🔥 Trending CVEs - Last 90 Days

4,671 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
12,061
Total CVEs Published
1,038
Critical Severity
3,633
High Severity
⚠️
Critical Alert
1,038 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-21969 9.8

An unauthenticated remote code execution vulnerability in Oracle Agile Product Lifecycle Management for Process allows attackers to completely comprom...

📅 46 days ago • Jan 20, 2026
CVE-2025-56005 9.8

CVE-2025-56005 is a critical vulnerability in the PLY (Python Lex-Yacc) library that allows remote code execution via an undocumented 'picklefile' par...

📅 46 days ago • Jan 20, 2026
CVE-2025-55423 9.8

A critical command injection vulnerability in ipTIME routers allows attackers to execute arbitrary operating system commands by injecting malicious in...

📅 46 days ago • Jan 20, 2026
CVE-2025-64087 9.8

A Server-Side Template Injection (SSTI) vulnerability in the FreeMarker component of opensagres XDocReport allows attackers to execute arbitrary code ...

📅 46 days ago • Jan 20, 2026
CVE-2025-65482 9.8

An XML External Entity (XXE) vulnerability in opensagres XDocReport versions 0.9.2 through 2.0.3 allows attackers to execute arbitrary code by uploadi...

📅 46 days ago • Jan 20, 2026
CVE-2026-0906 9.8

This vulnerability allows attackers to spoof the URL bar (Omnibox) in Google Chrome on Android, potentially tricking users into believing they're on a...

📅 46 days ago • Jan 20, 2026
CVE-2026-0907 9.8

This vulnerability allows attackers to spoof the user interface in Chrome's Split View mode, potentially tricking users into interacting with maliciou...

📅 46 days ago • Jan 20, 2026
CVE-2026-0905 9.8

This vulnerability in Google Chrome allows attackers who obtain network log files to potentially extract sensitive information due to insufficient pol...

📅 46 days ago • Jan 20, 2026
CVE-2026-23947 9.8

Orval versions 7.19.0 through 8.0.2 contain a code injection vulnerability in the x-enumDescriptions field processing. Untrusted OpenAPI specification...

📅 46 days ago • Jan 20, 2026
CVE-2026-23944 9.8

CVE-2026-23944 is an authentication bypass vulnerability in Arcane Docker management interface that allows unauthenticated attackers to proxy requests...

📅 47 days ago • Jan 19, 2026
CVE-2026-23837 9.8

CVE-2026-23837 is an authentication bypass vulnerability in MyTube that allows unauthenticated attackers to access protected administrative functions....

📅 47 days ago • Jan 19, 2026
CVE-2026-23883 9.8

This is a use-after-free vulnerability in FreeRDP's X11 client graphics handling that allows a malicious RDP server to trigger heap corruption in the ...

📅 47 days ago • Jan 19, 2026
CVE-2026-23884 9.8

CVE-2026-23884 is a use-after-free vulnerability in FreeRDP clients where offscreen bitmap deletion leaves a pointer to freed memory. A malicious RDP ...

📅 47 days ago • Jan 19, 2026
CVE-2026-23533 9.8

A heap buffer overflow vulnerability in FreeRDP's ClearCodec decode path allows malicious RDP servers to trigger client-side memory corruption. This c...

📅 47 days ago • Jan 19, 2026
CVE-2026-23534 9.8

A heap buffer overflow vulnerability in FreeRDP's ClearCodec decode path allows malicious RDP servers to trigger client-side memory corruption. This a...

📅 47 days ago • Jan 19, 2026
CVE-2026-23532 9.8

A heap buffer overflow vulnerability in FreeRDP client allows malicious RDP servers to trigger client-side memory corruption. This can cause denial of...

📅 47 days ago • Jan 19, 2026
CVE-2026-1162 9.8

This vulnerability allows remote attackers to execute arbitrary code on UTT HiPER 810 routers by exploiting a buffer overflow in the password change f...

📅 47 days ago • Jan 19, 2026
CVE-2026-23530 9.8

FreeRDP clients prior to version 3.21.0 contain a heap buffer overflow vulnerability in the planar bitmap decompression function. A malicious RDP serv...

📅 47 days ago • Jan 19, 2026
CVE-2026-23531 9.8

This CVE describes a heap buffer overflow vulnerability in FreeRDP's ClearCodec implementation. A malicious RDP server can send crafted RDPGFX surface...

📅 47 days ago • Jan 19, 2026
CVE-2026-0610 9.8

A SQL injection vulnerability in Devolutions Server's remote-sessions component allows attackers to execute arbitrary SQL commands. This affects Devol...

📅 47 days ago • Jan 19, 2026
CVE-2025-10484 9.8

This vulnerability allows unauthenticated attackers to bypass authentication in the Registration & Login with Mobile Phone Number for WooCommerce Word...

📅 49 days ago • Jan 17, 2026
CVE-2025-15403 9.8

This vulnerability in the RegistrationMagic WordPress plugin allows unauthenticated attackers to manipulate menu generation logic, granting administra...

📅 49 days ago • Jan 17, 2026
CVE-2026-23744 9.8

MCPJam inspector versions 1.4.2 and earlier contain a critical remote code execution vulnerability. Attackers can send a crafted HTTP request that tri...

📅 50 days ago • Jan 16, 2026
CVE-2025-14894 9.8

CVE-2025-14894 is an unauthenticated remote code execution vulnerability in Livewire Filemanager for Laravel applications. Attackers can upload malici...

📅 50 days ago • Jan 16, 2026
CVE-2025-60021 9.8

This CVE describes a remote command injection vulnerability in Apache bRPC's heap profiler service. Attackers can execute arbitrary commands by inject...

📅 50 days ago • Jan 16, 2026
CVE-2026-1019 9.8

The Police Statistics Database System developed by Gotac has a Missing Authentication vulnerability that allows unauthenticated remote attackers to re...

📅 50 days ago • Jan 16, 2026
CVE-2026-1021 9.8

The Police Statistics Database System developed by Gotac contains an arbitrary file upload vulnerability that allows unauthenticated remote attackers ...

📅 50 days ago • Jan 16, 2026
CVE-2025-62582 9.8

Delta Electronics DIAView has a critical authentication bypass vulnerability (CWE-306) that allows attackers to bypass authentication mechanisms and g...

📅 50 days ago • Jan 16, 2026
CVE-2025-62581 9.8

Delta Electronics DIAView contains multiple unspecified vulnerabilities related to CWE-321 (Use of Hard-coded Cryptographic Key). Attackers could pote...

📅 50 days ago • Jan 16, 2026
CVE-2021-47785 9.8

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote attackers to execute arbitrary co...

📅 50 days ago • Jan 16, 2026
CVE-2023-7334 9.8

This CVE describes a critical .NET deserialization vulnerability in Changjetong T+ software that allows remote attackers to execute arbitrary code on ...

📅 51 days ago • Jan 15, 2026
CVE-2025-70892 9.8

CVE-2025-70892 is a critical SQL injection vulnerability in Phpgurukul Cyber Cafe Management System v1.0 that allows attackers to execute arbitrary SQ...

📅 51 days ago • Jan 15, 2026
CVE-2026-23519 9.8

This vulnerability in RustCrypto CMOV allows timing side-channel attacks on cryptographic operations when using the thumbv6m-none-eabi compiler target...

📅 51 days ago • Jan 15, 2026
CVE-2025-62193 9.8

This vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands on NOAA PMEL Live Access Server (LAS) insta...

📅 51 days ago • Jan 15, 2026
CVE-2025-67079 9.8

This CVE describes a critical file upload vulnerability in Omnispace Agora Project that allows attackers to execute arbitrary code through the Imagick...

📅 51 days ago • Jan 15, 2026
CVE-2021-47819 9.8

CVE-2021-47819 is a critical file upload vulnerability in ProjeQtOr Project Management software that allows guest users to upload malicious PHP files ...

📅 51 days ago • Jan 15, 2026
CVE-2021-47781 9.8

CVE-2021-47781 is a critical buffer overflow vulnerability in Cmder Console Emulator version 1.3.18 that allows attackers to cause denial of service b...

📅 51 days ago • Jan 15, 2026
CVE-2021-47774 9.8

Kingdia CD Extractor 3.0.2 contains a critical buffer overflow vulnerability in its registration name field that allows remote attackers to execute ar...

📅 51 days ago • Jan 15, 2026
CVE-2021-47772 9.8

CVE-2021-47772 is a critical buffer overflow vulnerability in 10-Strike Network Inventory Explorer Pro that allows remote code execution via malicious...

📅 51 days ago • Jan 15, 2026
CVE-2021-47753 9.8

CVE-2021-47753 is an unauthenticated file upload vulnerability in phpKF CMS that allows remote attackers to upload malicious PHP files disguised as PN...

📅 51 days ago • Jan 15, 2026
CVE-2026-22857 9.8

This is a critical heap use-after-free vulnerability in FreeRDP that allows remote code execution. Attackers can exploit this to execute arbitrary cod...

📅 52 days ago • Jan 14, 2026
CVE-2026-22852 9.8

A heap buffer overflow vulnerability in FreeRDP allows malicious RDP servers to trigger memory corruption and crash FreeRDP clients. This affects all ...

📅 52 days ago • Jan 14, 2026
CVE-2026-22853 9.8

CVE-2026-22853 is a critical heap buffer overflow vulnerability in FreeRDP's RDPEAR component that allows attackers to execute arbitrary code or cause...

📅 52 days ago • Jan 14, 2026
CVE-2026-22854 9.8

This is a critical heap buffer overflow vulnerability in FreeRDP that allows a malicious RDP server to execute arbitrary code on client systems by sen...

📅 52 days ago • Jan 14, 2026
CVE-2026-22708 9.8

This vulnerability in Cursor AI code editor allows attackers to execute shell built-ins without allowlist approval when the Cursor Agent runs in Auto-...

📅 52 days ago • Jan 14, 2026
CVE-2025-70968 9.8

FreeImage 3.18.0 contains a use-after-free vulnerability in the TARGA image parser that allows attackers to execute arbitrary code or cause denial of ...

📅 52 days ago • Jan 14, 2026
CVE-2025-37184 9.8

This vulnerability allows unauthenticated remote attackers to bypass multi-factor authentication requirements in an Orchestrator service, enabling the...

📅 52 days ago • Jan 14, 2026
CVE-2026-22238 9.8

This critical vulnerability in BLUVOYIX allows unauthenticated attackers to create admin users via specially crafted HTTP requests to admin APIs. Succ...

📅 52 days ago • Jan 14, 2026
CVE-2026-22236 9.8

This critical authentication bypass vulnerability in BLUVOYIX allows unauthenticated attackers to send crafted HTTP requests to backend APIs and gain ...

📅 52 days ago • Jan 14, 2026
CVE-2026-22237 9.8

This vulnerability exposes sensitive internal API documentation in BLUVOYIX, allowing unauthenticated attackers to craft HTTP requests that abuse inte...

📅 52 days ago • Jan 14, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free