Home Embedded Vulns General Vulns

ESV-Tracker

An AI-powered database that classifies embedded vulnerabilities separately from general-purpose ones.

No Dedicated Database Existed. Until Now.

Embedded system vulnerabilities are critical, yet buried alongside millions of general CVEs. ESV-Tracker changes that.

Your Embedded Threat Center.

Search the database, track embedded CVEs, and explore real-time statistics — all in one place.

2703
New Embedded Vulns (7 Days)
9800
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score

Vulnerability Trends (Last 6 Months)

ESV Severity Distribution (90 Days)

Top Affected ESV Vendors (90 Days)

  • google 129 Vulns
  • dell 48 Vulns
  • microsoft 27 Vulns
  • apple 10 Vulns
  • snipeitapp 2 Vulns

Recent Critical ESVs

CVE-2026-100886 CRITICAL 10.0
CVE-2026-101084 CRITICAL 9.6
CVE-2026-101065 CRITICAL 9.8
CVE-2026-100741 CRITICAL 9.8
CVE-2026-100721 CRITICAL 9.0

Recently Added Vulnerabilities

CVE ID Description Severity Published Type
CVE-2026-100718 Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When… High (7.1) 2026-09-26 Environment Specific
CVE-2026-100717 froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return… Critical (9.9) 2026-09-26 Environment Specific
CVE-2026-100716 Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fail… Critical (9.9) 2026-09-26 General Purpose
CVE-2026-100715 Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron tas… Critical (9.6) 2026-09-26 Environment Specific
CVE-2026-100714 Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings … Critical (9.1) 2026-09-26 Environment Specific