Comparison Overview
The Hangar SSF

The Hangar SSF
N/A
Last Update: 21/04/2026

Waffle House, Inc.
5986 Financial Dr NW, Norcross, 30071, US
Last Update: 01/04/2026
Waffle House has been serving Good Food Fast® since 1955. We started in one restaurant serving Avondale Estates, GA, and then grew into a national brand with more than 1,900 restaurants in 25 states providing career paths to 40,000 + employees. The love and devotion o...
Compliance Ranges Comparison

The Hangar SSF







Waffle House, Inc.






Benchmark & Cyber Underwriting Signals
Incidents vs Restaurants Industry Avg (This Year)
No incidents recorded for The Hangar SSF in 2026.
Incidents vs Restaurants Industry Avg (This Year)
No incidents recorded for Waffle House, Inc. in 2026.
Incident History - The Hangar SSF (X = Date, Y = Severity)
The Hangar SSF cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Waffle House, Inc. (X = Date, Y = Severity)
Waffle House, Inc. cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

The Hangar SSF

Waffle House, Inc.
FAQ
Latest Global CVEs
Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugin:shell|execute to run attacker-controlled operating system commands with the privileges of the NoteGen process. In combination with script execution in the webview (for example via chat XSS), this enables full remote code execution on the user's machine.
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled content that reaches the model prompt (for example a malicious skill REFERENCE.md that instructs the model to emit HTML) can cause the model response to include executable markup such as an img onerror handler. When the user views the chat response, that markup runs as JavaScript in the privileged Tauri webview, enabling arbitrary script execution in the application context (cross-site scripting).