🔥 Trending CVEs - Last 30 Days

1,268 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,796
Total CVEs Published
306
Critical Severity
962
High Severity
⚠️
Critical Alert
306 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-0848 10.0

CVE-2026-0848 allows arbitrary code execution in NLTK versions <=3.9.2 due to improper input validation in the StanfordSegmenter module. Attackers can...

⚡ Yesterday • Mar 5, 2026
CVE-2026-29000 10.0

This critical authentication bypass vulnerability in pac4j-jwt allows attackers with the server's RSA public key to forge JWT authentication tokens an...

📅 2 days ago • Mar 4, 2026
CVE-2026-20131 10.0

This critical vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to execute arbitrary Java code with roo...

📅 2 days ago • Mar 4, 2026
CVE-2026-20079 10.0

An authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary s...

📅 2 days ago • Mar 4, 2026
CVE-2026-28289 10.0

This CVE describes a patch bypass vulnerability in FreeScout help desk software that allows authenticated users with file upload permissions to achiev...

📅 3 days ago • Mar 3, 2026
CVE-2026-24898 10.0

OpenEMR versions before 8.0.0 contain an unauthenticated token disclosure vulnerability in the MedEx callback endpoint. Any unauthenticated visitor ca...

📅 3 days ago • Mar 3, 2026
CVE-2026-20127 10.0

This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to gain admi...

📅 9 days ago • Feb 25, 2026
CVE-2026-27597 10.0

CVE-2026-27597 is a critical sandbox escape vulnerability in Enclave, a secure JavaScript sandbox for AI agent code execution. Attackers can bypass se...

📅 10 days ago • Feb 25, 2026
CVE-2026-2776 10.0

This CVE describes a sandbox escape vulnerability in Firefox's Telemetry component due to incorrect boundary conditions. Attackers could potentially b...

📅 10 days ago • Feb 24, 2026
CVE-2026-2778 10.0

This CVE describes a sandbox escape vulnerability in Firefox's DOM Core & HTML component due to incorrect boundary conditions. It allows malicious web...

📅 10 days ago • Feb 24, 2026
CVE-2026-2768 10.0

This CVE describes a sandbox escape vulnerability in Firefox's IndexedDB storage component. Attackers could potentially break out of browser security ...

📅 10 days ago • Feb 24, 2026
CVE-2026-2760 10.0

This CVE describes a sandbox escape vulnerability in Firefox's WebRender graphics component due to incorrect boundary conditions. It allows attackers ...

📅 10 days ago • Feb 24, 2026
CVE-2026-23693 10.0

The ElementsKit Lite WordPress plugin versions before 3.7.9 expose an unauthenticated REST endpoint that accepts Mailchimp API credentials. Unauthenti...

📅 11 days ago • Feb 23, 2026
CVE-2026-27211 10.0

Cloud Hypervisor versions 34.0 through 50.0 are vulnerable to host file exfiltration when using virtio-block devices with raw images. A malicious gues...

📅 14 days ago • Feb 21, 2026
CVE-2021-35402 10.0

This vulnerability allows remote attackers to execute arbitrary operating system commands on PROLiNK PRC2402M routers by injecting shell metacharacter...

📅 14 days ago • Feb 20, 2026
CVE-2025-30412 10.0

CVE-2025-30412 allows attackers to bypass authentication mechanisms in Acronis Cyber Protect, potentially leading to unauthorized access, sensitive da...

📅 15 days ago • Feb 20, 2026
CVE-2025-14009 10.0

This critical vulnerability in NLTK's downloader component allows remote code execution when users download malicious zip packages. Attackers can craf...

📅 16 days ago • Feb 18, 2026
CVE-2026-22769 10.0

Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 HF1 contain hardcoded credentials that allow unauthenticated remote attackers to gain r...

📅 17 days ago • Feb 17, 2026
CVE-2025-69770 10.0

This zip slip vulnerability in MojoPortal CMS allows attackers to upload malicious zip files that extract to arbitrary locations on the server, potent...

📅 21 days ago • Feb 13, 2026
CVE-2026-26216 10.0

Crawl4AI versions before 0.8.0 contain an unauthenticated remote code execution vulnerability in the Docker API deployment. Attackers can send malicio...

📅 22 days ago • Feb 12, 2026
CVE-2025-64075 10.0

A path traversal vulnerability in the ZBT WE2001 router's check_token function allows remote attackers to bypass authentication by manipulating sessio...

📅 23 days ago • Feb 11, 2026
CVE-2026-25632 10.0

CVE-2026-25632 is a critical remote code execution vulnerability in EPyT-Flow's REST API. Attackers can send malicious JSON payloads that trigger dyna...

📅 28 days ago • Feb 6, 2026
CVE-2026-25641 10.0

CVE-2026-25641 is a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandbox restrictions by ...

📅 28 days ago • Feb 6, 2026
CVE-2026-25520 10.0

SandboxJS versions before 0.8.29 have a critical sandbox escape vulnerability that allows attackers to obtain the host's Function constructor and exec...

📅 28 days ago • Feb 6, 2026
CVE-2026-25586 10.0

This CVE describes a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandboxing by shadowing...

📅 28 days ago • Feb 6, 2026
CVE-2026-25587 10.0

CVE-2026-25587 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can overwrite Map.prototype.has to br...

📅 28 days ago • Feb 6, 2026
CVE-2026-25725 10.0

This vulnerability allows malicious code running inside Claude Code's sandbox to create a missing settings.json file and inject persistent hooks that ...

📅 28 days ago • Feb 6, 2026
CVE-2025-68121 10.0

This vulnerability in Go's crypto/tls package allows TLS session resumption to succeed when it should fail due to certificate authority configuration ...

📅 29 days ago • Feb 5, 2026
CVE-2026-29789 9.9

This vulnerability allows authenticated attackers with workflow write access in one project to create and manage sites on servers belonging to other p...

🔥 Today • Mar 6, 2026
CVE-2026-28466 9.9

OpenClaw gateway versions before 2026.2.14 have an authorization bypass vulnerability where authenticated clients can manipulate node.invoke parameter...

⚡ Yesterday • Mar 5, 2026
CVE-2026-27965 9.9

This vulnerability allows attackers with read/write access to Vitess backup storage locations to manipulate backup manifest files, leading to arbitrar...

📅 9 days ago • Feb 26, 2026
CVE-2026-27941 9.9

This vulnerability in OpenLIT's GitHub Actions workflows allows attackers to execute arbitrary code with repository write privileges and access sensit...

📅 9 days ago • Feb 26, 2026
CVE-2026-27495 9.9

This vulnerability in n8n allows authenticated users with workflow creation/modification permissions to escape the JavaScript Task Runner sandbox and ...

📅 9 days ago • Feb 25, 2026
CVE-2026-24908 9.9

OpenEMR versions before 8.0.0 contain an SQL injection vulnerability in the Patient REST API endpoint that allows authenticated users with API access ...

📅 9 days ago • Feb 25, 2026
CVE-2026-27728 9.9

CVE-2026-27728 is an OS command injection vulnerability in OneUptime's NetworkPathMonitor.performTraceroute() function that allows authenticated proje...

📅 9 days ago • Feb 25, 2026
CVE-2026-27702 9.9

This CVE describes a critical server-side JavaScript injection vulnerability in Budibase Cloud (SaaS) that allows any authenticated user to execute ar...

📅 9 days ago • Feb 25, 2026
CVE-2025-62878 9.9

This CVE allows attackers to manipulate PersistentVolume path patterns to create volumes in arbitrary host node locations, potentially overwriting sen...

📅 10 days ago • Feb 25, 2026
CVE-2026-27626 9.9

CVE-2026-27626 allows authenticated users to execute arbitrary OS commands on OliveTin hosts by injecting shell metacharacters through password-type a...

📅 10 days ago • Feb 25, 2026
CVE-2026-24849 9.9

CVE-2026-24849 is an arbitrary file read vulnerability in OpenEMR's EtherFaxActions.php. Any authenticated user, regardless of privilege level, can ex...

📅 10 days ago • Feb 25, 2026
CVE-2026-27574 9.9

CVE-2026-27574 allows remote code execution in OneUptime monitoring software. Any user with ProjectMember role (including anonymous users via open reg...

📅 14 days ago • Feb 21, 2026
CVE-2025-69403 9.9

This vulnerability allows attackers to upload malicious files to WordPress sites using the Bravis Addons plugin. It affects all WordPress installation...

📅 14 days ago • Feb 20, 2026
CVE-2025-68549 9.9

This vulnerability allows attackers to upload malicious files, including web shells, to servers running the Wiguard WordPress theme. It affects all ve...

📅 14 days ago • Feb 20, 2026
CVE-2026-26030 9.9

Microsoft Semantic Kernel Python SDK versions before 1.39.4 contain a remote code execution vulnerability in the InMemoryVectorStore filter functional...

📅 15 days ago • Feb 19, 2026
CVE-2025-70830 9.9

This CVE describes a Server-Side Template Injection vulnerability in Datart's Freemarker template engine that allows authenticated attackers to execut...

📅 17 days ago • Feb 17, 2026
CVE-2026-0488 9.9

An authenticated attacker in SAP CRM and SAP S/4HANA can exploit a flaw in the Scripting Editor's generic function module to execute arbitrary SQL sta...

📅 25 days ago • Feb 10, 2026
CVE-2026-1868 9.9

This vulnerability in GitLab AI Gateway allows attackers to execute arbitrary code or cause denial of service through insecure template expansion in D...

📅 26 days ago • Feb 9, 2026
CVE-2026-25763 9.9

OpenProject versions before 16.6.7 and 17.0.3 contain an arbitrary file write vulnerability that can lead to remote code execution. Attackers with rep...

📅 28 days ago • Feb 6, 2026
CVE-2026-25592 9.9

CVE-2026-25592 is an arbitrary file write vulnerability in Microsoft's Semantic Kernel .NET SDK that allows attackers to write files to arbitrary loca...

📅 28 days ago • Feb 6, 2026
CVE-2026-2331 9.8

This critical vulnerability allows unauthenticated attackers to read and write sensitive files via AppEngine's HTTP-based file access feature. Attacke...

⚡ Yesterday • Mar 6, 2026
CVE-2026-29058 9.8

CVE-2026-29058 is a critical remote code execution vulnerability in AVideo video-sharing platform where unauthenticated attackers can execute arbitrar...

⚡ Yesterday • Mar 6, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free