Comparison Overview
Kroger Specialty Pharmacy

Kroger Specialty Pharmacy
3200 Lake Emma Road, Lake Mary, 32846, US
Last Update: 01/04/2026
Kroger Specialty Pharmacy is now BioPlus Specialty Pharmacy. You’ll get the same great service and medications as you did from Kroger Specialty Pharmacy, but now under the BioPlus name! To learn more about this transition, visit https://bioplusrx.com/kroger-specialty-ph...

Merck
126 E Lincoln Ave, P.O. Box 2000, Rahway, New Jersey, US, 07065
Last Update: 20/09/2026
At Merck, known as MSD outside of the United States and Canada, we are unified around our purpose: We use the power of leading-edge science to save and improve lives around the world. For more than 130 years, we have brought hope to humanity through the development of i...
Compliance Ranges Comparison

Kroger Specialty Pharmacy







Merck






Benchmark & Cyber Underwriting Signals
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
No incidents recorded for Kroger Specialty Pharmacy in 2026.
Incidents vs Pharmaceutical Manufacturing Industry Avg (This Year)
No incidents recorded for Merck in 2026.
Incident History - Kroger Specialty Pharmacy (X = Date, Y = Severity)
Kroger Specialty Pharmacy cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Merck (X = Date, Y = Severity)
Merck cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Kroger Specialty Pharmacy

Merck
FAQ
Latest Global CVEs
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundation MediaWiki - WikiLambda extension allows Stored XSS. This issue affects MediaWiki - WikiLambda extension: before 1.46.1.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Refreshed skin allows Stored XSS. This issue affects Mediawiki - Refreshed skin: before 1.46.1, 1.45.5, 1.43.10.
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.
- https://gist.github.com/mmadersbacher/46050b4224eb979431986cdef1dd2ad3
- https://github.com/alexcorvi/anchorme.js
- https://github.com/alexcorvi/anchorme.js/blob/f3ae9850baa344f27b46bb149e9b891831d273b1/src/index.ts#L109
- https://www.npmjs.com/package/anchorme
- https://www.vulncheck.com/advisories/anchorme-through-3.0.8-regular-expression-denial-of-service