🔥 Trending CVEs - Last 30 Days

1,263 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,748
Total CVEs Published
303
Critical Severity
960
High Severity
⚠️
Critical Alert
303 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-25794 8.2

This vulnerability in ImageMagick allows attackers to trigger an integer overflow when processing large UHDR images, leading to heap buffer overflow a...

📅 12 days ago • Feb 24, 2026
CVE-2019-25440 8.2

This SQL injection vulnerability in WebIncorp ERP allows unauthenticated attackers to manipulate database queries through the prod_id parameter in pro...

📅 13 days ago • Feb 22, 2026
CVE-2019-25443 8.2

Inventory Webapp contains an unauthenticated SQL injection vulnerability in the add-item.php endpoint. Attackers can inject malicious SQL code through...

📅 13 days ago • Feb 22, 2026
CVE-2019-25433 8.2

XOOPS CMS 2.5.9 contains an unauthenticated SQL injection vulnerability in the gerar_pdf.php endpoint via the cid parameter. Attackers can execute arb...

📅 13 days ago • Feb 22, 2026
CVE-2019-25366 8.2

CVE-2019-25366 is an SQL injection vulnerability in microASP Portal+ CMS that allows unauthenticated attackers to execute arbitrary SQL queries by inj...

📅 13 days ago • Feb 22, 2026
CVE-2026-2818 8.2

CVE-2026-2818 is a zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality that allows attackers to write arbitrary...

📅 15 days ago • Feb 20, 2026
CVE-2026-26723 8.2

A Cross-Site Scripting (XSS) vulnerability in Key Systems Inc Global Facilities Management Software allows remote attackers to inject malicious script...

📅 15 days ago • Feb 20, 2026
CVE-2026-21535 8.2

CVE-2026-21535 is an improper access control vulnerability in Microsoft Teams that allows unauthorized attackers to access and disclose sensitive info...

📅 16 days ago • Feb 19, 2026
CVE-2026-26337 8.2

CVE-2026-26337 is an absolute path traversal vulnerability in Hyland Alfresco Transformation Service that allows unauthenticated attackers to read arb...

📅 16 days ago • Feb 19, 2026
CVE-2026-27179 8.2

MajorDoMo contains an unauthenticated SQL injection vulnerability in the commands module that allows attackers to execute arbitrary SQL queries withou...

📅 17 days ago • Feb 18, 2026
CVE-2019-25359 8.2

This SQL injection vulnerability in SD.NET RIM allows attackers to execute arbitrary SQL commands through POST parameters 'idtyp' and 'idgremium' at t...

📅 17 days ago • Feb 18, 2026
CVE-2026-24708 8.2

This vulnerability in OpenStack Nova allows authenticated users to trigger unsafe image resize operations by writing malicious QCOW headers to root or...

📅 17 days ago • Feb 18, 2026
CVE-2025-1924 8.2

A vulnerability in Yokogawa's Vnet/IP Interface Package allows attackers to cause denial of service or execute arbitrary code by sending maliciously c...

📅 22 days ago • Feb 13, 2026
CVE-2019-25325 8.2

CVE-2019-25325 is an SQL injection vulnerability in Thrive Smart Home 1.1 that allows unauthenticated attackers to bypass authentication by injecting ...

📅 23 days ago • Feb 12, 2026
CVE-2026-23857 8.2

This vulnerability in Dell Update Package (DUP) Framework allows low-privileged local attackers to elevate their privileges to higher levels. It affec...

📅 23 days ago • Feb 12, 2026
CVE-2025-9986 8.2

This vulnerability in Vadi Corporate Information Systems' DIGIKENT software exposes sensitive system information to unauthorized parties. It affects a...

📅 24 days ago • Feb 11, 2026
CVE-2025-59023 8.2

This vulnerability in PowerDNS Recursor allows attackers to poison cached DNS delegations by sending crafted delegations or IP fragments. This affects...

📅 26 days ago • Feb 9, 2026
CVE-2026-25847 8.2

A DOM-based cross-site scripting (XSS) vulnerability in JetBrains PyCharm's Jupyter viewer page allows attackers to execute arbitrary JavaScript in th...

📅 26 days ago • Feb 9, 2026
CVE-2026-25636 8.2

A path traversal vulnerability in Calibre's EPUB conversion allows malicious EPUB files to corrupt arbitrary files writable by the Calibre process. At...

📅 29 days ago • Feb 6, 2026
CVE-2026-23989 8.2

This vulnerability in REVA's GRPC authorization middleware allows attackers to bypass scope verification on public links. Malicious users can exploit ...

📅 29 days ago • Feb 6, 2026
CVE-2026-30851 8.1

Caddy servers running versions 2.10.0 through 2.11.1 with forward_auth middleware configured are vulnerable to identity injection and privilege escala...

🔥 Today • Mar 7, 2026
CVE-2026-28678 8.1

DSA Study Hub's authentication system stored JSON Web Tokens in HTTP cookies without cryptographic protection, allowing attackers to read and potentia...

🔥 Today • Mar 7, 2026
CVE-2026-29067 8.1

This vulnerability allows attackers to hijack password reset links by manipulating HTTP headers. Attackers can send malicious Forwarded or X-Forwarded...

🔥 Today • Mar 7, 2026
CVE-2026-29091 8.1

This vulnerability allows remote code execution in applications using Locutus library versions before 3.0.0. Attackers can inject arbitrary JavaScript...

⚡ Yesterday • Mar 6, 2026
CVE-2026-29093 8.1

This vulnerability exposes memcached session storage without authentication in WWBN AVideo's Docker configuration, allowing attackers to hijack sessio...

⚡ Yesterday • Mar 6, 2026
CVE-2025-59541 8.1

This CSRF vulnerability in Chamilo LMS allows attackers to trick authenticated trainers into deleting projects within courses without their consent. T...

⚡ Yesterday • Mar 6, 2026
CVE-2026-28710 8.1

CVE-2026-28710 allows attackers to access and manipulate sensitive information in Acronis Cyber Protect 17 due to improper authentication. This affect...

📅 2 days ago • Mar 6, 2026
CVE-2026-28472 8.1

OpenClaw versions before 2026.2.2 have an authentication bypass vulnerability in the WebSocket gateway connection handshake. Attackers can connect wit...

📅 2 days ago • Mar 5, 2026
CVE-2026-28447 8.1

OpenClaw versions 2026.1.29-beta.1 through 2026.2.1 contain a path traversal vulnerability in plugin installation. Attackers can craft malicious plugi...

📅 2 days ago • Mar 5, 2026
CVE-2026-1321 8.1

This vulnerability in the WordPress Restrict Content plugin allows unauthenticated attackers to register with any membership level, including inactive...

📅 2 days ago • Mar 5, 2026
CVE-2026-20002 8.1

This SQL injection vulnerability in Cisco Secure FMC's web management interface allows authenticated attackers to execute arbitrary SQL commands. Atta...

📅 3 days ago • Mar 4, 2026
CVE-2026-20777 8.1

A heap-based buffer overflow vulnerability in libbiosig's Nicolet WFT file parser allows arbitrary code execution when processing malicious .wft files...

📅 4 days ago • Mar 3, 2026
CVE-2026-1779 8.1

This vulnerability allows unauthenticated attackers to bypass authentication in WordPress sites using the User Registration & Membership plugin. Attac...

📅 9 days ago • Feb 26, 2026
CVE-2026-3172 8.1

A buffer overflow vulnerability in the parallel HNSW index build functionality of pgvector allows authenticated database users to read sensitive data ...

📅 10 days ago • Feb 25, 2026
CVE-2026-25136 8.1

This is a reflected Cross-site Scripting (XSS) vulnerability in Rucio's WebUI that allows attackers to steal login session tokens. Attackers can craft...

📅 10 days ago • Feb 25, 2026
CVE-2026-22719 8.1

CVE-2026-22719 is a command injection vulnerability in VMware Aria Operations that allows unauthenticated attackers to execute arbitrary commands duri...

📅 10 days ago • Feb 25, 2026
CVE-2026-24890 8.1

OpenEMR patient portal users can forge provider signatures by exploiting an authorization bypass in the signature upload endpoint. This affects all Op...

📅 10 days ago • Feb 25, 2026
CVE-2026-3179 8.1

This path traversal vulnerability in ASUSTOR ADM FTP Backup allows attackers to access files outside the intended directory by manipulating file paths...

📅 10 days ago • Feb 25, 2026
CVE-2026-27607 8.1

This vulnerability in RustFS allows attackers to bypass upload policy restrictions in presigned POST uploads, enabling unauthorized file uploads that ...

📅 10 days ago • Feb 25, 2026
CVE-2025-67752 8.1

OpenEMR versions before 7.0.4 have disabled SSL/TLS certificate verification by default in their HTTP client, making all HTTPS connections vulnerable ...

📅 11 days ago • Feb 25, 2026
CVE-2026-2459 8.1

An authenticated user with Installer role in REB500 can access and modify directories they are not authorized to access. This privilege escalation vul...

📅 11 days ago • Feb 24, 2026
CVE-2026-27206 8.1

Zumba Json Serializer versions 3.2.2 and below allow PHP Object Injection through untrusted JSON deserialization. The library's @type field can instan...

📅 14 days ago • Feb 21, 2026
CVE-2026-27196 8.1

This stored cross-site scripting (XSS) vulnerability in Statmatic CMS allows authenticated users with field management permissions to inject malicious...

📅 14 days ago • Feb 21, 2026
CVE-2026-27192 8.1

FeathersJS versions 5.0.39 and below have an origin validation vulnerability where the getAllowedOrigin() function uses startsWith() for comparison, a...

📅 14 days ago • Feb 21, 2026
CVE-2026-27134 8.1

This vulnerability allows unauthorized authentication in Strimzi Kafka clusters when using custom CA certificates with multi-stage chains. Attackers w...

📅 15 days ago • Feb 21, 2026
CVE-2026-2033 8.1

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on MLflow Tracking Server installations via directory traversal i...

📅 15 days ago • Feb 20, 2026
CVE-2026-27190 8.1

This CVE describes a command injection vulnerability in Deno's node:child_process implementation that allows attackers to execute arbitrary commands o...

📅 15 days ago • Feb 20, 2026
CVE-2026-22376 8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the Parkivia WordPress theme. Att...

📅 15 days ago • Feb 20, 2026
CVE-2026-22378 8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

📅 15 days ago • Feb 20, 2026
CVE-2026-22380 8.1

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

📅 15 days ago • Feb 20, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free