Comparison Overview
Carvana

Carvana
300 E Rio Salado Pkwy, Tempe, 85281, US
Last Update: 24/08/2026
Carvana (NYSE: CVNA) is an industry pioneer for buying and selling used vehicles online. As the fastest growing used automotive retailer in U.S. history, its proven, customer-first ecommerce model has positively impacted millions of people's lives through convenient, ac...

Fanatics
95 Morton St, New York, NY, US, 10014
Last Update: 01/04/2026
Fanatics is a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fan...
Compliance Ranges Comparison

Carvana







Fanatics






Benchmark & Cyber Underwriting Signals
Incidents vs Technology, Information and Internet Industry Avg (This Year)
No incidents recorded for Carvana in 2026.
Incidents vs Technology, Information and Internet Industry Avg (This Year)
No incidents recorded for Fanatics in 2026.
Incident History - Carvana (X = Date, Y = Severity)
Carvana cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Fanatics (X = Date, Y = Severity)
Fanatics cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Carvana

Fanatics
FAQ
Latest Global CVEs
A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml-rpc.cpp of the component ggml-RPC Server. Performing a manipulation of the argument op/op_params results in deserialization. The attack may be initiated remotely. This vulnerability is distinct from CVE-2026-34159 (GHSA-j8rj-fmpv-wcxw, PR #20908), which only added a buffer==nullptr rejection in create_node() and does not validate op or op_params. The reported GitHub issue was closed automatically due to inactivity.
A vulnerability has been found in CTFd up to 3.8.4. The affected element is the function _is_safe_url of the file CTFd/utils/validators/__init__.py. Such manipulation of the argument Next leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9. Upgrading the affected component is recommended.
- https://github.com/CTFd/CTFd/
- https://github.com/CTFd/CTFd/commit/5d8515842fd1ab2c3a9f2dde9ffca907aa334ea9
- https://github.com/CTFd/CTFd/pull/3026
- https://github.com/CTFd/CTFd/releases/tag/3.8.4
- https://mblunt.dev/writeups/ctfd-open-redirect/
- https://vuldb.com/cve/CVE-2026-78145
- https://vuldb.com/submit/882469
- https://vuldb.com/vuln/394533
- https://vuldb.com/vuln/394533/cti
A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used.
A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the argument resident_id results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used.