126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 109 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-12138 | The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valid… | High (8.8) | 2025-11-21 | General-Purpose |
| CVE-2025-12135 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all vers… | High (7.2) | 2025-11-21 | General-Purpose |
| CVE-2025-12086 | The Return Refund and Exchange For WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i… | Medium (4.3) | 2025-11-21 | General-Purpose |
| CVE-2025-11985 | The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege es… | High (8.8) | 2025-11-21 | General-Purpose |
| CVE-2025-11885 | The EchBay Admin Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_ebnonce' param… | Medium (6.1) | 2025-11-21 | General-Purpose |