Comparison Overview
UCR Staff Assembly

UCR Staff Assembly
900 University Ave, Riverside, 92507, US
Last Update: 15/03/2026
UCR Staff Assembly is an association of many employees dedicated to promoting the interests and welfare of all UCR staff. It seeks to inform, involve, connect and recognize staff in one of the fastest-growing campuses in the UC system.

UC San Diego
9500 Gilman Dr, La Jolla, CA, US, 92093
Last Update: 01/04/2026
Recognized as one of the top 15 research universities worldwide, our culture of collaboration sparks discoveries that advance society and drive economic impact. Everything we do is dedicated to ensuring our students have the opportunity to become changemakers, equipped ...
Compliance Ranges Comparison

UCR Staff Assembly







UC San Diego






Benchmark & Cyber Underwriting Signals
Incidents vs Higher Education Industry Avg (This Year)
No incidents recorded for UCR Staff Assembly in 2026.
Incidents vs Higher Education Industry Avg (This Year)
No incidents recorded for UC San Diego in 2026.
Incident History - UCR Staff Assembly (X = Date, Y = Severity)
UCR Staff Assembly cyber incidents detection timeline including parent company and subsidiaries.
Incident History - UC San Diego (X = Date, Y = Severity)
UC San Diego cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

UCR Staff Assembly

UC San Diego
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.