126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 111 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-64679 | Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | High (7.8) | 2025-12-09 | General-Purpose |
| CVE-2025-64678 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execu… | High (8.8) | 2025-12-09 | General-Purpose |
| CVE-2025-64673 | Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally. | High (7.8) | 2025-12-09 | General-Purpose |
| CVE-2025-64672 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint all… | High (8.8) | 2025-12-09 | General-Purpose |
| CVE-2025-64671 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized a… | High (8.4) | 2025-12-09 | General-Purpose |