Comparison Overview
CARB-X

CARB-X
undefined, Boston, MA, undefined, undefined
Last Update: 18/02/2026
CARB-X (Combating Antibiotic Resistant Bacteria Biopharmaceutical Accelerator) is a global non-profit partnership dedicated to accelerating early development antibacterial R&D to address the rising global threat of drug-resistant bacteria. CARB-X is led by Boston Univer...

Thermo Fisher Scientific
168 Third Avenue, Waltham, MA, US
Last Update: 01/04/2026
About Thermo Fisher Scientific Thermo Fisher Scientific Inc. is the world leader in serving science, with annual revenue of approximately $40 billion. Our Mission is to enable our customers to make the world healthier, cleaner and safer. Whether our customers are accele...
Compliance Ranges Comparison

CARB-X







Thermo Fisher Scientific






Benchmark & Cyber Underwriting Signals
Incidents vs Biotechnology Research Industry Avg (This Year)
No incidents recorded for CARB-X in 2026.
Incidents vs Biotechnology Research Industry Avg (This Year)
No incidents recorded for Thermo Fisher Scientific in 2026.
Incident History - CARB-X (X = Date, Y = Severity)
CARB-X cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Thermo Fisher Scientific (X = Date, Y = Severity)
Thermo Fisher Scientific cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

CARB-X

Thermo Fisher Scientific
FAQ
Latest Global CVEs
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information disclosure.
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing differential can be exploited to smuggle HTTP requests.
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or disclose sensitive heap memory.
Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
Weintek cMT3092X HMI stores user account passwords in plaintext.