2691
New Embedded Vulns (7 Days)
9800
Active Critical ESVs
google
Top Target (30 Days)
6.94
Average ESV CVSS Score
Vulnerability Trends (Last 6 Months)
ESV Severity Distribution (90 Days)
Top Affected ESV Vendors (90 Days)
- google 129 Vulns
- dell 48 Vulns
- microsoft 27 Vulns
- apple 10 Vulns
- snipeitapp 2 Vulns
Recent Critical ESVs
CVE-2026-100886
CRITICAL 10.0
CVE-2026-101084
CRITICAL 9.6
CVE-2026-101065
CRITICAL 9.8
CVE-2026-100741
CRITICAL 9.8
CVE-2026-100721
CRITICAL 9.0
Recently Added Vulnerabilities
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2026-100693 | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-liter… | High (8.4) | 2026-09-26 | Environment Specific |
| CVE-2026-100692 | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stop… | High (7.5) | 2026-09-26 | Environment Specific |
| CVE-2026-100691 | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does n… | Medium (5.4) | 2026-09-26 | Environment Specific |
| CVE-2026-100690 | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.… | High (7.5) | 2026-09-26 | Environment Specific |
| CVE-2026-100689 | GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submod… | Medium (5.9) | 2026-09-26 | Environment Specific |