🔥 Trending CVEs - Last 30 Days

1,220 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,577
Total CVEs Published
282
Critical Severity
938
High Severity
⚠️
Critical Alert
282 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-21325 7.8

CVE-2026-21325 is an out-of-bounds read vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious f...

📅 27 days ago • Feb 10, 2026
CVE-2026-21326 7.8

Adobe After Effects versions 25.6 and earlier contain a use-after-free vulnerability that could allow attackers to execute arbitrary code on a victim'...

📅 27 days ago • Feb 10, 2026
CVE-2026-21328 7.8

Adobe After Effects versions 25.6 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a v...

📅 27 days ago • Feb 10, 2026
CVE-2026-21329 7.8

CVE-2026-21329 is a use-after-free vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious file. ...

📅 27 days ago • Feb 10, 2026
CVE-2026-21330 7.8

Adobe After Effects versions 25.6 and earlier contain a type confusion vulnerability that could allow arbitrary code execution when a user opens a mal...

📅 27 days ago • Feb 10, 2026
CVE-2026-21318 7.8

CVE-2026-21318 is an out-of-bounds write vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious ...

📅 27 days ago • Feb 10, 2026
CVE-2026-21320 7.8

Adobe After Effects versions 25.6 and earlier contain a use-after-free vulnerability that could allow an attacker to execute arbitrary code on a victi...

📅 27 days ago • Feb 10, 2026
CVE-2026-21322 7.8

CVE-2026-21322 is an out-of-bounds read vulnerability in Adobe After Effects that could allow arbitrary code execution when a user opens a malicious f...

📅 27 days ago • Feb 10, 2026
CVE-2026-21323 7.8

Adobe After Effects versions 25.6 and earlier contain a use-after-free vulnerability that could allow attackers to execute arbitrary code on a victim'...

📅 27 days ago • Feb 10, 2026
CVE-2026-21312 7.8

Adobe Audition versions 25.3 and earlier contain an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code when a user...

📅 27 days ago • Feb 10, 2026
CVE-2026-21259 7.8

A heap-based buffer overflow vulnerability in Microsoft Office Excel allows local attackers to execute arbitrary code with elevated privileges. This a...

📅 27 days ago • Feb 10, 2026
CVE-2026-21250 7.8

CVE-2026-21250 is a local privilege escalation vulnerability in Windows HTTP.sys driver where an authorized attacker can exploit untrusted pointer der...

📅 27 days ago • Feb 10, 2026
CVE-2026-21246 7.8

A heap-based buffer overflow vulnerability in Microsoft Graphics Component allows authenticated attackers to execute arbitrary code with elevated priv...

📅 27 days ago • Feb 10, 2026
CVE-2026-21245 7.8

A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...

📅 27 days ago • Feb 10, 2026
CVE-2026-21239 7.8

A heap-based buffer overflow vulnerability in the Windows Kernel allows authenticated attackers to execute arbitrary code with elevated privileges. Th...

📅 27 days ago • Feb 10, 2026
CVE-2026-21232 7.8

CVE-2026-21232 is an untrusted pointer dereference vulnerability in Windows HTTP.sys that allows an authenticated attacker to escalate privileges loca...

📅 27 days ago • Feb 10, 2026
CVE-2026-0651 7.8

This vulnerability allows attackers on the same local network to probe the TP-Link Tapo C260 v1 camera's filesystem to determine if specific files exi...

📅 27 days ago • Feb 10, 2026
CVE-2026-23720 7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

📅 27 days ago • Feb 10, 2026
CVE-2026-25655 7.8

A vulnerability in SINEC NMS allows low-privileged users to modify configuration files, enabling DLL hijacking attacks. This could lead to arbitrary c...

📅 27 days ago • Feb 10, 2026
CVE-2026-25656 7.8

A low-privileged user can modify configuration files in SINEC NMS User Management Component, allowing malicious DLL loading. This leads to arbitrary c...

📅 27 days ago • Feb 10, 2026
CVE-2026-22923 7.8

A data validation vulnerability in NX software versions before V2512 allows local attackers to manipulate internal data during PDF export, potentially...

📅 27 days ago • Feb 10, 2026
CVE-2026-23715 7.8

An out-of-bounds write vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into openin...

📅 27 days ago • Feb 10, 2026
CVE-2026-23716 7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

📅 27 days ago • Feb 10, 2026
CVE-2026-23717 7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

📅 27 days ago • Feb 10, 2026
CVE-2026-23718 7.8

An out-of-bounds read vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into opening...

📅 27 days ago • Feb 10, 2026
CVE-2026-23719 7.8

A heap-based buffer overflow vulnerability in Simcenter Femap and Simcenter Nastran allows attackers to execute arbitrary code by tricking users into ...

📅 27 days ago • Feb 10, 2026
CVE-2025-11547 7.8

CVE-2025-11547 is a privilege escalation vulnerability in AXIS Camera Station Pro that allows authenticated non-admin users to gain administrative pri...

📅 28 days ago • Feb 10, 2026
CVE-2025-15310 7.8

CVE-2025-15310 is a local privilege escalation vulnerability in Tanium Patch Endpoint Tools that allows authenticated local users to gain elevated pri...

📅 28 days ago • Feb 10, 2026
CVE-2025-15319 7.8

CVE-2025-15319 is a local privilege escalation vulnerability in Tanium's Endpoint Configuration Toolset Solution that allows authenticated local users...

📅 28 days ago • Feb 9, 2026
CVE-2026-25931 7.8

This vulnerability in vscode-spell-checker extension allows arbitrary code execution when opening untrusted VS Code workspaces. Attackers can place ma...

📅 28 days ago • Feb 9, 2026
CVE-2026-25925 7.8

PowerDocu versions before 2.4.0 contain a critical deserialization vulnerability where the application blindly trusts the $type property in JSON files...

📅 28 days ago • Feb 9, 2026
CVE-2026-25880 7.8

SumatraPDF versions 3.5.2 and earlier contain a vulnerability where clicking 'Show in folder' in the File menu executes explorer.exe from the same dir...

📅 28 days ago • Feb 9, 2026
CVE-2026-0870 7.8

GIGABYTE MacroHub has a local privilege escalation vulnerability where authenticated local attackers can execute arbitrary code with SYSTEM privileges...

📅 29 days ago • Feb 9, 2026
CVE-2026-29186 7.7

This CVE describes a configuration bypass vulnerability in Backstage's TechDocs plugin that allows arbitrary Python code execution. Attackers can craf...

📅 2 days ago • Mar 7, 2026
CVE-2026-30822 7.7

Flowise versions before 3.0.13 contain an unauthenticated database injection vulnerability that allows attackers to manipulate internal database field...

📅 3 days ago • Mar 7, 2026
CVE-2026-28468 7.7

OpenClaw sandbox browser bridge server accepts requests without gateway authentication, allowing local attackers to access browser control endpoints. ...

📅 4 days ago • Mar 5, 2026
CVE-2026-28393 7.7

OpenClaw versions 2.0.0-beta3 through 2026.2.13 contain a path traversal vulnerability in the hook transform module loading mechanism. Attackers with ...

📅 4 days ago • Mar 5, 2026
CVE-2026-20100 7.7

This vulnerability allows authenticated remote attackers with VPN access to cause Cisco ASA/FTD devices to crash and reload by sending specially craft...

📅 5 days ago • Mar 4, 2026
CVE-2026-20049 7.7

This vulnerability allows authenticated remote attackers to cause denial of service on Cisco ASA and FTD firewalls by sending specially crafted GCM-en...

📅 5 days ago • Mar 4, 2026
CVE-2026-20014 7.7

This vulnerability in Cisco Secure Firewall ASA and FTD software allows authenticated VPN users to send specially crafted IKEv2 packets that cause mem...

📅 5 days ago • Mar 4, 2026
CVE-2026-27938 7.7

This CVE describes a command injection vulnerability in WPGraphQL's GitHub Actions workflow that allows arbitrary command execution when merging pull ...

📅 12 days ago • Feb 26, 2026
CVE-2026-27706 7.7

Plane project management tool versions before 1.2.2 contain a Full Read SSRF vulnerability in the 'Add Link' feature. Authenticated users can send arb...

📅 12 days ago • Feb 25, 2026
CVE-2026-20048 7.7

An authenticated remote attacker can cause a denial of service (DoS) on Cisco Nexus 9000 Series Fabric Switches in ACI mode by sending continuous SNMP...

📅 12 days ago • Feb 25, 2026
CVE-2024-1524 7.7

This vulnerability allows a malicious actor to take over local user accounts when federated authentication with Silent Just-In-Time Provisioning is en...

📅 14 days ago • Feb 24, 2026
CVE-2026-27479 7.7

Wallos versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the logo/icon upload functionality. Attackers can bypass...

📅 17 days ago • Feb 21, 2026
CVE-2026-27464 7.7

This vulnerability allows authenticated users in Metabase to extract sensitive information including database credentials via template evaluation in e...

📅 17 days ago • Feb 21, 2026
CVE-2025-69377 7.7

This path traversal vulnerability in the WordPress User Extra Fields plugin allows attackers to delete arbitrary files on the server. It affects all W...

📅 17 days ago • Feb 20, 2026
CVE-2025-68862 7.7

This path traversal vulnerability in the Woo File Dropzone WordPress plugin allows attackers to delete arbitrary files on the server. It affects all W...

📅 17 days ago • Feb 20, 2026
CVE-2025-1272 7.7

CVE-2025-1272 is a Linux kernel vulnerability where lockdown mode is disabled without warning in Fedora Linux kernel versions 6.12+, allowing attacker...

📅 19 days ago • Feb 18, 2026
CVE-2026-2592 7.7

This vulnerability allows unauthenticated attackers to mark WooCommerce orders as paid without actual payment by reusing valid payment tokens from oth...

📅 21 days ago • Feb 17, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free