126
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 109 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-21074 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b… | Medium (4.3) | 2025-11-05 | Embedded |
| CVE-2025-21073 | Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attack… | Medium (6.8) | 2025-11-05 | Embedded |
| CVE-2025-21071 | Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged … | Medium (5.7) | 2025-11-05 | Embedded |
| CVE-2025-11749 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… | Critical (9.8) | 2025-11-05 | General-Purpose |
| CVE-2025-11072 | The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downlo… | Medium (5.3) | 2025-11-05 | General-Purpose |