Home Embedded Vulns General Vulns

ESV-Tracker

An AI-powered database that classifies embedded vulnerabilities separately from general-purpose ones.

No Dedicated Database Existed. Until Now.

Embedded system vulnerabilities are critical, yet buried alongside millions of general CVEs. ESV-Tracker changes that.

Your Embedded Threat Center.

Search the database, track embedded CVEs, and explore real-time statistics — all in one place.

2674
New Embedded Vulns (7 Days)
9375
Active Critical ESVs
google
Top Target (30 Days)
6.95
Average ESV CVSS Score

Vulnerability Trends (Last 6 Months)

ESV Severity Distribution (90 Days)

Top Affected ESV Vendors (90 Days)

  • google 129 Vulns
  • dell 48 Vulns
  • microsoft 27 Vulns
  • apple 10 Vulns
  • snipeitapp 2 Vulns

Recent Critical ESVs

CVE-2026-90558 CRITICAL 9.8
CVE-2026-78159 CRITICAL 9.8
CVE-2026-78006 CRITICAL 9.8
CVE-2026-85681 CRITICAL 9.8
CVE-2026-84171 CRITICAL 9.8

Recently Added Vulnerabilities

CVE ID Description Severity Published Type
CVE-2019-20218 selectExpander in select.c in SQLite 3.30.1 proceeds with WITH stack unwinding even after a parsing error. High (7.5) 2020-01-02 General Purpose
CVE-2019-20213 D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a … High (7.5) 2020-01-02 Environment Specific
CVE-2019-20208 dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow. Medium (5.5) 2020-01-02 General Purpose
CVE-2019-20205 libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c. High (8.8) 2020-01-02 General Purpose
CVE-2019-20204 The Postie plugin 1.9.40 for WordPress allows XSS, as demonstrated by a certain payload with jaVasCript:/* at the begin… Medium (5.4) 2020-01-02 General Purpose