Comparison Overview
IRIS HR

IRIS HR
Heathrow Approach, 470 London Road, Slough, Berkshire, GB, SL3 8QY
Last Update: 01/04/2026
IRIS's domestic and global HR software and HR services are used by over four million employees. From recruitment, attainment and engagement to reporting, our human resources software connects thousands of businesses with their employees every day. Our HR management s...

HubSpot
2 Canal Park, Cambridge, Massachusetts, US, 02141
Last Update: 12/09/2026
HubSpot is a leading CRM platform that provides software and support to help businesses grow better. Our platform includes marketing, sales, service, and website management products that start free and scale to meet our customers’ needs at any stage of growth. Today, th...
Compliance Ranges Comparison

IRIS HR







HubSpot






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for IRIS HR in 2026.
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for HubSpot in 2026.
Incident History - IRIS HR (X = Date, Y = Severity)
IRIS HR cyber incidents detection timeline including parent company and subsidiaries.
Incident History - HubSpot (X = Date, Y = Severity)
HubSpot cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

IRIS HR

HubSpot
FAQ
Latest Global CVEs
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.
Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238.
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content.