Comparison Overview
Marcus & Millichap

Marcus & Millichap
23975 Park Sorrento, Calabasas, 91302, US
Last Update: 04/05/2026
Marcus & Millichap was founded in 1971 with the goal of being a new kind of company – one driven by long-term relationships and built on a culture of collaboration. We focus on bringing together specialized market knowledge, the industry's leading brokerage platform and...

Compass
110 Fifth Avenue, New York, 10011, US
Last Update: 14/09/2026
Compass is a real estate technology company with a powerful end-to-end platform that supports the entire buying and selling workflow. We deliver an incomparable experience to both agents and their clients all in service of the Compass mission: to help everyone find thei...
Compliance Ranges Comparison

Marcus & Millichap







Compass






Benchmark & Cyber Underwriting Signals
Incidents vs Real Estate Industry Avg (This Year)
Marcus & Millichap has 40.83% fewer incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Real Estate Industry Avg (This Year)
No incidents recorded for Compass in 2026.
Incident History - Marcus & Millichap (X = Date, Y = Severity)
Marcus & Millichap cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Compass (X = Date, Y = Severity)
Compass cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Marcus & Millichap

Compass
FAQ
Latest Global CVEs
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10.
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.
- https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3
- https://github.com/alexcorvi/anchorme.js
- https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109
- https://www.npmjs.com/package/anchorme
- https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service