2571
New Embedded Vulns (7 Days)
9800
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- google 129 Vulns
- dell 48 Vulns
- microsoft 27 Vulns
- apple 10 Vulns
- snipeitapp 2 Vulns
Recent Critical ESVs
CVE-2026-100886
CRITICAL 10.0
CVE-2026-101084
CRITICAL 9.6
CVE-2026-101065
CRITICAL 9.8
CVE-2026-100741
CRITICAL 9.8
CVE-2026-100721
CRITICAL 9.0
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-100668 | Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) i… | Medium (6.5) | 2026-09-26 | General Purpose |
| CVE-2026-100667 | grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challen… | Medium (5.3) | 2026-09-26 | General Purpose |
| CVE-2026-100666 | Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to … | High (7.3) | 2026-09-26 | Environment Specific |
| CVE-2026-100665 | Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certif… | High (7.5) | 2026-09-26 | Environment Specific |
| CVE-2026-100664 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authorit… | High (7.5) | 2026-09-26 | General Purpose |