Home Embedded Vulns General Vulns
126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score

Vulnerability Trends (Last 6 Months)

ESV Severity Distribution (90 Days)

Top Affected ESV Vendors (90 Days)

  • apple 137 Vulns
  • tenda 110 Vulns
  • samsung 52 Vulns
  • dlink 45 Vulns
  • ruijie 35 Vulns

Recent Critical ESVs

CVE-2020-37002 CRITICAL 9.8
CVE-2025-21589 CRITICAL 9.8
CVE-2026-24858 CRITICAL 9.8
CVE-2025-15467 CRITICAL 9.8
CVE-2020-36940 CRITICAL 9.8

Recently Added Vulnerabilities

CVE ID Description Severity Published Type
CVE-2025-66397 ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloa… High (8.3) 2025-12-17 General-Purpose
CVE-2025-66396 ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in t… High (7.2) 2025-12-17 General-Purpose
CVE-2025-65233 Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF'… Medium (6.1) 2025-12-17 General-Purpose
CVE-2025-34442 AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata i… High (7.5) 2025-12-17 General-Purpose
CVE-2025-34441 AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Respons… High (7.5) 2025-12-17 General-Purpose