126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 109 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-10018 | QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with adm… | Medium (4.8) | 2025-11-14 | General-Purpose |
| CVE-2025-8855 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticati… | High (8.1) | 2025-11-14 | Embedded |
| CVE-2025-11981 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' param… | Medium (4.9) | 2025-11-14 | General-Purpose |
| CVE-2025-11794 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows s… | Medium (4.9) | 2025-11-14 | General-Purpose |
| CVE-2025-55073 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between… | Medium (5.4) | 2025-11-14 | General-Purpose |