Comparison Overview
Gyft, a First Data company

Gyft, a First Data company
150 West Evelyn Street, Mountain View, 94041, US
Last Update: 02/04/2026
Gyft is a digital gift card platform that enables you to manage your gift cards. Users can upload, send and redeem gift cards from their phones. Gyft is seamlessly integrated with Facebook to make sending gift cards convenient and fun! For retailers, Gyft creates a ...

Ivideon. Cloud Video Surveillance
Harvard Ave Ste C, Irvine, US
Last Update: 30/03/2026
Ivideon is a rapidly growing Cloud VSaaS company. Founded in 2010 Ivideon serves all vertical markets worldwide covering 5M users globally. Ivideon clients include major international corporations, governments as well as SMBs and home users. Ivideon technology and prod...
Compliance Ranges Comparison

Gyft, a First Data company







Ivideon. Cloud Video Surveillance






Benchmark & Cyber Underwriting Signals
Incidents vs Technology, Information and Internet Industry Avg (This Year)
No incidents recorded for Gyft, a First Data company in 2026.
Incidents vs Technology, Information and Internet Industry Avg (This Year)
No incidents recorded for Ivideon. Cloud Video Surveillance in 2026.
Incident History - Gyft, a First Data company (X = Date, Y = Severity)
Gyft, a First Data company cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Ivideon. Cloud Video Surveillance (X = Date, Y = Severity)
Ivideon. Cloud Video Surveillance cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Gyft, a First Data company

Ivideon. Cloud Video Surveillance
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.