2699
New Embedded Vulns (7 Days)
9958
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- google 129 Vulns
- dell 48 Vulns
- microsoft 27 Vulns
- apple 10 Vulns
- jetbrains 7 Vulns
Recent Critical ESVs
CVE-2026-86345
CRITICAL 9.0
CVE-2026-103765
CRITICAL 9.4
CVE-2026-103764
CRITICAL 9.8
CVE-2026-56660
CRITICAL 9.1
CVE-2026-53953
CRITICAL 9.1
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-7108 | The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field. | Medium (5.4) | 2020-01-16 | General Purpose |
| CVE-2020-7107 | The Ultimate FAQ plugin before 1.8.30 for WordPress allows XSS via Display_FAQ to Shortcodes/DisplayFAQs.php. | Medium (6.1) | 2020-01-16 | General Purpose |
| CVE-2020-7106 | Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automati… | Medium (6.1) | 2020-01-16 | General Purpose |
| CVE-2020-7105 | async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return val… | High (7.5) | 2020-01-16 | General Purpose |
| CVE-2020-7045 | In Wireshark 3.0.x before 3.0.8, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c… | Medium (6.5) | 2020-01-16 | General Purpose |