Comparison Overview
Molecular Devices China

Molecular Devices China
长宁区福泉北路, 上海, 200335, CN
Last Update: 01/12/2025
Molecular Devices始创于上世纪80年代美国硅谷,作为全球高通量仪器设备的优秀品牌,一直致力于为生命科学研究及药物研发提供先进的解决方案。其产品覆盖微孔板检测分析、高通量筛选、高内涵成像、高效克隆筛选等。公司以持续创新、快速高效、高质量的产品及完善的售后服务著称业内。 Molecular Devices为您提供高性能的分析检测系统,加快和改进药物研发及基础生命科学的研究。我们的产品除了用于科研单位和部门外,还帮助制药和生物技术企业从分子、细胞和系统水平去了解各项生物功能,研究开发新的治疗方法。 Molecular Dev...

Avantor
100 Matsonford Rd, Radnor Township, US
Last Update: 11/09/2026
Avantor® is a leading global provider of mission-critical products and services to customers in the biopharma, healthcare, education & government, and advanced technologies & applied materials industries. Our portfolio is used in virtually every stage of the most impo...
Compliance Ranges Comparison

Molecular Devices China







Avantor






Benchmark & Cyber Underwriting Signals
Incidents vs Biotechnology Research Industry Avg (This Year)
No incidents recorded for Molecular Devices China in 2026.
Incidents vs Biotechnology Research Industry Avg (This Year)
No incidents recorded for Avantor in 2026.
Incident History - Molecular Devices China (X = Date, Y = Severity)
Molecular Devices China cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Avantor (X = Date, Y = Severity)
Avantor cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Molecular Devices China

Avantor
FAQ
Latest Global CVEs
Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenticated attackers to grow process memory without limit. Attackers can repeatedly send notify frames up to 1 MB to the handshake RPC port, filling the uncapped notifys vector until the out-of-memory killer terminates the engine.
- https://github.com/kvcache-ai/Mooncake
- https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata.cpp#L285-L296
- https://github.com/kvcache-ai/Mooncake/issues/4445
- https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-memory-exhaustion-via-unbounded-notify-queue
Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the handshake daemon by never reading replies. Attackers can send a Metadata request to the handshake RPC port and stall SocketHandShakePlugin's single listener thread in writeFully(), breaking all subsequent handshakes, metadata fetches, notify and probe requests.
- https://github.com/kvcache-ai/Mooncake
- https://github.com/kvcache-ai/Mooncake/blob/719735896c86b56fabec6cf3e825fb2ea640597a/mooncake-transfer-engine/src/transfer_metadata_plugin.cpp#L730-L803
- https://github.com/kvcache-ai/Mooncake/issues/4443
- https://www.vulncheck.com/advisories/mooncake-transfer-engine-through-0.3.13-post1-denial-of-service-via-p2p-handshake-daemon-response-write
Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working directory by supplying absolute paths or ../ sequences. Attackers can steer an AI agent via prompt injection to abuse save_presentation, open_presentation, or manage_image output_path to overwrite any server-writable file or load external files.
- https://github.com/GongRzhe/Office-PowerPoint-MCP-Server
- https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/tools/presentation_tools.py#L127-L141
- https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/blob/3631ba2ec0c24504476f78bf74d329c9be11caaa/utils/presentation_utils.py#L61-L73
- https://github.com/GongRzhe/Office-PowerPoint-MCP-Server/pull/33
- https://www.vulncheck.com/advisories/office-powerpoint-mcp-server-through-2.0.7-path-traversal-via-save-presentation-and-manage-image
A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LDAPMessage on the same connection, causing the server to hand that connection to a second worker thread before the first worker's result is flushed. The second worker blocks until nsslapd-ioblocktimeout while holding the connection mutex, preventing delivery of the completed operation's result. Repeating this across a small number of connections proportional to the configured worker-thread pool size exhausts the entire pool under default configuration, denying service to all clients (anonymous and authenticated, plaintext and TLS) for as long as the attacker maintains the connections.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.