23
New Embedded Vulns (7 Days)
147
Active Critical ESVs
Cisco
Top Target (30 Days)
7.84
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- Cisco 89 Vulns
- Siemens 67 Vulns
- Schneider Electric 54 Vulns
- Rockwell Automation 42 Vulns
- Honeywell 38 Vulns
- ABB 31 Vulns
- Emerson 28 Vulns
- GE Digital 24 Vulns
- Phoenix Contact 19 Vulns
- Mitsubishi Electric 16 Vulns
Recent Critical ESVs
CVE-2024-8923
CRITICAL 9.8
CVE-2024-8756
CRITICAL 9.4
CVE-2024-8621
CRITICAL 9.1
CVE-2024-8509
CRITICAL 9.0
CVE-2024-8334
CRITICAL 9.0
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-41232 | Spring Security Aspects may not correctly locate method security annotations on private methods. This can cause an auth… | Critical (9.1) | 2025-05-21 | General-Purpose |
| CVE-2025-3781 | The Raisely Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's raisely_do… | Medium (6.4) | 2025-05-21 | General-Purpose |
| CVE-2025-3750 | The Network Posts Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_height’ para… | Medium (6.4) | 2025-05-21 | General-Purpose |
| CVE-2025-27804 | Several OS command injection vulnerabilities exist in the device firmware in the /var/salia/mqtt.php script. By publish… | Medium (6.5) | 2025-05-21 | Embedded |
| CVE-2025-27803 | The devices do not implement any authentication for the web interface or the MQTT server. An attacker who has network a… | Medium (6.5) | 2025-05-21 | Embedded |