Home Embedded Vulns General Vulns

ESV-Tracker

An AI-powered database that classifies embedded vulnerabilities separately from general-purpose ones.

No Dedicated Database Existed. Until Now.

Embedded system vulnerabilities are critical, yet buried alongside millions of general CVEs. ESV-Tracker changes that.

Your Embedded Threat Center.

Search the database, track embedded CVEs, and explore real-time statistics — all in one place.

2588
New Embedded Vulns (7 Days)
9832
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score

Vulnerability Trends (Last 6 Months)

ESV Severity Distribution (90 Days)

Top Affected ESV Vendors (90 Days)

  • google 129 Vulns
  • dell 48 Vulns
  • microsoft 27 Vulns
  • apple 10 Vulns
  • snipeitapp 2 Vulns

Recent Critical ESVs

CVE-2026-102361 CRITICAL 9.1
CVE-2026-101264 CRITICAL 9.1
CVE-2026-101263 CRITICAL 9.1
CVE-2026-101262 CRITICAL 9.1
CVE-2026-101261 CRITICAL 9.1

Recently Added Vulnerabilities

CVE ID Description Severity Published Type
CVE-2026-18747 The MCUmgr SMP-over-console transport decodes a base64 frame, reads a 16-bit packet length from it, verifies a CRC and … Medium (6.8) 2026-09-29 Environment Specific
CVE-2026-18746 parse_write_op() in subsys/net/lib/lwm2m/lwm2m_message_handling.c handles inbound CoAP WRITE/CREATE requests that carry… Medium (5.9) 2026-09-29 Environment Specific
CVE-2026-18417 The native BSD-socket layer recorded a pending asynchronous socket error by type-punning it into struct net_context's v… Medium (6.5) 2026-09-29 Environment Specific
CVE-2026-102367 mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint that fails t… Medium (5.4) 2026-09-29 Environment Specific
CVE-2026-102366 mall4j through 4.0 contains an unrestricted file upload vulnerability in FileController endpoints that lack authorizati… Medium (4.4) 2026-09-29 Environment Specific