🔥 Trending CVEs - Last 90 Days
4,477 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
This CVE describes a supply chain compromise where unauthorized modifications were introduced into certain ASUS Live Update client versions. The modif...
📅 83 days ago • Dec 17, 2025CVE-2025-65834 is a critical buffer overflow vulnerability in Shotcut video editor that allows remote code execution when processing malicious MLT pro...
📅 83 days ago • Dec 16, 2025This vulnerability allows an attacker to perform an out-of-bounds write in the PCIe driver's S-EL0 address space via a malformed SMC call to the UEFI-...
📅 83 days ago • Dec 16, 2025This vulnerability allows attackers to execute arbitrary code in the UEFI-MM Secure Partition context through an out-of-bounds write via a malformed S...
📅 83 days ago • Dec 16, 2025This CVE describes an authentication bypass vulnerability in QNAP operating systems that allows remote attackers to spoof authentication and access re...
📅 84 days ago • Dec 16, 2025This SQL injection vulnerability in QNAP operating systems allows remote attackers to execute arbitrary SQL commands. If exploited, attackers could ex...
📅 84 days ago • Dec 16, 2025This vulnerability in Weblate allows one user to accept an invitation that was opened by another user, potentially leading to unauthorized access or p...
📅 84 days ago • Dec 15, 2025Bus Reservation System 1.1 contains a SQL injection vulnerability in the pickup_id parameter that allows attackers to execute arbitrary SQL queries. T...
📅 84 days ago • Dec 15, 2025Soosyze 2.0.0 contains an unrestricted file upload vulnerability that allows attackers to upload HTML files containing PHP code. This enables remote c...
📅 84 days ago • Dec 15, 2025GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field. Attackers can crash the application by overw...
📅 84 days ago • Dec 15, 2025This CVE describes a critical remote code execution vulnerability in MooreThreads torch_musa where unsafe deserialization via pickle.load() allows arb...
📅 84 days ago • Dec 15, 2025This vulnerability allows unauthenticated attackers to create new user accounts with administrator privileges in WordPress sites using the Fox LMS plu...
📅 84 days ago • Dec 15, 2025A remote buffer overflow vulnerability exists in Shiguangwu sgwbox N3 devices version 2.0.25 through the WIREDCFGGET interface. Attackers can exploit ...
📅 85 days ago • Dec 15, 2025A buffer overflow vulnerability in the Shiguangwu sgwbox N3 NAS device allows remote attackers to execute arbitrary code by manipulating parameters in...
📅 85 days ago • Dec 15, 2025This is a critical command injection vulnerability in Shiguangwu sgwbox N3 version 2.0.25 that allows remote attackers to execute arbitrary commands o...
📅 85 days ago • Dec 15, 2025This vulnerability allows remote attackers to execute arbitrary commands on Shiguangwu sgwbox N3 devices through command injection in the NETREBOOT In...
📅 85 days ago • Dec 15, 2025This vulnerability allows remote attackers to execute arbitrary commands on Shiguangwu sgwbox N3 NAS devices through command injection in the SHARESER...
📅 85 days ago • Dec 15, 2025A remote stack-based buffer overflow vulnerability in Tenda WH450 routers allows attackers to execute arbitrary code by sending specially crafted HTTP...
📅 85 days ago • Dec 14, 2025The Growatt ShineLan-X communication dongle contains an undocumented backup account with hardcoded credentials, creating a backdoor that allows attack...
📅 86 days ago • Dec 13, 2025The SWD debug interface on Growatt ShineLan-X communication dongles is enabled by default, allowing attackers to gain debug access to extract secrets ...
📅 86 days ago • Dec 13, 2025CVE-2025-36747 is a critical vulnerability in ShineLan-X firmware where hardcoded FTP credentials allow attackers to establish insecure connections. T...
📅 86 days ago • Dec 13, 2025The JAY Login & Register WordPress plugin has an authentication bypass vulnerability that allows unauthenticated attackers to log in as any existing u...
📅 86 days ago • Dec 13, 2025The Export WP Page to Static HTML & PDF WordPress plugin exposes authentication cookies in publicly accessible cookies.txt files when administrators t...
📅 86 days ago • Dec 13, 2025This SQL injection vulnerability in the URL Shortener Plugin For WordPress allows unauthenticated attackers to execute arbitrary SQL queries through t...
📅 86 days ago • Dec 13, 2025This vulnerability in Gladinet CentreStack and Triofox involves hardcoded AES encryption keys, allowing attackers to decrypt sensitive data and potent...
📅 87 days ago • Dec 12, 2025The Dormakaba Saflok System 6000 uses a predictable key generation algorithm that allows attackers to derive valid card access keys from a 32-bit uniq...
📅 87 days ago • Dec 12, 2025Typora 1.7.4 contains a command injection vulnerability in PDF export preferences that allows attackers to execute arbitrary system commands. Attacker...
📅 87 days ago • Dec 12, 2025PCMan FTP Server 2.0 contains a critical buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. At...
📅 87 days ago • Dec 12, 2025Insecure permissions in MineAdmin v3.x scheduled tasks allow attackers to execute arbitrary commands, leading to remote code execution and full accoun...
📅 87 days ago • Dec 12, 2025Apache StreamPark versions 2.0.0 through 2.1.6 use a hard-coded encryption key, allowing attackers to decrypt sensitive data or forge encrypted inform...
📅 87 days ago • Dec 12, 2025This CVE describes a GitHub Actions workflow vulnerability in Parse Server that grants elevated permissions to CI/CD pipelines. It allows unauthorized...
📅 88 days ago • Dec 12, 2025CVE-2025-67728 is a command injection vulnerability in Fireshare that allows authenticated users (or unauthenticated users if Public Uploads is enable...
📅 88 days ago • Dec 12, 2025This vulnerability allows unauthenticated attackers to delete arbitrary files on WordPress servers running the vulnerable Multi Uploader for Gravity F...
📅 88 days ago • Dec 12, 2025The LazyTasks WordPress plugin has an unauthenticated privilege escalation vulnerability that allows attackers to change any user's email address via ...
📅 88 days ago • Dec 12, 2025CVE-2024-58308 is a critical SQL injection vulnerability in Quick.CMS 6.7 that allows unauthenticated attackers to bypass login authentication and gai...
📅 88 days ago • Dec 11, 2025CVE-2024-58309 is an unauthenticated SQL injection vulnerability in xbtitFM 4.1.18 that allows remote attackers to execute arbitrary SQL commands. Att...
📅 88 days ago • Dec 11, 2025This critical vulnerability in AzeoTech DAQFactory allows attackers to write data beyond allocated memory boundaries, potentially leading to arbitrary...
📅 88 days ago • Dec 11, 2025An uninitialized pointer vulnerability in AzeoTech DAQFactory allows attackers to execute arbitrary code on affected systems. This affects DAQFactory ...
📅 88 days ago • Dec 11, 2025This critical vulnerability in Android's audio decoder allows remote attackers to execute arbitrary code without user interaction by exploiting an out...
📅 88 days ago • Dec 11, 2025This is a critical buffer overflow vulnerability in UTT 进取 512W routers that allows remote attackers to execute arbitrary code by exploiting the s...
📅 88 days ago • Dec 11, 2025The WP CarDealer WordPress plugin has a critical privilege escalation vulnerability that allows unauthenticated attackers to register accounts with ad...
📅 89 days ago • Dec 11, 2025Aqara Hub devices contain an undocumented remote access mechanism that allows attackers to execute arbitrary commands without authentication. This vul...
📅 89 days ago • Dec 10, 2025The Meatmeet Pro device contains hardcoded Wi-Fi credentials in its firmware, allowing attackers to gain unauthorized access to the vendor's Wi-Fi net...
📅 89 days ago • Dec 10, 2025This CVE describes a mobile application that contains hardcoded Wi-Fi credentials for the vendor's development network. If attackers extract these cre...
📅 89 days ago • Dec 10, 2025The Meatmeet Android mobile app version 1.1.2.0 contains an exported activity that can be triggered by other apps, revealing a hidden page with inform...
📅 89 days ago • Dec 10, 2025CVE-2023-53740 is an authentication bypass vulnerability in Screen SFT DAB 1.9.3 that allows attackers to change the admin password without authentica...
📅 89 days ago • Dec 10, 2025An unauthenticated remote code execution vulnerability in ChanCMS v3.3.4 allows attackers to execute arbitrary code via template injection in the /vip...
📅 89 days ago • Dec 10, 2025This vulnerability in Barracuda Service Center allows attackers to execute arbitrary code remotely by exploiting insecure reflection in WSDL service n...
📅 89 days ago • Dec 10, 2025Barracuda Service Center in the RMM solution prior to version 2025.1.1 exposes a .NET Remoting service that allows deserialization of arbitrary types,...
📅 89 days ago • Dec 10, 2025This vulnerability in Barracuda Service Center allows attackers to upload malicious WSDL files that bypass URL validation, leading to arbitrary file w...
📅 89 days ago • Dec 10, 2025Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats