2703
New Embedded Vulns (7 Days)
9800
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- google 129 Vulns
- dell 48 Vulns
- microsoft 27 Vulns
- apple 10 Vulns
- snipeitapp 2 Vulns
Recent Critical ESVs
CVE-2026-100886
CRITICAL 10.0
CVE-2026-101084
CRITICAL 9.6
CVE-2026-101065
CRITICAL 9.8
CVE-2026-100741
CRITICAL 9.8
CVE-2026-100721
CRITICAL 9.0
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-100718 | Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When… | High (7.1) | 2026-09-26 | Environment Specific |
| CVE-2026-100717 | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return… | Critical (9.9) | 2026-09-26 | Environment Specific |
| CVE-2026-100716 | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fail… | Critical (9.9) | 2026-09-26 | General Purpose |
| CVE-2026-100715 | Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron tas… | Critical (9.6) | 2026-09-26 | Environment Specific |
| CVE-2026-100714 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings … | Critical (9.1) | 2026-09-26 | Environment Specific |