Comparison Overview
American Girl

American Girl
8400 Fairway Place, Middleton, 53562, US
Last Update: 18/03/2026
The story of American Girl started in 1986 with Pleasant Rowland, a writer and retired teacher from Chicago with a brilliant idea. Pleasant found inspiration to create educational dolls with historic backstories after a visit to Colonial Williamsburg, Virginia. Origin...

Rodan + Fields
60 Spear Street, San Francisco, CA, US, 94105
Last Update: 04/04/2026
We are Rodan + Fields, founded by Stanford-trained dermatologists with a mission to revolutionize skincare for women everywhere. Our products are dermatologist-developed and inspired by Women-Backed Science™, delivering real, visible results. We understand what works f...
Compliance Ranges Comparison

American Girl







Rodan + Fields






Benchmark & Cyber Underwriting Signals
Incidents vs Manufacturing Industry Avg (This Year)
No incidents recorded for American Girl in 2026.
Incidents vs Manufacturing Industry Avg (This Year)
No incidents recorded for Rodan + Fields in 2026.
Incident History - American Girl (X = Date, Y = Severity)
American Girl cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Rodan + Fields (X = Date, Y = Severity)
Rodan + Fields cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

American Girl

Rodan + Fields
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.