🔥 Trending CVEs - Last 90 Days

4,477 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,288
Total CVEs Published
989
Critical Severity
3,488
High Severity
⚠️
Critical Alert
989 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-59374 9.8

This CVE describes a supply chain compromise where unauthorized modifications were introduced into certain ASUS Live Update client versions. The modif...

📅 83 days ago • Dec 17, 2025
CVE-2025-65834 9.8

CVE-2025-65834 is a critical buffer overflow vulnerability in Shotcut video editor that allows remote code execution when processing malicious MLT pro...

📅 83 days ago • Dec 16, 2025
CVE-2025-62863 9.8

This vulnerability allows an attacker to perform an out-of-bounds write in the PCIe driver's S-EL0 address space via a malformed SMC call to the UEFI-...

📅 83 days ago • Dec 16, 2025
CVE-2025-62864 9.8

This vulnerability allows attackers to execute arbitrary code in the UEFI-MM Secure Partition context through an out-of-bounds write via a malformed S...

📅 83 days ago • Dec 16, 2025
CVE-2025-59385 9.8

This CVE describes an authentication bypass vulnerability in QNAP operating systems that allows remote attackers to spoof authentication and access re...

📅 84 days ago • Dec 16, 2025
CVE-2025-62849 9.8

This SQL injection vulnerability in QNAP operating systems allows remote attackers to execute arbitrary SQL commands. If exploited, attackers could ex...

📅 84 days ago • Dec 16, 2025
CVE-2025-64725 9.8

This vulnerability in Weblate allows one user to accept an invitation that was opened by another user, potentially leading to unauthorized access or p...

📅 84 days ago • Dec 15, 2025
CVE-2023-53877 9.8

Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to execute arbitrary SQL queries. T...

📅 84 days ago • Dec 15, 2025
CVE-2023-53871 9.8

Soosyze 2.0.0 contains an unrestricted file upload vulnerability that allows attackers to upload HTML files containing PHP code. This enables remote c...

📅 84 days ago • Dec 15, 2025
CVE-2023-53874 9.8

GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field. Attackers can crash the application by overw...

📅 84 days ago • Dec 15, 2025
CVE-2025-65213 9.8

This CVE describes a critical remote code execution vulnerability in MooreThreads torch_musa where unsafe deserialization via pickle.load() allows arb...

📅 84 days ago • Dec 15, 2025
CVE-2025-14156 9.8

This vulnerability allows unauthenticated attackers to create new user accounts with administrator privileges in WordPress sites using the Fox LMS plu...

📅 84 days ago • Dec 15, 2025
CVE-2025-14708 9.8

A remote buffer overflow vulnerability exists in Shiguangwu sgwbox N3 devices version 2.0.25 through the WIREDCFGGET interface. Attackers can exploit ...

📅 85 days ago • Dec 15, 2025
CVE-2025-14709 9.8

A buffer overflow vulnerability in the Shiguangwu sgwbox N3 NAS device allows remote attackers to execute arbitrary code by manipulating parameters in...

📅 85 days ago • Dec 15, 2025
CVE-2025-14707 9.8

This is a critical command injection vulnerability in Shiguangwu sgwbox N3 version 2.0.25 that allows remote attackers to execute arbitrary commands o...

📅 85 days ago • Dec 15, 2025
CVE-2025-14706 9.8

This vulnerability allows remote attackers to execute arbitrary commands on Shiguangwu sgwbox N3 devices through command injection in the NETREBOOT In...

📅 85 days ago • Dec 15, 2025
CVE-2025-14705 9.8

This vulnerability allows remote attackers to execute arbitrary commands on Shiguangwu sgwbox N3 NAS devices through command injection in the SHARESER...

📅 85 days ago • Dec 15, 2025
CVE-2025-14665 9.8

A remote stack-based buffer overflow vulnerability in Tenda WH450 routers allows attackers to execute arbitrary code by sending specially crafted HTTP...

📅 85 days ago • Dec 14, 2025
CVE-2025-36752 9.8

The Growatt ShineLan-X communication dongle contains an undocumented backup account with hardcoded credentials, creating a backdoor that allows attack...

📅 86 days ago • Dec 13, 2025
CVE-2025-36753 9.8

The SWD debug interface on Growatt ShineLan-X communication dongles is enabled by default, allowing attackers to gain debug access to extract secrets ...

📅 86 days ago • Dec 13, 2025
CVE-2025-36747 9.8

CVE-2025-36747 is a critical vulnerability in ShineLan-X firmware where hardcoded FTP credentials allow attackers to establish insecure connections. T...

📅 86 days ago • Dec 13, 2025
CVE-2025-14440 9.8

The JAY Login & Register WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing u...

📅 86 days ago • Dec 13, 2025
CVE-2025-11693 9.8

The Export WP Page to Static HTML & PDF WordPress plugin exposes authentication cookies in publicly accessible cookies.txt files when administrators t...

📅 86 days ago • Dec 13, 2025
CVE-2025-10738 9.8

This SQL injection vulnerability in the URL Shortener Plugin For WordPress allows unauthenticated attackers to execute arbitrary SQL queries through t...

📅 86 days ago • Dec 13, 2025
CVE-2025-14611 9.8

This vulnerability in Gladinet CentreStack and Triofox involves hardcoded AES encryption keys, allowing attackers to decrypt sensitive data and potent...

📅 87 days ago • Dec 12, 2025
CVE-2024-58311 9.8

The Dormakaba Saflok System 6000 uses a predictable key generation algorithm that allows attackers to derive valid card access keys from a 32-bit uniq...

📅 87 days ago • Dec 12, 2025
CVE-2024-14010 9.8

Typora 1.7.4 contains a command injection vulnerability in PDF export preferences that allows attackers to execute arbitrary system commands. Attacker...

📅 87 days ago • Dec 12, 2025
CVE-2024-58299 9.8

PCMan FTP Server 2.0 contains a critical buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. At...

📅 87 days ago • Dec 12, 2025
CVE-2025-65854 9.8

Insecure permissions in MineAdmin v3.x scheduled tasks allow attackers to execute arbitrary commands, leading to remote code execution and full accoun...

📅 87 days ago • Dec 12, 2025
CVE-2025-54947 9.8

Apache StreamPark versions 2.0.0 through 2.1.6 use a hard-coded encryption key, allowing attackers to decrypt sensitive data or forge encrypted inform...

📅 87 days ago • Dec 12, 2025
CVE-2025-67727 9.8

This CVE describes a GitHub Actions workflow vulnerability in Parse Server that grants elevated permissions to CI/CD pipelines. It allows unauthorized...

📅 88 days ago • Dec 12, 2025
CVE-2025-67728 9.8

CVE-2025-67728 is a command injection vulnerability in Fireshare that allows authenticated users (or unauthenticated users if Public Uploads is enable...

📅 88 days ago • Dec 12, 2025
CVE-2025-14344 9.8

This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress servers running the vulnerable Multi Uploader for Gravity F...

📅 88 days ago • Dec 12, 2025
CVE-2025-12963 9.8

The LazyTasks WordPress plugin has an unauthenticated privilege escalation vulnerability that allows attackers to change any user's email address via ...

📅 88 days ago • Dec 12, 2025
CVE-2024-58308 9.8

CVE-2024-58308 is a critical SQL injection vulnerability in Quick.CMS 6.7 that allows unauthenticated attackers to bypass login authentication and gai...

📅 88 days ago • Dec 11, 2025
CVE-2024-58309 9.8

CVE-2024-58309 is an unauthenticated SQL injection vulnerability in xbtitFM 4.1.18 that allows remote attackers to execute arbitrary SQL commands. Att...

📅 88 days ago • Dec 11, 2025
CVE-2025-66590 9.8

This critical vulnerability in AzeoTech DAQFactory allows attackers to write data beyond allocated memory boundaries, potentially leading to arbitrary...

📅 88 days ago • Dec 11, 2025
CVE-2025-66588 9.8

An uninitialized pointer vulnerability in AzeoTech DAQFactory allows attackers to execute arbitrary code on affected systems. This affects DAQFactory ...

📅 88 days ago • Dec 11, 2025
CVE-2025-36937 9.8

This critical vulnerability in Android's audio decoder allows remote attackers to execute arbitrary code without user interaction by exploiting an out...

📅 88 days ago • Dec 11, 2025
CVE-2025-14535 9.8

This is a critical buffer overflow vulnerability in UTT 进取 512W routers that allows remote attackers to execute arbitrary code by exploiting the s...

📅 88 days ago • Dec 11, 2025
CVE-2025-13764 9.8

The WP CarDealer WordPress plugin has a critical privilege escalation vulnerability that allows unauthenticated attackers to register accounts with ad...

📅 89 days ago • Dec 11, 2025
CVE-2025-65294 9.8

Aqara Hub devices contain an undocumented remote access mechanism that allows attackers to execute arbitrary commands without authentication. This vul...

📅 89 days ago • Dec 10, 2025
CVE-2025-65823 9.8

The Meatmeet Pro device contains hardcoded Wi-Fi credentials in its firmware, allowing attackers to gain unauthorized access to the vendor's Wi-Fi net...

📅 89 days ago • Dec 10, 2025
CVE-2025-65826 9.8

This CVE describes a mobile application that contains hardcoded Wi-Fi credentials for the vendor's development network. If attackers extract these cre...

📅 89 days ago • Dec 10, 2025
CVE-2025-65820 9.8

The Meatmeet Android mobile app version 1.1.2.0 contains an exported activity that can be triggered by other apps, revealing a hidden page with inform...

📅 89 days ago • Dec 10, 2025
CVE-2023-53740 9.8

CVE-2023-53740 is an authentication bypass vulnerability in Screen SFT DAB 1.9.3 that allows attackers to change the admin password without authentica...

📅 89 days ago • Dec 10, 2025
CVE-2025-65602 9.8

An unauthenticated remote code execution vulnerability in ChanCMS v3.3.4 allows attackers to execute arbitrary code via template injection in the /vip...

📅 89 days ago • Dec 10, 2025
CVE-2025-34393 9.8

This vulnerability in Barracuda Service Center allows attackers to execute arbitrary code remotely by exploiting insecure reflection in WSDL service n...

📅 89 days ago • Dec 10, 2025
CVE-2025-34394 9.8

Barracuda Service Center in the RMM solution prior to version 2025.1.1 exposes a .NET Remoting service that allows deserialization of arbitrary types,...

📅 89 days ago • Dec 10, 2025
CVE-2025-34392 9.8

This vulnerability in Barracuda Service Center allows attackers to upload malicious WSDL files that bypass URL validation, leading to arbitrary file w...

📅 89 days ago • Dec 10, 2025

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free