Comparison Overview
L Brands

L Brands
3 Limited Parkway, Columbus, OH, US, 43230
Last Update: 04/04/2026
On August 2, 2021, L Brands (NYSE: LB) completed the separation of the Victoria’s Secret business into an independent, public company through a tax-free spin-off to L Brands shareholders. The new company, named Victoria’s Secret & Co., includes Victoria’s Secret Lingeri...

Esselunga
Via Giambologna 1, Limito di Pioltello, 20096, IT
Last Update: 04/04/2026
Esselunga è una delle principali catene italiane nel settore della grande distribuzione. La sua storia inizia nel 1957 con l'apertura a Milano del primo supermercato in Italia; oggi, attraverso una rete di oltre 180 negozi, il gruppo è presente in Lombardia, Toscana, Em...
Compliance Ranges Comparison

L Brands







Esselunga






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for L Brands in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Esselunga in 2026.
Incident History - L Brands (X = Date, Y = Severity)
L Brands cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Esselunga (X = Date, Y = Severity)
Esselunga cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

L Brands

Esselunga
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.