Comparison Overview
WHSmith

WHSmith
Aldgate Tower, London, E1 8FA, GB
Last Update: 07/06/2026
WHSmith is a leading, global travel retailer. Since 1792, we’ve grown and evolved into a globally recognised brand, and we’re proud to be that air of familiarity people love and trust on their journey, both in life and through life. Today, we have more than 1200 stores...

PUMA Group
PUMA Way 1, Herzogenaurach, DE, 91074
Last Update: 09/09/2026
PUMA is one of the world’s leading sports brands, designing, developing, selling and marketing footwear, apparel and accessories. For more than 75 years, PUMA has relentlessly pushed sport and culture forward by creating fast products for the world’s fastest athletes. P...
Compliance Ranges Comparison

WHSmith







PUMA Group






Benchmark & Cyber Underwriting Signals
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for WHSmith in 2026.
Incidents vs Retail Industry Avg (This Year)
No incidents recorded for PUMA Group in 2026.
Incident History - WHSmith (X = Date, Y = Severity)
WHSmith cyber incidents detection timeline including parent company and subsidiaries.
Incident History - PUMA Group (X = Date, Y = Severity)
PUMA Group cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

WHSmith

PUMA Group
FAQ
Latest Global CVEs
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.
Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This issue affects Escargot: ac94df78493ee6fede286620d94f724e46b4d238.
Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persistent script payloads through these pages to have malicious code executed in the context of other users viewing the affected content.