Comparison Overview
Kingfisher plc

Kingfisher plc
1 Paddington Square, London, GB, W2 1GG
Last Update: 02/04/2026
Kingfisher plc is an international home improvement company with over 2,000 stores, and operations in eight countries across Europe. We operate under retail banners including B&Q, Castorama, Brico Dépôt, Screwfix, TradePoint and Koçtaş, supported by a team of over 78,00...

B&M Retail
Estuary Commerce Park , Liverpool, Merseyside, GB, L24 8RJ
Last Update: 03/04/2026
B&M is a fast-growing discount retailer, operating from over 750 high street and out of town stores across the UK, with a team of over 38,000! In the UK, we offer customers a broad range of FMCG brands and non-grocery products at sensational prices. Our aim is to prov...
Compliance Ranges Comparison

Kingfisher plc







B&M Retail






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Kingfisher plc in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for B&M Retail in 2026.
Incident History - Kingfisher plc (X = Date, Y = Severity)
Kingfisher plc cyber incidents detection timeline including parent company and subsidiaries.
Incident History - B&M Retail (X = Date, Y = Severity)
B&M Retail cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Kingfisher plc

B&M Retail
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.