Comparison Overview
StubHub

StubHub
New York, NY, US, 10007
Last Update: 05/04/2026
At StubHub, our mission is to give everyone the freedom to access and connect through live experiences. As the world's leading live event marketplace, we connect fans, sellers, and partners globally, providing access to an expansive catalog of events across more than 90...

PayPal
2211 North First Street, San Jose, 95131, US
Last Update: 09/09/2026
We're championing possibilities for all by making money fast, easy, and more enjoyable. Our hope is to unlock opportunities for people in their everyday lives and empower the millions of people and businesses around the world who trust, rely, and use PayPal every day. ...
Compliance Ranges Comparison

StubHub







PayPal






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for StubHub in 2026.
Incidents vs Software Development Industry Avg (This Year)
PayPal has 593.07% more incidents than the average of all companies with at least one recorded incident.
Incident History - StubHub (X = Date, Y = Severity)
StubHub cyber incidents detection timeline including parent company and subsidiaries.
Incident History - PayPal (X = Date, Y = Severity)
PayPal cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

StubHub

PayPal
FAQ
Latest Global CVEs
The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.
Denuvo Anti-Tamper through 2026-03-04 allows bypass of a hypervisor presence check via CPUID interception (SimpleSvm.sys on AMD; hyperkd.sys and hyperhv.dll on Intel).
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because "quotation character already used in the string" is mishandled.
Zilliz Attu before 3.0.0 has a Playground feature that does not require authentication for proxying arbitrary HTTP and HTTPS requests to URLs on the public internet.
The Playground feature of Zilliz Attu before 3.0.0 allows SSRF (proxying of requests to private IP addresses).