Comparison Overview
Lilly Brasil

Lilly Brasil
Av. Morumbi, 8264, São Paulo, BR
Last Update: 02/02/2026
A Lilly é líder mundial em saúde e há mais de um século une cuidado com descoberta para melhorar a vida de pessoas ao redor do mundo. A excelência, a integridade e o respeito pelas pessoas são valores inegociáveis e nos guiam em tudo o que fazemos. Nosso time de profi...

Ipca Laboratories Limited
125 Kandivli Industrial Estate, Kandivli (West), Mumbai, Maharashtra, IN, 400067
Last Update: 02/04/2026
A consumer-led global pharmaceutical company, creating healthy doses of life since 1949. When you operate in an industry like pharmaceuticals, your work goes way beyond creating ‘products for customers’. It is different from any other domain – there lies a higher sense...
Compliance Ranges Comparison

Lilly Brasil







Ipca Laboratories Limited






Benchmark & Cyber Underwriting Signals
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
No incidents recorded for Lilly Brasil in 2026.
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
No incidents recorded for Ipca Laboratories Limited in 2026.
Incident History - Lilly Brasil (X = Date, Y = Severity)
Lilly Brasil cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Ipca Laboratories Limited (X = Date, Y = Severity)
Ipca Laboratories Limited cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Lilly Brasil

Ipca Laboratories Limited
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).