🔥 Trending CVEs - Last 30 Days

1,252 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,730
Total CVEs Published
301
Critical Severity
951
High Severity
⚠️
Critical Alert
301 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-25761 8.8

Super-linter GitHub Action versions 6.0.0 to 8.3.0 are vulnerable to command injection via specially crafted filenames containing shell command substi...

📅 26 days ago • Feb 9, 2026
CVE-2026-25495 8.8

This CVE describes a SQL injection vulnerability in Craft CMS affecting the element-indexes/get-elements endpoint. Attackers with Control Panel access...

📅 26 days ago • Feb 9, 2026
CVE-2026-25497 8.8

This CVE describes a privilege escalation vulnerability in Craft CMS's GraphQL API where authenticated users with write access to one asset volume can...

📅 26 days ago • Feb 9, 2026
CVE-2026-1486 8.8

This vulnerability allows attackers to bypass disabled Identity Provider (IdP) checks in Keycloak's JWT authorization grant flow. An attacker with a d...

📅 26 days ago • Feb 9, 2026
CVE-2025-10465 8.8

This vulnerability allows attackers to upload malicious files (like web shells) to Sensaway web servers without proper file type validation. It affect...

📅 26 days ago • Feb 9, 2026
CVE-2026-2202 8.8

A buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the shareSpeed parameter in the...

📅 26 days ago • Feb 9, 2026
CVE-2026-2203 8.8

A buffer overflow vulnerability exists in Tenda AC8 routers version 16.03.33.05. Remote attackers can exploit this by sending specially crafted reques...

📅 26 days ago • Feb 9, 2026
CVE-2026-2185 8.8

A stack-based buffer overflow vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code by manipulating device name paramet...

📅 27 days ago • Feb 8, 2026
CVE-2026-2186 8.8

This vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSetIpMacBind fu...

📅 27 days ago • Feb 8, 2026
CVE-2026-2187 8.8

This CVE describes a stack-based buffer overflow vulnerability in Tenda RX3 routers. Attackers can remotely exploit this vulnerability by manipulating...

📅 27 days ago • Feb 8, 2026
CVE-2026-2180 8.8

A stack-based buffer overflow vulnerability exists in Tenda RX3 routers version 16.03.13.11. Attackers can remotely exploit this by manipulating the s...

📅 27 days ago • Feb 8, 2026
CVE-2026-2181 8.8

A stack-based buffer overflow vulnerability exists in Tenda RX3 router firmware version 16.03.13.11. Attackers can remotely exploit this by manipulati...

📅 27 days ago • Feb 8, 2026
CVE-2026-2140 8.8

A buffer overflow vulnerability exists in Tenda TX9 routers through firmware version 22.03.02.10_multi. Attackers can remotely exploit this vulnerabil...

📅 27 days ago • Feb 8, 2026
CVE-2026-2139 8.8

A buffer overflow vulnerability in Tenda TX9 routers allows remote attackers to execute arbitrary code by manipulating the ssid parameter in the fast_...

📅 27 days ago • Feb 8, 2026
CVE-2026-2138 8.8

A buffer overflow vulnerability in Tenda TX9 routers allows remote attackers to execute arbitrary code by manipulating the list argument in the SetSta...

📅 27 days ago • Feb 8, 2026
CVE-2026-2137 8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda TX3 routers via a buffer overflow in the SetIpMacBind function. Attacker...

📅 27 days ago • Feb 8, 2026
CVE-2025-15100 8.8

The JAY Login & Register WordPress plugin contains a privilege escalation vulnerability that allows authenticated users with Subscriber-level access o...

📅 27 days ago • Feb 8, 2026
CVE-2026-25857 8.8

This CVE describes an OS command injection vulnerability in Tenda G300-F router firmware that allows remote attackers to execute arbitrary commands on...

📅 28 days ago • Feb 7, 2026
CVE-2026-2086 8.8

A buffer overflow vulnerability in the UTT HiPER 810G firewall's management interface allows remote attackers to execute arbitrary code or crash the d...

📅 28 days ago • Feb 7, 2026
CVE-2026-2071 8.8

A buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by exploiting the s...

📅 28 days ago • Feb 7, 2026
CVE-2026-2070 8.8

A buffer overflow vulnerability in UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by exploitin...

📅 29 days ago • Feb 6, 2026
CVE-2026-2068 8.8

This CVE describes a remote buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627. Attackers can exploit this by sending spec...

📅 29 days ago • Feb 6, 2026
CVE-2026-25533 8.8

This vulnerability allows attackers to bypass multiple security layers in Enclave, a JavaScript sandbox for AI agent code execution. Attackers can esc...

📅 29 days ago • Feb 6, 2026
CVE-2026-2066 8.8

A buffer overflow vulnerability exists in the UTT 进取 520W router firmware version 1.7.7-180627, specifically in the formIpGroupConfig function. At...

📅 29 days ago • Feb 6, 2026
CVE-2026-2067 8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by manip...

📅 29 days ago • Feb 6, 2026
CVE-2025-69212 8.8

OpenSTAManager versions 2.9.8 and earlier contain a critical OS command injection vulnerability in the P7M file decoding functionality. Authenticated ...

📅 29 days ago • Feb 6, 2026
CVE-2025-69214 8.8

OpenSTAManager versions 2.9.8 and earlier contain an SQL injection vulnerability in the ajax_select.php endpoint. Authenticated attackers can execute ...

📅 29 days ago • Feb 6, 2026
CVE-2026-24851 8.8

OpenFGA versions 1.8.5 to 1.11.2 have an improper policy enforcement vulnerability that can allow unauthorized access when specific authorization mode...

📅 29 days ago • Feb 6, 2026
CVE-2025-64175 8.8

Gogs versions 0.13.3 and earlier have a critical authentication bypass vulnerability where 2FA recovery codes are not scoped to specific users. An att...

📅 29 days ago • Feb 6, 2026
CVE-2025-15566 8.8

This CVE allows attackers to inject malicious configuration into ingress-nginx via the auth-proxy-set-headers annotation, potentially leading to arbit...

📅 29 days ago • Feb 6, 2026
CVE-2026-28683 8.7

This vulnerability allows authenticated attackers to upload malicious SVG files and create hotlinks that execute stored cross-site scripting (XSS) att...

⚡ Yesterday • Mar 6, 2026
CVE-2026-26022 8.7

This stored XSS vulnerability in Gogs allows authenticated users to inject malicious JavaScript via data: URIs in comments and issue descriptions. The...

📅 2 days ago • Mar 5, 2026
CVE-2025-69231 8.7

A stored cross-site scripting vulnerability in OpenEMR's GAD-7 anxiety assessment form allows authenticated clinicians to inject malicious JavaScript....

📅 10 days ago • Feb 25, 2026
CVE-2026-25648 8.7

Authenticated users in Traccar GPS tracking system can upload malicious SVG files containing JavaScript, which executes in other users' browsers when ...

📅 12 days ago • Feb 23, 2026
CVE-2026-25759 8.7

A stored cross-site scripting (XSS) vulnerability in Statmatic CMS allows authenticated users with content creation permissions to inject malicious Ja...

📅 24 days ago • Feb 11, 2026
CVE-2026-28679 8.6

CVE-2026-28679 is a path traversal vulnerability in Home-Gallery.org that allows attackers to download sensitive system files outside the intended med...

⚡ Yesterday • Mar 6, 2026
CVE-2026-26125 8.6

This vulnerability allows attackers to elevate privileges in Payment Orchestrator Service, potentially gaining unauthorized access to payment processi...

📅 2 days ago • Mar 5, 2026
CVE-2026-0847 8.6

This vulnerability in NLTK allows attackers to read arbitrary files on the server through path traversal attacks in multiple CorpusReader classes. It ...

📅 3 days ago • Mar 4, 2026
CVE-2026-20103 8.6

An unauthenticated remote attacker can send crafted packets to Cisco ASA/FTD Remote Access SSL VPN servers to exhaust device memory, causing denial of...

📅 3 days ago • Mar 4, 2026
CVE-2026-20039 8.6

An unauthenticated remote attacker can cause Cisco ASA/FTD firewall devices to reload by sending crafted HTTP requests to the VPN web server, resultin...

📅 3 days ago • Mar 4, 2026
CVE-2026-27696 8.6

This SSRF vulnerability in changedetection.io allows authenticated users (or any user when no password is configured, which is the default) to make th...

📅 10 days ago • Feb 25, 2026
CVE-2026-25965 8.6

ImageMagick's path security policy enforcement occurs before filesystem path resolution, allowing path traversal attacks to bypass policy rules like '...

📅 11 days ago • Feb 24, 2026
CVE-2026-25545 8.6

This SSRF vulnerability in Astro web framework allows attackers to redirect error page requests to internal network resources by manipulating the Host...

📅 11 days ago • Feb 24, 2026
CVE-2025-69379 8.6

This path traversal vulnerability in the WordPress 'Upload Files Anywhere' plugin allows attackers to delete arbitrary files on the server. It affects...

📅 15 days ago • Feb 20, 2026
CVE-2026-1714 8.6

This vulnerability allows unauthenticated attackers to abuse the ShopLentor WordPress plugin as an email relay. Attackers can send arbitrary emails wi...

📅 17 days ago • Feb 18, 2026
CVE-2025-7631 8.6

This SQL injection vulnerability in Tumeva News Software allows attackers to execute arbitrary SQL commands on the database. All users running affecte...

📅 18 days ago • Feb 17, 2026
CVE-2026-1603 8.6

An authentication bypass vulnerability in Ivanti Endpoint Manager allows remote unauthenticated attackers to access stored credential data. This affec...

📅 25 days ago • Feb 10, 2026
CVE-2025-7799 8.6

This reflected XSS vulnerability in Zirve Information Technologies' e-Taxpayer Accounting Website allows attackers to inject malicious scripts into we...

📅 26 days ago • Feb 9, 2026
CVE-2026-25635 8.6

Calibre e-book manager versions before 9.2.0 contain a path traversal vulnerability in the CHM reader that allows attackers to write arbitrary files a...

📅 29 days ago • Feb 6, 2026
CVE-2026-25580 8.6

This SSRF vulnerability in Pydantic AI allows attackers to make the server request internal network resources when applications accept message history...

📅 29 days ago • Feb 6, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free