🔥 Trending CVEs - Last 90 Days

4,679 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
12,040
Total CVEs Published
1,040
Critical Severity
3,639
High Severity
⚠️
Critical Alert
1,040 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-22237 9.8

This vulnerability exposes sensitive internal API documentation in BLUVOYIX, allowing unauthenticated attackers to craft HTTP requests that abuse inte...

📅 52 days ago • Jan 14, 2026
CVE-2025-14502 9.8

The News and Blog Designer Bundle WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to include and execu...

📅 52 days ago • Jan 14, 2026
CVE-2025-14301 9.8

This vulnerability in the Integration Opvius AI for WooCommerce WordPress plugin allows unauthenticated attackers to perform path traversal attacks. A...

📅 52 days ago • Jan 14, 2026
CVE-2023-54335 9.8

eXtplorer 2.1.14 contains an authentication bypass vulnerability that allows attackers to login without valid credentials by manipulating login reques...

📅 53 days ago • Jan 13, 2026
CVE-2023-54339 9.8

CVE-2023-54339 is a remote command execution vulnerability in Webgrind 1.1 that allows unauthenticated attackers to inject and execute arbitrary OS co...

📅 53 days ago • Jan 13, 2026
CVE-2023-54330 9.8

This CVE describes a critical remote stack-based buffer overflow vulnerability in Inbit Messenger versions 4.6.0 to 4.9.0. Unauthenticated attackers c...

📅 53 days ago • Jan 13, 2026
CVE-2023-54334 9.8

Explorer32++ 1.3.5.531 contains a critical buffer overflow vulnerability in Structured Exception Handler (SEH) records that allows remote code executi...

📅 53 days ago • Jan 13, 2026
CVE-2023-54329 9.8

CVE-2023-54329 is a critical remote command execution vulnerability in Inbit Messenger versions 4.6.0 through 4.9.0. Unauthenticated attackers can exp...

📅 53 days ago • Jan 13, 2026
CVE-2022-50935 9.8

CVE-2022-50935 is an unquoted service path vulnerability in the Flame II HSPA USB Modem software for Windows. Attackers can exploit this to execute ar...

📅 53 days ago • Jan 13, 2026
CVE-2022-50922 9.8

Audio Conversion Wizard v2.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing a specially crafte...

📅 53 days ago • Jan 13, 2026
CVE-2022-50925 9.8

CVE-2022-50925 is a remote keystroke injection vulnerability in Prowise Reflect version 1.0.9 that allows attackers to send keyboard events through an...

📅 53 days ago • Jan 13, 2026
CVE-2022-50926 9.8

This vulnerability in WAGO 750-8212 PFC200 G2 2ETH RS firmware allows attackers to escalate privileges by manipulating session cookies. Attackers can ...

📅 53 days ago • Jan 13, 2026
CVE-2022-50919 9.8

CVE-2022-50919 is an unauthenticated remote code execution vulnerability in Tdarr's Help terminal that allows attackers to inject arbitrary commands. ...

📅 53 days ago • Jan 13, 2026
CVE-2025-64155 9.8

This CVE describes an OS command injection vulnerability in Fortinet FortiSIEM that allows attackers to execute arbitrary commands via crafted TCP req...

📅 53 days ago • Jan 13, 2026
CVE-2025-47855 9.8

An unauthenticated attacker can obtain device configuration files from vulnerable FortiFone systems by sending crafted HTTP/HTTPS requests. This affec...

📅 53 days ago • Jan 13, 2026
CVE-2025-65783 9.8

An arbitrary file upload vulnerability in Hubert Hub v2.0 allows attackers to upload malicious PDF files to execute arbitrary code on affected systems...

📅 53 days ago • Jan 13, 2026
CVE-2026-0892 9.8

This CVE describes memory safety bugs in Firefox and Thunderbird that could lead to memory corruption. With sufficient effort, attackers could potenti...

📅 53 days ago • Jan 13, 2026
CVE-2026-0879 9.8

This CVE describes a sandbox escape vulnerability in the Graphics component of Mozilla products due to incorrect boundary conditions. Attackers could ...

📅 53 days ago • Jan 13, 2026
CVE-2026-0884 9.8

A use-after-free vulnerability in the JavaScript Engine component allows attackers to execute arbitrary code or cause denial of service. This affects ...

📅 53 days ago • Jan 13, 2026
CVE-2025-10915 9.8

The Dreamer Blog WordPress theme through version 1.2 allows attackers to install arbitrary plugins or themes due to missing capability checks. This af...

📅 53 days ago • Jan 13, 2026
CVE-2026-22781 9.8

TinyWeb HTTP Server versions before 1.98 are vulnerable to unauthenticated remote command injection via CGI ISINDEX-style query parameters. Attackers ...

📅 54 days ago • Jan 12, 2026
CVE-2025-46070 9.8

A critical remote code execution vulnerability in Automai BotManager v25.2.0 allows attackers to execute arbitrary code on affected systems via the Bo...

📅 54 days ago • Jan 12, 2026
CVE-2025-65552 9.8

The D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on its 433 MHz sensor communication channel. Attackers within RF r...

📅 54 days ago • Jan 12, 2026
CVE-2025-69269 9.8

This OS command injection vulnerability in Broadcom DX NetOps Spectrum allows attackers to execute arbitrary operating system commands on affected sys...

📅 54 days ago • Jan 12, 2026
CVE-2025-69270 9.8

This vulnerability in Broadcom DX NetOps Spectrum exposes sensitive information through query strings in GET requests, allowing attackers to hijack us...

📅 54 days ago • Jan 12, 2026
CVE-2025-69542 9.8

A command injection vulnerability in D-Link DIR895LA1 routers allows attackers to execute arbitrary commands with root privileges by sending malicious...

📅 57 days ago • Jan 9, 2026
CVE-2025-70161 9.8

EDIMAX BR-6208AC V2 router firmware version 1.02 contains a command injection vulnerability in the pppUserName field that allows attackers to execute ...

📅 57 days ago • Jan 9, 2026
CVE-2025-14598 9.8

BeeS Software Solutions BET Portal contains a critical SQL injection vulnerability in its login functionality, allowing attackers to execute arbitrary...

📅 57 days ago • Jan 9, 2026
CVE-2025-66050 9.8

Vivotek IP7137 cameras have a critical authentication bypass vulnerability where administrator accounts have no default password requirement. Attacker...

📅 57 days ago • Jan 9, 2026
CVE-2026-22234 9.8

This vulnerability allows unauthenticated attackers to access the OPEXUS eCasePortal 'Attachments.aspx' endpoint, manipulate predictable 'formid' valu...

📅 58 days ago • Jan 8, 2026
CVE-2025-61246 9.8

This vulnerability allows attackers to execute arbitrary SQL commands through the proId parameter in master/review_action.php. It affects all installa...

📅 58 days ago • Jan 8, 2026
CVE-2025-61548 9.8

This SQL injection vulnerability in Print Shop Pro WebDesk allows remote attackers to execute arbitrary SQL commands by manipulating the hfInventoryDi...

📅 58 days ago • Jan 8, 2026
CVE-2026-22043 9.8

A privilege escalation vulnerability in RustFS IAM allows restricted service accounts or STS credentials to self-issue unrestricted service accounts w...

📅 58 days ago • Jan 8, 2026
CVE-2025-69258 9.8

An unauthenticated remote attacker can exploit a LoadLibraryEX vulnerability in Trend Micro Apex Central to load malicious DLLs, leading to arbitrary ...

📅 58 days ago • Jan 8, 2026
CVE-2025-62877 9.8

CVE-2025-62877 exposes the default SSH login password in SUSE Harvester virtualization environments when using the interactive installer (1.5.x or 1.6...

📅 58 days ago • Jan 8, 2026
CVE-2025-67921 9.8

This SQL injection vulnerability in the VanKarWai Lobo WordPress theme allows attackers to execute arbitrary SQL commands through specially crafted in...

📅 58 days ago • Jan 8, 2026
CVE-2025-67924 9.8

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the Corpkit theme. It affects all Wo...

📅 58 days ago • Jan 8, 2026
CVE-2025-67928 9.8

This SQL injection vulnerability in the Automotive Listings WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It af...

📅 58 days ago • Jan 8, 2026
CVE-2025-67913 9.8

This CVE describes a missing authorization vulnerability in the Aruba HiSpeed Cache WordPress plugin that allows attackers to access functionality not...

📅 58 days ago • Jan 8, 2026
CVE-2025-67915 9.8

This CVE describes an authentication bypass vulnerability in the Arraytics Timetics WordPress plugin that allows attackers to gain unauthorized access...

📅 58 days ago • Jan 8, 2026
CVE-2025-67920 9.8

This vulnerability allows attackers to include local PHP files through improper filename control in the Neo Ocular WordPress theme, potentially leadin...

📅 58 days ago • Jan 8, 2026
CVE-2025-67910 9.8

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress servers running the ContentStudio plugin. Attackers ...

📅 58 days ago • Jan 8, 2026
CVE-2025-67911 9.8

This CVE describes a PHP object injection vulnerability in Tribulant Software's Newsletters WordPress plugin. Attackers can exploit insecure deseriali...

📅 58 days ago • Jan 8, 2026
CVE-2025-22728 9.8

This SQL injection vulnerability in the Workreap WordPress theme plugin allows attackers to execute arbitrary SQL commands on the database. It affects...

📅 58 days ago • Jan 8, 2026
CVE-2025-23504 9.8

This CVE describes an authentication bypass vulnerability in the RiceTheme Felan Framework WordPress plugin that allows attackers to gain unauthorized...

📅 58 days ago • Jan 8, 2026
CVE-2025-23993 9.8

This SQL injection vulnerability in the Felan Framework WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It affect...

📅 58 days ago • Jan 8, 2026
CVE-2025-22509 9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Atlas WordPress theme. Attackers ...

📅 58 days ago • Jan 8, 2026
CVE-2025-22707 9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Moody WordPress theme. Attackers ...

📅 58 days ago • Jan 8, 2026
CVE-2025-22708 9.8

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements in the Mi...

📅 58 days ago • Jan 8, 2026
CVE-2025-22712 9.8

This vulnerability allows attackers to include arbitrary local files through PHP's include/require statements in the Typify WordPress theme. Attackers...

📅 58 days ago • Jan 8, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free