126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 109 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2024-29370 | In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allows an attacker to cause a Denial-of-Service (DoS) … | Medium (5.3) | 2025-12-17 | General-Purpose |
| CVE-2022-23851 | Netaxis API Orchestrator (APIO) before 0.19.3 allows server side template injection (SSTI). | Critical (9.8) | 2025-12-17 | General-Purpose |
| CVE-2025-14266 | CSRF in Ercom Cryptobox administration console allows attacker to trigger some actions on behalf of a Cryptobox adminis… | Unknown | 2025-12-17 | Embedded |
| CVE-2025-62690 | Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to r… | Low (3.1) | 2025-12-17 | General-Purpose |
| CVE-2025-62190 | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fai… | Medium (4.3) | 2025-12-17 | General-Purpose |