126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 110 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-66397 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, the allowRegistration, acceptKiosk, reloa… | High (8.3) | 2025-12-17 | General-Purpose |
| CVE-2025-66396 | ChurchCRM is an open-source church management system. Prior to version 6.5.3, a SQL injection vulnerability exists in t… | High (7.2) | 2025-12-17 | General-Purpose |
| CVE-2025-65233 | Reflected cross-site scripting (XSS) in SLiMS (slims9_bulian) before 9.6.0 via improper handling of $_SERVER['PHP_SELF'… | Medium (6.1) | 2025-12-17 | General-Purpose |
| CVE-2025-34442 | AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata i… | High (7.5) | 2025-12-17 | General-Purpose |
| CVE-2025-34441 | AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Respons… | High (7.5) | 2025-12-17 | General-Purpose |