Comparison Overview
Global Sourcing Office

Global Sourcing Office
Unit 704-706, West Wing | Tsim Sha Tsui Centre | 66 Mody Road , Kowloon, Hong Kong, HK, 999999
Last Update: 15/12/2025
Global Sourcing Office: Meijer Trading Limited (“MTL”) is a limited liability company incorporated in Hong Kong SAR in 2013, which is the first operation that Meijer Inc. and its subsidiaries (“the Group”) has set up outside the US. The retailer has two offices in Hong ...

B&M Retail
Estuary Commerce Park , Liverpool, Merseyside, GB, L24 8RJ
Last Update: 03/04/2026
B&M is a fast-growing discount retailer, operating from over 750 high street and out of town stores across the UK, with a team of over 38,000! In the UK, we offer customers a broad range of FMCG brands and non-grocery products at sensational prices. Our aim is to prov...
Compliance Ranges Comparison

Global Sourcing Office







B&M Retail






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Global Sourcing Office in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for B&M Retail in 2026.
Incident History - Global Sourcing Office (X = Date, Y = Severity)
Global Sourcing Office cyber incidents detection timeline including parent company and subsidiaries.
Incident History - B&M Retail (X = Date, Y = Severity)
B&M Retail cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Global Sourcing Office

B&M Retail
FAQ
Latest Global CVEs
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #132.
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140.
An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, deletion of stored credentials and service disruption.