Comparison Overview

GeoVision

VS

RussNeft

GeoVision

5811 Irvington Blvd, Houston, TX 77009, Houston, Texas, US, 77008
Last Update: 2025-12-01

When a well kicks off horizontally, our expertise runs deep. At GeoVision, our experienced geologists have overseen every basin in North America. With so much on the line, you need a partner that goes all-in- a team of geologists who put their heart into it. At GeoVision, we steer the way and our clients come out looking like rock stars.

NAICS: 211
NAICS Definition: Oil and Gas Extraction
Employees: 33
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
1

RussNeft

69, Pyatnitskaya st Moscow, RU
Last Update: 2025-12-01
Between 750 and 799

ОАО Oil and Gas Company «RussNeft» came into existence in September 2002 . The structure of OAO NK “RussNeft” counts 24 upstream enterprises, 2 refineries, its own distribution net of gas filling stations. Geographic reach of “RussNeft” covers 12 regions of Russia and CIS: Khanty-Mansi Autonomous District, Yamalo-Nenets Autonomous District, Tomsk, Ulianovsk, Penza, Briansk, Saratov, Kirov and Orenburg regions, the Republics of Udmurtia and Belarus. The head office of the Company is in Moscow. The Company is developing 167 oil and gas fields. The net effective pay of the company exceeds 600 million tons. The total amount of oil produced by the enterprises of the company is 13 million tons. In accordance with the approved long-term strategy of development “RussNeft is going within a 7-year period to build up the volume of production by more than one third. The total throughput of the refineries is 5.134 million tons. Since 2011 engine fuels of the Company meet ecological class Euro 3 quality standard.

NAICS: 211
NAICS Definition: Oil and Gas Extraction
Employees: 10,001
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/targeted-geovision-llc.jpeg
GeoVision
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/russneft.jpeg
RussNeft
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
GeoVision
100%
Compliance Rate
0/4 Standards Verified
RussNeft
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Oil and Gas Industry Average (This Year)

No incidents recorded for GeoVision in 2025.

Incidents vs Oil and Gas Industry Average (This Year)

No incidents recorded for RussNeft in 2025.

Incident History — GeoVision (X = Date, Y = Severity)

GeoVision cyber incidents detection timeline including parent company and subsidiaries

Incident History — RussNeft (X = Date, Y = Severity)

RussNeft cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/targeted-geovision-llc.jpeg
GeoVision
Incidents

Date Detected: 6/2024
Type:Vulnerability
Attack Vector: Command Injection
Motivation: DDoS, Cryptomining
Blog: Blog
https://images.rankiteo.com/companyimages/russneft.jpeg
RussNeft
Incidents

No Incident

FAQ

RussNeft company demonstrates a stronger AI Cybersecurity Score compared to GeoVision company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

GeoVision company has historically faced a number of disclosed cyber incidents, whereas RussNeft company has not reported any.

In the current year, RussNeft company and GeoVision company have not reported any cyber incidents.

Neither RussNeft company nor GeoVision company has reported experiencing a ransomware attack publicly.

Neither RussNeft company nor GeoVision company has reported experiencing a data breach publicly.

Neither RussNeft company nor GeoVision company has reported experiencing targeted cyberattacks publicly.

GeoVision company has disclosed at least one vulnerability, while RussNeft company has not reported such incidents publicly.

Neither GeoVision nor RussNeft holds any compliance certifications.

Neither company holds any compliance certifications.

Neither GeoVision company nor RussNeft company has publicly disclosed detailed information about the number of their subsidiaries.

RussNeft company employs more people globally than GeoVision company, reflecting its scale as a Oil and Gas.

Neither GeoVision nor RussNeft holds SOC 2 Type 1 certification.

Neither GeoVision nor RussNeft holds SOC 2 Type 2 certification.

Neither GeoVision nor RussNeft holds ISO 27001 certification.

Neither GeoVision nor RussNeft holds PCI DSS certification.

Neither GeoVision nor RussNeft holds HIPAA certification.

Neither GeoVision nor RussNeft holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. Other parameters might be affected as well. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 3.3
Severity: LOW
AV:N/AC:L/Au:M/C:N/I:P/A:N
cvss3
Base: 2.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically, this is root. There is no attempt to sanitize these arguments in the default configuration of this MCP server at the affected version (as of commit 2f3a5512 in September of 2025).

Risk Information
cvss3
Base: 9.1
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description

A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affected by this issue is some unknown functionality of the file /includes/header_menu.php of the component GET Parameter Handler. Executing manipulation of the argument Error can lead to cross site scripting. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:P/A:N
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Qualitor 8.20/8.24. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing manipulation of the argument passageiros results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProjectManager.java of the component Project Import. Such manipulation leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 6.5
Severity: LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
cvss3
Base: 6.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X