Comparison Overview
Cheef Holdings

Cheef Holdings
7250 Bandini Blvd, None, Commerce, California, US, 90040
Last Update: 01/04/2026
Cheef Holdings is the parent corporation to the #1 pet and people CBD products. Our pet brand Holistapet can be found at www.holistapet.com and Pet Hemp Company can be found at www.pethempco.com. Our people CBD brand Cheef Botanicals can be found at www.cheefbotanical...

Mercado Libre
Buenos Aires, Buenos Aires, C1430DNN, AR
Last Update: 26/07/2026
At Mercado Libre, we are transforming the way people buy, sell, advertise, pay, finance, and ship across Latin America. We are the leading e-commerce and fintech company in the region, with a presence in 18 countries and a team of more than 130,000 people. We are one o...
Compliance Ranges Comparison

Cheef Holdings







Mercado Libre






Benchmark & Cyber Underwriting Signals
Incidents vs Internet Publishing Industry Avg (This Year)
No incidents recorded for Cheef Holdings in 2026.
Incidents vs Internet Publishing Industry Avg (This Year)
Mercado Libre has 3.85% fewer incidents than the average of all companies with at least one recorded incident.
Incident History - Cheef Holdings (X = Date, Y = Severity)
Cheef Holdings cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Mercado Libre (X = Date, Y = Severity)
Mercado Libre cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Cheef Holdings

Mercado Libre
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).