Comparison Overview
WinSCP

WinSCP
WinSCP, Praha, 12000, CZ
Last Update: 10/03/2026
Since 2000, we are developing WinSCP, a popular free file manager for Microsoft Windows, which has been downloaded more than 200 million times! WinSCP is a powerful multi-functional tool that will improve your productivity. WinSCP can copy files between a local and rem...

Epic
1979 Milky Way, Verona, WI, US, 53593
Last Update: 02/04/2026
Join us in our mission to help the world get well, help the world stay well, and help future generations be healthier. We hire smart and motivated people from all academic majors to code, test, and implement healthcare software that hundreds of millions of patients and...
Compliance Ranges Comparison

WinSCP







Epic






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for WinSCP in 2026.
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Epic in 2026.
Incident History - WinSCP (X = Date, Y = Severity)
WinSCP cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Epic (X = Date, Y = Severity)
Epic cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

WinSCP

Epic
FAQ
Latest Global CVEs
MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply crafted alog files with backslash sequences in variable names to escape the output directory and append to arbitrary files on Windows systems.
- https://github.com/moos-ivp/moos-ivp
- https://github.com/moos-ivp/moos-ivp/blob/1de9ae146cd63c209e8c3fd81611a4ed2472971b/ivp/src/lib_logutils/SplitHandler.cpp#L189
- https://github.com/moos-ivp/moos-ivp/commit/6f0619e905b325d6b88f76425673045c6e4f6f94
- https://github.com/moos-ivp/moos-ivp/pull/137
- https://www.vulncheck.com/advisories/moos-ivp-through-24.8.1-alog-splitting-path-traversal-on-windows
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted short packet to read memory before authentication.
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/Comms/MOOSCommPkt.cpp#L228
- https://github.com/themoos/core-moos/commit/d30c14585753f9ae39749d9628ed15c8383f0568
- https://github.com/themoos/core-moos/pull/75
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-out-of-bounds-read-via-short-packet
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line can send a full-length telegram to trigger the off-by-one write, corrupting the stack and potentially enabling code execution.
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/Utils/MOOSSerialPort.cpp#L595
- https://github.com/themoos/core-moos/commit/befb04df2039d0080715ea35f56268092db4ec0f
- https://github.com/themoos/core-moos/pull/73
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-off-by-one-buffer-overflow-in-serial-telegram-handling
MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that execute in the browser of operators viewing the web interface.
- https://github.com/themoos/core-moos
- https://github.com/themoos/core-moos/blob/ec9c77c68fcbdef8f5e4c60fe243acd223433f0c/Core/libMOOS/DB/HTTPConnection.cpp#L460
- https://github.com/themoos/core-moos/commit/a3f26f099bb08decb143f704d8b1ca16ae405b44
- https://github.com/themoos/core-moos/pull/78
- https://www.vulncheck.com/advisories/moos-core-moos-through-10.4.0-moosdb-http-pages-stored-cross-site-scripting
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
- https://github.com/themoos/ui-moos
- https://github.com/themoos/ui-moos/blob/50b9c6c65169c501f746cfef1e167f74a7735e74/Tools/Graphical/uMS/ScopeTabPane.cpp#L243
- https://github.com/themoos/ui-moos/commit/a6ebc0bc6cb360315ce620e865f996d189cddb0e
- https://github.com/themoos/ui-moos/pull/5
- https://www.vulncheck.com/advisories/moos-ui-moos-through-50b9c6c-ums-buffer-overflow-via-long-moos-identifiers