28
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- tenda 105 Vulns
- apple 51 Vulns
- dlink 44 Vulns
- ruijie 35 Vulns
- qnap 31 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-13538 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.… | Critical (9.8) | 2025-11-27 | General-Purpose |
| CVE-2025-12758 | Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Sp… | High (7.5) | 2025-11-27 | General-Purpose |
| CVE-2025-12151 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter i… | Medium (6.4) | 2025-11-27 | General-Purpose |
| CVE-2025-66314 | Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Prope… | High (7.5) | 2025-11-27 | Embedded |
| CVE-2025-34351 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. At the request of the MITRE… | Unknown | 2025-11-27 | General-Purpose |