Home Embedded Vulns General Vulns

ESV-Tracker

An AI-powered database that classifies embedded vulnerabilities separately from general-purpose ones.

No Dedicated Database Existed. Until Now.

Embedded system vulnerabilities are critical, yet buried alongside millions of general CVEs. ESV-Tracker changes that.

Your Embedded Threat Center.

Search the database, track embedded CVEs, and explore real-time statistics — all in one place.

2571
New Embedded Vulns (7 Days)
9800
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score

Vulnerability Trends (Last 6 Months)

ESV Severity Distribution (90 Days)

Top Affected ESV Vendors (90 Days)

  • google 129 Vulns
  • dell 48 Vulns
  • microsoft 27 Vulns
  • apple 10 Vulns
  • snipeitapp 2 Vulns

Recent Critical ESVs

CVE-2026-100886 CRITICAL 10.0
CVE-2026-101084 CRITICAL 9.6
CVE-2026-101065 CRITICAL 9.8
CVE-2026-100741 CRITICAL 9.8
CVE-2026-100721 CRITICAL 9.0

Recently Added Vulnerabilities

CVE ID Description Severity Published Type
CVE-2026-100668 Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) i… Medium (6.5) 2026-09-26 General Purpose
CVE-2026-100667 grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challen… Medium (5.3) 2026-09-26 General Purpose
CVE-2026-100666 Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to … High (7.3) 2026-09-26 Environment Specific
CVE-2026-100665 Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certif… High (7.5) 2026-09-26 Environment Specific
CVE-2026-100664 Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authorit… High (7.5) 2026-09-26 General Purpose