Comparison Overview
Sunweb Group

Sunweb Group
Bahialaan 2, Rotterdam, 3065 WC, NL
Last Update: 03/06/2026
Sunweb Group is one of Europe’s largest online travel agencies, bringing unforgettable holiday experiences to eight international markets, including the Netherlands, Belgium, Denmark, Sweden, France, the UK, and Germany. With our well-known brands, Sunweb and ‘Eliza Was...

Carnival Cruise Line
3655 NW 87th Avenue, Miami, Florida, US, 33178
Last Update: 01/06/2026
Since our founding in 1972, Carnival Cruise Line — "The World’s Most Popular Cruise Line®” — carries millions of passengers every year. We offer a fun and unique career destination for a wide range of professionals in Marketing, IT, Accounting/Audit, Finance, Marine Ope...
Compliance Ranges Comparison

Sunweb Group







Carnival Cruise Line






Benchmark & Cyber Underwriting Signals
Incidents vs Travel Arrangements Industry Avg (This Year)
Sunweb Group has 56.14% fewer incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Travel Arrangements Industry Avg (This Year)
Carnival Cruise Line has 94.17% more incidents than the average of all companies with at least one recorded incident.
Incident History - Sunweb Group (X = Date, Y = Severity)
Sunweb Group cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Carnival Cruise Line (X = Date, Y = Severity)
Carnival Cruise Line cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Sunweb Group

Carnival Cruise Line
FAQ
Latest Global CVEs
In OpenStack Glance through 32.0.0, the /v2/tasks API accepts type=import tasks that bypass import_filtering_opts, allowing an admin to fetch internal URLs from the Glance service network (aka SSRF), as long as https:// or http:// is used. This API has been available only to admins since Xena, and it has been deprecated for several releases.
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.