Comparison Overview
Shawgrass

Shawgrass
185 S Industrial Blvd, Calhoun, Georgia 30701, US
Last Update: 27/04/2026
The name Shaw is a definitive brand in the synthetic turf market and Shawgrass is leading the way with a mix of products for residential/commercial landscape applications, pets, recreation and golf. Shawgrass products are designed and developed by the same research and...

Grainger
100 Grainger Parkway, Lake Forest, 60045, US
Last Update: 03/04/2026
As a leading business-to-business organization, more than 4.5 million customers worldwide rely on Grainger for products in categories such as safety, material handling and metalworking, along with services like inventory management and technical support. For our Team ...
Compliance Ranges Comparison

Shawgrass







Grainger






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Office Equipment Industry Avg (This Year)
No incidents recorded for Shawgrass in 2026.
Incidents vs Retail Office Equipment Industry Avg (This Year)
No incidents recorded for Grainger in 2026.
Incident History - Shawgrass (X = Date, Y = Severity)
Shawgrass cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Grainger (X = Date, Y = Severity)
Grainger cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Shawgrass

Grainger
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.