0
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- tenda 105 Vulns
- apple 51 Vulns
- dlink 44 Vulns
- ruijie 35 Vulns
- qnap 30 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-1221 | PrismX MX100 AP controller developed by BROWAN COMMUNICATIONS has a Use of Hard-coded Credentials vulnerability, allow… | Critical (9.8) | 2026-01-20 | Embedded |
| CVE-2025-66523 | URL parameters are directly embedded into JavaScript code or HTML attributes without proper encoding or sanitization. T… | Medium (6.1) | 2026-01-20 | General-Purpose |
| CVE-2026-1218 | A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClien… | Medium (6.3) | 2026-01-20 | General-Purpose |
| CVE-2026-1045 | The Viet contact plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u… | Medium (4.4) | 2026-01-20 | General-Purpose |
| CVE-2026-1042 | The WP Hello Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'digit_one' and 'digit_two' … | Medium (4.4) | 2026-01-20 | General-Purpose |