Comparison Overview

Eliivate

VS

the LEGO Group

Eliivate

680 Lynn Street, Danville, Virginia, 24541, US
Last Update: 2025-03-08 (UTC)
Between 900 and 1000

Excellent

Introducing the all new lifestyle brand โ€” Eliivate. // Our goal is to create products that push you to new limits. The time is now. All products are hand-made & packaged in Virginia.

NAICS: 339
NAICS Definition:
Employees: 1
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

the LEGO Group

Aastvej 1, Billund, undefined, 7190, DK
Last Update: 2025-05-06 (UTC)

We are the LEGO Group, the company behind the worldโ€™s most loved LEGOยฎ bricks. Our brand name derived from the two Danish words Leg Godt, which mean โ€œPlay Wellโ€. Weโ€™ve been sparking imaginations and inspiring the builders of tomorrow since 1932. This is our mission and what motivates our colleagues around the world every day. Today, we remain proudly family-owned with headquarters in Billund, Denmark. We have regional hubs in Boston, USA; London, UK; Shanghai, China; and Singapore, as well as 7 manufacturing facilities around the world. These places are home to 28,000+ colleagues in everything from design and engineering to digital technology and marketing. Together we learn, imagine and build โ€“ creating play experiences that are sold in over 130 countries worldwide. A purposeful and responsible global brand where creativity helps to inspire builders all around the world. Just imagine being part of that!

NAICS: 30
NAICS Definition: Manufacturing
Employees: 19,364
Subsidiaries: 1
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/eliivate.jpeg
Eliivate
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
https://images.rankiteo.com/companyimages/lego-group.jpeg
the LEGO Group
โ€”
ISO 27001
Not verified
โ€”
SOC 2
Not verified
โ€”
GDPR
No public badge
โ€”
PCI DSS
No public badge
Compliance Summary
Eliivate
100%
Compliance Rate
0/4 Standards Verified
the LEGO Group
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Manufacturing Industry Average (This Year)

No incidents recorded for Eliivate in 2025.

Incidents vs Manufacturing Industry Average (This Year)

No incidents recorded for the LEGO Group in 2025.

Incident History โ€” Eliivate (X = Date, Y = Severity)

Eliivate cyber incidents detection timeline including parent company and subsidiaries

Incident History โ€” the LEGO Group (X = Date, Y = Severity)

the LEGO Group cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/eliivate.jpeg
Eliivate
Incidents

No Incident

https://images.rankiteo.com/companyimages/lego-group.jpeg
the LEGO Group
Incidents

No Incident

FAQ

Eliivate company company demonstrates a stronger AI risk posture compared to the LEGO Group company company, reflecting its advanced AI governance and monitoring frameworks.

Historically, the LEGO Group company has disclosed a higher number of cyber incidents compared to Eliivate company.

In the current year, the LEGO Group company and Eliivate company have not reported any cyber incidents.

Neither the LEGO Group company nor Eliivate company has reported experiencing a ransomware attack publicly.

Neither the LEGO Group company nor Eliivate company has reported experiencing a data breach publicly.

Neither the LEGO Group company nor Eliivate company has reported experiencing targeted cyberattacks publicly.

Neither Eliivate company nor the LEGO Group company has reported experiencing or disclosing vulnerabilities publicly.

the LEGO Group company has more subsidiaries worldwide compared to Eliivate company.

the LEGO Group company employs more people globally than Eliivate company, reflecting its scale as a Manufacturing.

Latest Global CVEs (Not Company-Specific)

Description

PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use`--extra-index-url`. But when `--extra-index-url` is used, pip always checks for the PyPI index first, and then the external index. One package listed in the code is not published in PyPI. If an attacker publishes a package with higher version in PyPI, the malicious code from the attacker controlled package may be pulled, leading to remote code execution and a supply chain attack. As of time of publication, a patched version is unavailable.

Risk Information
cvss4
Base: 9.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

KUNO CMS is a fully deployable full-stack blog application. In versions prior to 1.3.15, an SSRF (Server-Side Request Forgery) vulnerability exists in the Media module of the Kuno CMS administrative panel. A logged-in administrator can upload a specially crafted SVG file containing an external image reference, causing the server to initiate an outgoing connection to an arbitrary external URL. This can lead to information disclosure or internal network probing. Version 1.3.15 contains a fix for the issue.

Risk Information
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:L/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The Profile widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions uses a userโ€™s name in the โ€œContent-Dispositionโ€ header, which allows remote authenticated users to change the file extension when a vCard file is downloaded.

Risk Information
cvss4
Base: 4.8
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

The YoSmart YoLink API through 2025-10-02 uses an endpoint URL that is derived from a device's MAC address along with an MD5 hash of non-secret information, such as a key that begins with cf50.

Risk Information
cvss3
Base: 5.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
Description

The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.

Risk Information
cvss3
Base: 3.5
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N