Comparison Overview
XONAR

XONAR
Randwycksingel 35, Maastricht, 6229 EG, NL
Last Update: 02/04/2026
XONAR biedt hulp bij opgroei- en opvoedingsproblemen aan jeugdigen in de leeftijd van 0 tot 18 jaar en hun gezinnen (Jeugd & Opvoedhulp). Tevens is er een gevarieerd hulpaanbod voor vrouwen (met of zonder kinderen) die in moeilijkheden verkeren en/of slachtoffer zijn va...

Transport for London
5 Endeavour Square, Westfield Avenue,, London , E20 1JN, GB
Last Update: 04/04/2026
Every day, we help millions of people to make journeys across London: By Tube, bus, tram, car, bike – and more. People don’t associate us with journeys by river, on foot or via the air, but we help with that, too. Getting people to where they need to go has been our bus...
Compliance Ranges Comparison

XONAR







Transport for London






Benchmark & Cyber Underwriting Signals
Incidents vs Non-profit Organizations Industry Avg (This Year)
No incidents recorded for XONAR in 2026.
Incidents vs Non-profit Organizations Industry Avg (This Year)
No incidents recorded for Transport for London in 2026.
Incident History - XONAR (X = Date, Y = Severity)
XONAR cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Transport for London (X = Date, Y = Severity)
Transport for London cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

XONAR

Transport for London
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.