32
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- tenda 105 Vulns
- apple 51 Vulns
- dlink 44 Vulns
- ruijie 35 Vulns
- qnap 31 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-32803 | In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1,… | Medium (4.0) | 2025-05-28 | General-Purpose |
| CVE-2025-31501 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an RT permalink. | High (7.2) | 2025-05-28 | General-Purpose |
| CVE-2025-31500 | Best Practical RT (Request Tracker) 5.0 through 5.0.7 allows XSS via JavaScript injection in an Asset name. | High (7.2) | 2025-05-28 | General-Purpose |
| CVE-2025-30087 | Best Practical RT (Request Tracker) 4.4 through 4.4.7 and 5.0 through 5.0.7 allows XSS via injection of crafted paramet… | High (7.2) | 2025-05-28 | General-Purpose |
| CVE-2025-1461 | Improper neutralization of the value of the 'eventMoreText' property of the 'VCalendar' component in Vuetify allows uns… | Medium (5.6) | 2025-05-28 | General-Purpose |