Comparison Overview
TJX Information Technology Network

TJX Information Technology Network
N/A
Last Update: 31/03/2026
Welcome to TJX Information Technology. We are the technology arm of TJX – a leading Global off-price apparel and home fashions retailer, a Fortune 100 company with offices, stores, and distribution centers around the world. We strive to offer our Associates new discov...

Alibaba.com
699 Wang Shang Road, Hangzhou, 310052, CN
Last Update: 27/09/2026
The first business of Alibaba Group, Alibaba.com (www.alibaba.com) is the leading platform for global wholesale trade serving millions of buyers and suppliers around the world. Through Alibaba.com, small businesses can sell their products to companies in other countries...
Compliance Ranges Comparison

TJX Information Technology Network







Alibaba.com






Benchmark & Cyber Underwriting Signals
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for TJX Information Technology Network in 2026.
Incidents vs Software Development Industry Avg (This Year)
No incidents recorded for Alibaba.com in 2026.
Incident History - TJX Information Technology Network (X = Date, Y = Severity)
TJX Information Technology Network cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Alibaba.com (X = Date, Y = Severity)
Alibaba.com cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

TJX Information Technology Network

Alibaba.com
FAQ
Latest Global CVEs
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
- https://github.com/NginxProxyManager/nginx-proxy-manager
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/README.md#L36
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/user.js#L52-L62
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/templates/proxy_host.conf#L28
- https://github.com/NginxProxyManager/nginx-proxy-manager/issues/5749
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908
- https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-improper-authorization-via-advanced-config
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
- https://github.com/NginxProxyManager/nginx-proxy-manager
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/app.js#L15-L58
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/2fa.js#L196-L240
- https://github.com/NginxProxyManager/nginx-proxy-manager/blob/v2.16.0/backend/internal/token.js#L154-L182
- https://github.com/NginxProxyManager/nginx-proxy-manager/pull/5908
- https://www.vulncheck.com/advisories/nginx-proxy-manager-through-2.16.0-missing-brute-force-protection
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
- https://github.com/cle-b/httpdbg
- https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97
- https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302
- https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3
- https://github.com/cle-b/httpdbg/issues/220
- https://github.com/cle-b/httpdbg/pull/222
- https://github.com/cle-b/httpdbg/releases/tag/v2.2.1
- https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url
Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use path traversal sequences to write files outside the extraction directory when users download and extract logs.
- https://github.com/amir20/dozzle
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/container/docker/client.go#L610-L614
- https://github.com/amir20/dozzle/blob/v11.1.1/internal/web/download.go#L141-L146
- https://github.com/amir20/dozzle/commit/bc07db73dd84ce2cb939b744e983a8cfdf29c644
- https://github.com/amir20/dozzle/pull/5242
- https://github.com/amir20/dozzle/releases/tag/v11.1.2
- https://www.vulncheck.com/advisories/dozzle-before-11.1.2-path-traversal-via-log-zip-download
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.