Comparison Overview
The TJX Companies, Inc.

The TJX Companies, Inc.
770 Cochituate Road, Framingham, 01701, US
Last Update: 25/09/2026
TJX is the leading off-price apparel and home fashions retailer in the U.S. and worldwide, with four global home offices, seven brands, nearly 4,700 stores in nine countries, and five distinctive branded e-commerce sites. As Associates, we make a difference with our con...

CarMax
12800 Tuckahoe Creek Parkway, Richmond, Virginia, US, 23238
Last Update: 14/09/2026
We're fueled by a common goal: creating an iconic car-buying experience. We make car-buying fair, accessible, and joyful for all. We are committed to making progress in how we positively impact our society, now and in the future. Above all, we care about people. We are ...
Compliance Ranges Comparison

The TJX Companies, Inc.







CarMax






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for The TJX Companies, Inc. in 2026.
Incidents vs Retail Industry Avg (This Year)
CarMax has 1.96% fewer incidents than the average of all companies with at least one recorded incident.
Incident History - The TJX Companies, Inc. (X = Date, Y = Severity)
The TJX Companies, Inc. cyber incidents detection timeline including parent company and subsidiaries.
Incident History - CarMax (X = Date, Y = Severity)
CarMax cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

The TJX Companies, Inc.

CarMax
FAQ
Latest Global CVEs
A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)
Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)