119
New Embedded Vulns (7 Days)
348
Active Critical ESVs
tenda
Top Target (30 Days)
6.96
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- apple 137 Vulns
- tenda 105 Vulns
- samsung 52 Vulns
- dlink 45 Vulns
- ruijie 35 Vulns
Recent Critical ESVs
CVE-2020-37002
CRITICAL 9.8
CVE-2025-21589
CRITICAL 9.8
CVE-2026-24858
CRITICAL 9.8
CVE-2025-15467
CRITICAL 9.8
CVE-2020-36940
CRITICAL 9.8
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2025-23167 | A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the require… | Unknown | 2025-05-19 | General-Purpose |
| CVE-2025-23166 | The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when execut… | Unknown | 2025-05-19 | General-Purpose |
| CVE-2025-23165 | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 pat… | Unknown | 2025-05-19 | General-Purpose |
| CVE-2025-23164 | A misconfigured access token mechanism in the Unifi Protect Application (Version 5.3.41 and earlier) could permit the r… | Unknown | 2025-05-19 | Embedded |
| CVE-2025-23123 | A malicious actor with access to the management network could execute a remote code execution (RCE) by exploiting a hea… | Unknown | 2025-05-19 | Embedded |