Comparison Overview
wienerberger

wienerberger
Wienerbergerplatz 1 Vienna, 1100, AT
Last Update: 22/03/2026
wienerberger is one of the leading providers of innovative, ecological solutions for the entire building envelope, in the fields of new build and renovation, as well as infrastructure in water and energy management. With more than 20,000 employees worldwide, wienerberge...

Renewal by Andersen
9900 Jamaica Avenue S, Cottage Grove, MN, 55016, US
Last Update: 22/03/2026
Renewal by Andersen is the window and door replacement subsidiary of Andersen Corporation, a company that’s revolutionized the window and door business for more than 120 years. Since 1903, Andersen Corporation has been known for its high-quality, innovative, and well-c...
Compliance Ranges Comparison

wienerberger







Renewal by Andersen






Benchmark & Cyber Underwriting Signals
Incidents vs Building Construction Industry Avg (This Year)
No incidents recorded for wienerberger in 2026.
Incidents vs Building Construction Industry Avg (This Year)
No incidents recorded for Renewal by Andersen in 2026.
Incident History - wienerberger (X = Date, Y = Severity)
wienerberger cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Renewal by Andersen (X = Date, Y = Severity)
Renewal by Andersen cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

wienerberger

Renewal by Andersen
FAQ
Latest Global CVEs
Fides is an open-source privacy engineering platform. From version 2.33.0 to before version 2.84.5, there is a DOM-based XSS vulnerability in fides.js via the fides_description override. This issue has been patched in version 2.84.5.
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by supplying an arbitrary caller-controlled contact_id in the POST request body without tenant ownership verification. Attackers can exploit the service-role client that bypasses row-level security to modify victim contact fields including name, email, and company across tenant boundaries using only a known contact UUID.
Namespace attributes are not encoded correctly during HTML serialization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sanitizer but accepted by browsers as valid end tags, allowing subsequent content to escape sanitization. This allows bypassing the cross-site scripting prevention mechanism of typo3/html-sanitizer before version 2.3.2.
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.