Comparison Overview
AstraZeneca

AstraZeneca
1 Francis Crick Avenue, Cambridge, CB2 0AA, GB
Last Update: 04/08/2026
We're transforming the future of healthcare by unlocking the power of what science can do for people, society and the planet. For more information, visit www.astrazeneca.com. Community Guidelines: bit.ly/2MgAcio

Merck
126 E Lincoln Ave, P.O. Box 2000, Rahway, New Jersey, US, 07065
Last Update: 05/07/2026
At Merck, known as MSD outside of the United States and Canada, we are unified around our purpose: We use the power of leading-edge science to save and improve lives around the world. For more than 130 years, we have brought hope to humanity through the development of i...
Compliance Ranges Comparison

AstraZeneca







Merck






Benchmark & Cyber Underwriting Signals
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
AstraZeneca has 30.72% more incidents than the average of same-industry companies with at least one recorded incident.
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
No incidents recorded for Merck in 2026.
Incident History - AstraZeneca (X = Date, Y = Severity)
AstraZeneca cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Merck (X = Date, Y = Severity)
Merck cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

AstraZeneca

Merck
FAQ
Latest Global CVEs
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts of the component execute Tool. The manipulation results in code injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-test Endpoint. Such manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.