Westpac cyber incidents detection timeline including parent company and subsidiaries.

R - Ransomware
C - Cyber Attack
D - Data Breach
V - Vulnerability

Notable Incidents

Last Cyber / HR Incidents / Global...
SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein

SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein

Incidents
No explicit notable incidents reported.
Westpac

Westpac

Incidents
🔒 Incident : Data Leak
WES224026323

FAQ

Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has the best AI Cybersecurity Score ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has experienced more cyber incidents in the past ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has experienced more cyber incidents this year ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has experienced at least one ransomware attack ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has experienced at least one data breach ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has experienced at least one targeted cyberattack ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has experienced at least one vulnerability ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one holds the most compliance certifications ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one holds the fewest compliance certifications ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has the most subsidiaries ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein company and Westpac company, which one has the largest number of employees ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein and Westpac, which company holds both SOC 2 Type 1 certifications ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein and Westpac, which company holds both SOC 2 Type 2 certifications ?
Which company is ISO 27001 certified - SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein or Westpac ?
Which company is PCI DSS compliant - SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein or Westpac ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein and Westpac, which company complies with HIPAA regulations for healthcare data ?
Between SGVSH - Sparkassen- und Giroverband für Schleswig-Holstein and Westpac, which company complies with GDPR requirements ?

Latest Global CVEs

CVE-2026-12175
SUMMARY

A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of the argument admissionNumber results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

PUBLISHED
Date2026-06-13
UPDATED
Date2026-06-13
RISK INFORMATION (Score: 4.7)
CVSS2
Base Score: 5.8
Complexity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
CVSS3
Base Score: 4.7
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS4
Base Score: 2.0
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
3.4
EXPLOITABILITY
1.2
CVE-2026-12174
SUMMARY

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation of the argument data leads to format string. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

PUBLISHED
Date2026-06-13
UPDATED
Date2026-06-13
RISK INFORMATION (Score: 8.8)
CVSS2
Base Score: 9.0
Complexity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Base Score: 8.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS4
Base Score: 7.4
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
2.8
CVE-2026-12183
SUMMARY

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax-login.php endpoint returns userid=1 (administrator) in response to any HTTP POST request that supplies arbitrary credentials (e.g., action=dologin&login=<any_value>&pwd=<any_value>), and subsequent privileged endpoints under /php/ajax-main.php and /modules/* do not validate a server-side session. A remote unauthenticated attacker can invoke any administrative action exposed by the configuration module, including reading and modifying user rules, fuel tank gauges, fuel dispensers, relays, cash registers, bank terminals, fuel cards, price and customer displays, cash collection, and pricing rules.

PUBLISHED
Date2026-06-13
UPDATED
Date2026-06-13
RISK INFORMATION (Score: 9.8)
CVSS3
Base Score: 9.8
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS4
Base Score: 9.3
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
IMPACT SCORE
5.9
EXPLOITABILITY
3.9
CVE-2026-6428
SUMMARY

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/. The vulnerable sink in sub calculate concatenates the unmodified Filter request parameter directly into a LIKE clause of the auxiliary $strsth2 statement and executes it via DBI without bound parameters: my $f = @$filters[0]; $f =~ s/\*/%/g; $strsth2 .= " AND $column LIKE '$f' "; This enables error-based SQL injection (e.g., via EXTRACTVALUE) and full read access to sensitive tables including borrowers (password hashes, 2FA secrets, PII), borrower_password_recovery, api_keys, and sessions. Proof of concept (error-based, single request): GET /cgi-bin/koha/reports/catalogue_out.pl?do_it=1&output=screen&Limit=10&Criteria=branchcode&Filter=x'+AND+EXTRACTVALUE(1,CONCAT(0x7e,VERSION(),0x7c,USER(),0x7c,DATABASE(),0x7e))--+- Cookie: CGISESSID=<LIBRARIAN_SESSION> The response body contains the DBI exception leaking the MariaDB version, database user, client IP, and database name, after which arbitrary data can be paged out using LIMIT n,1 / SUBSTRING(...). The vulnerable sink was introduced in commit 6bb77ae3e4 (2008-07-09); CVE-2015-4633 patched the same class in sibling files but did not generalise the fix to reports/catalogue_out.pl. Fixed in Koha 22.11.38, 24.11.16, 25.05.11, 25.11.05, 26.05.01, and 26.11.00 by replacing the raw concatenation with a parameterised placeholder.

PUBLISHED
Date2026-06-13
UPDATED
Date2026-06-13
RISK INFORMATION (Score: 7.6)
CVSS2
Base Score: 7.5
Complexity: LOW
AV:N/AC:L/Au:S/C:C/I:N/A:P
CVSS3
Base Score: 7.6
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CVSS4
Base Score: 5.6
Complexity: LOW
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:C/RE:X/U:Amber
IMPACT SCORE
4.7
EXPLOITABILITY
2.8
CVE-2026-5513
SUMMARY

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and including, 27.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires 'Remember personal information in cookies' setting to be enabled (disabled by default).

PUBLISHED
Date2026-06-13
UPDATED
Date2026-06-13
RISK INFORMATION (Score: 7.2)
CVSS3
Base Score: 7.2
Complexity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
IMPACT SCORE
2.7
EXPLOITABILITY
3.9