Comparison Overview
Carrefour Property

Carrefour Property
93 avenue de Paris, Massy, undefined, 91300, FR
Last Update: 07/03/2026
Filiale à 100% du groupe Carrefour, Carrefour Property est propriétaire des murs des hypermarchés et supermarchés de l’enseigne Carrefour en France, Espagne et Italie. En effet, Carrefour Property c'est : Près de 4 millions de m² de surface de vente 1 000 site...

Lendlease
Level 14, Tower Three, International Towers Sydney, Exchange Place, 300 Barangaroo Ave, Barangaroo, NSW, AU, 2000
Last Update: 02/04/2026
Lendlease is Australia’s leading real estate business with an international investments platform. We’re city shapers, asset creators and trusted partners. Our deep property experience and bold thinking delivers innovative real estate and investment solutions. Very f...
Compliance Ranges Comparison

Carrefour Property







Lendlease






Benchmark & Cyber Underwriting Signals
Incidents vs Real Estate Industry Avg (This Year)
No incidents recorded for Carrefour Property in 2026.
Incidents vs Real Estate Industry Avg (This Year)
No incidents recorded for Lendlease in 2026.
Incident History - Carrefour Property (X = Date, Y = Severity)
Carrefour Property cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Lendlease (X = Date, Y = Severity)
Lendlease cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Carrefour Property

Lendlease
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).