Home Embedded Vulns General Vulns

ESV-Tracker

An AI-powered database that classifies embedded vulnerabilities separately from general-purpose ones.

No Dedicated Database Existed. Until Now.

Embedded system vulnerabilities are critical, yet buried alongside millions of general CVEs. ESV-Tracker changes that.

Your Embedded Threat Center.

Search the database, track embedded CVEs, and explore real-time statistics — all in one place.

2523
New Embedded Vulns (7 Days)
10169
Active Critical ESVs
jetbrains
Top Target (30 Days)
6.93
Average ESV CVSS Score

Vulnerability Trends (Last 6 Months)

ESV Severity Distribution (90 Days)

Top Affected ESV Vendors (90 Days)

  • google 129 Vulns
  • dell 48 Vulns
  • microsoft 27 Vulns
  • apple 10 Vulns
  • jetbrains 7 Vulns

Recent Critical ESVs

CVE-2026-108474 CRITICAL 9.8
CVE-2026-108264 CRITICAL 9.1
CVE-2026-108263 CRITICAL 9.9
CVE-2026-108261 CRITICAL 9.3
CVE-2026-107845 CRITICAL 9.3

Recently Added Vulnerabilities

CVE ID Description Severity Published Type
CVE-2026-107376 webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser per… High (8.2) 2026-10-08 Environment Specific
CVE-2026-107375 JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice ar… High (8.8) 2026-10-08 Environment Specific
CVE-2026-107362 Malcolm file-upload component ships the upstream FilePond PHP server (pqina/filepond-server-php) largely unmodified: Do… High (7.1) 2026-10-08 Environment Specific
CVE-2026-107361 The Arkime live capture service (arkime-live) in Malcolm runs with network_mode: host, exposing port 8005 on all networ… Medium (4.2) 2026-10-08 Environment Specific
CVE-2026-107337 The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard… High (7.1) 2026-10-08 Environment Specific