Comparison Overview
Screwfix

Screwfix
Trade House, Mead Avenue, Yeovil, Somerset, GB, BA22 8RT
Last Update: 08/03/2026
There’s no stopping us at Screwfix! We’re a team of 14,000+ colleagues and one of the fastest-growing retailers in the UK, Ireland, and France, with over 970 stores and counting. As a true leader in E-Commerce, we’re proud to be part of the Kingfisher PLC Group, an i...

Macy's
151 W 34th St, New York, 10001, US
Last Update: 04/04/2026
Macy's is America’s store for life. The largest retail brand of Macy's, Inc. (NYSE:M) delivers quality fashion at affordable prices to customers at approximately 640 locations in 43 states, the District of Columbia, Puerto Rico, and Guam, as well as to customers in more...
Compliance Ranges Comparison

Screwfix







Macy's






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Screwfix in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for Macy's in 2026.
Incident History - Screwfix (X = Date, Y = Severity)
Screwfix cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Macy's (X = Date, Y = Severity)
Macy's cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Screwfix

Macy's
FAQ
Latest Global CVEs
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view private channel thread root post content and metadata via the team threads API.. Mattermost Advisory ID: MMSA-2026-00682
Mattermost Desktop App versions <=6.2 6.2.2.0 fail to redact the pre-auth secret when generating a diagnostics report, which allows a local attacker with access to a user's diagnostics report or log files to obtain the plaintext pre-auth secret configured for a connected server via inspecting the Server Connectivity (Step-3) diagnostics output. Mattermost Advisory ID: MMSA-2026-00716
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components