Comparison Overview
Hayneedle.com

Hayneedle.com
9394 W. Dodge Rd., Omaha, 68114, US
Last Update: 01/03/2026
Hayneedle (a Walmart company) Energetic, positive culture. Empowered, collaborative team. Smart, fast-paced growth. Hard work and company-wide commitment to helping customers create homes they love … this is how hayneedle.com has become one of the leading online retai...

Stop & Shop
1385 Hancock St, Quincy, MA, US
Last Update: 01/04/2026
Stop & Shop has been around for more than 100 years. We started small, as a corner grocery store back in 1914. And we’ve grown…a lot. We have more than 50,000 Associates in 350+ stores throughout Massachusetts, Connecticut, Rhode Island, New York, and New Jersey. Throug...
Compliance Ranges Comparison

Hayneedle.com







Stop & Shop






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Hayneedle.com in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Stop & Shop in 2026.
Incident History - Hayneedle.com (X = Date, Y = Severity)
Hayneedle.com cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Stop & Shop (X = Date, Y = Severity)
Stop & Shop cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Hayneedle.com

Stop & Shop
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.