🔥 Trending CVEs - Last 90 Days

4,470 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,278
Total CVEs Published
986
Critical Severity
3,484
High Severity
⚠️
Critical Alert
986 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2024-58041 9.1

Smolder versions through 1.51 for Perl use the non-cryptographically secure rand() function for cryptographic operations, making generated values pred...

📅 14 days ago • Feb 24, 2026
CVE-2026-3061 9.1

This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's media component by tricking a user into visiting a ...

📅 14 days ago • Feb 23, 2026
CVE-2025-70043 9.1

This vulnerability in Ayms node-To master branch disables TLS/SSL certificate validation, allowing man-in-the-middle attackers to intercept and manipu...

📅 14 days ago • Feb 23, 2026
CVE-2026-23552 9.1

The CVE-2026-23552 vulnerability allows attackers to bypass tenant isolation in Apache Camel Keycloak component by using JWT tokens from unauthorized ...

📅 15 days ago • Feb 23, 2026
CVE-2026-2588 9.1

This CVE describes an integer overflow vulnerability in Crypt::NaCl::Sodium Perl module versions through 2.001 on 32-bit systems. The flaw occurs when...

📅 15 days ago • Feb 23, 2026
CVE-2026-27197 9.1

This critical vulnerability in Sentry's SAML SSO implementation allows attackers to take over any user account by exploiting misconfigured multi-organ...

📅 17 days ago • Feb 21, 2026
CVE-2019-25444 9.1

This SQL injection vulnerability in Fiverr Clone Script 1.2.2 allows unauthenticated attackers to inject malicious SQL code through the page parameter...

📅 17 days ago • Feb 20, 2026
CVE-2026-26988 9.1

This SQL injection vulnerability in LibreNMS allows attackers to execute arbitrary SQL commands through the ajax_table.php endpoint when searching IPv...

📅 18 days ago • Feb 20, 2026
CVE-2025-55853 9.1

SoftVision webPDF versions before 10.0.2 contain a Server-Side Request Forgery (SSRF) vulnerability in the PDF converter function. Attackers can uploa...

📅 18 days ago • Feb 19, 2026
CVE-2026-25548 9.1

InvoicePlane 1.7.0 contains a critical Remote Code Execution vulnerability that allows authenticated administrators to execute arbitrary system comman...

📅 19 days ago • Feb 18, 2026
CVE-2025-70146 9.1

This vulnerability allows remote attackers to perform administrative operations without authentication in ProjectWorlds Online Time Table Generator 1....

📅 19 days ago • Feb 18, 2026
CVE-2026-25227 9.1

This vulnerability in authentik allows authenticated users with specific delegated permissions to execute arbitrary code on the authentik server conta...

📅 25 days ago • Feb 12, 2026
CVE-2026-25939 9.1

An authorization bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to create and modify arbitrary sche...

📅 28 days ago • Feb 9, 2026
CVE-2026-25811 9.1

PlaciPy placement management system version 1.0.0 allows cross-tenant data access by deriving tenant identifiers from user-provided email domains with...

📅 28 days ago • Feb 9, 2026
CVE-2026-25810 9.1

PlaciPy placement management system version 1.0.0 has an authorization vulnerability where authenticated users can access other users' student submiss...

📅 28 days ago • Feb 9, 2026
CVE-2026-25876 9.1

PlaciPy placement management system version 1.0.0 has a missing object-level authorization vulnerability that allows authenticated users to access ass...

📅 28 days ago • Feb 9, 2026
CVE-2026-25057 9.1

This vulnerability allows instructors to achieve arbitrary file write on the server by uploading specially crafted zip files. Attackers could write ma...

📅 28 days ago • Feb 9, 2026
CVE-2026-25848 9.1

This authentication bypass vulnerability in JetBrains Hub allows attackers to perform administrative actions without proper credentials. All organizat...

📅 29 days ago • Feb 9, 2026
CVE-2026-2234 9.1

CVE-2026-2234 is a missing authentication vulnerability in HGiga's C&Cm@il software that allows unauthenticated remote attackers to read and modify an...

📅 29 days ago • Feb 9, 2026
CVE-2026-25804 9.1

This vulnerability in Antrea's network policy priority assignment system causes incorrect traffic enforcement due to a uint16 arithmetic overflow when...

📅 31 days ago • Feb 6, 2026
CVE-2026-25643 9.1

CVE-2026-25643 is a critical Remote Command Execution vulnerability in Frigate NVR software that allows attackers to execute arbitrary system commands...

📅 31 days ago • Feb 6, 2026
CVE-2026-25722 9.1

CVE-2026-25722 is a directory traversal vulnerability in Claude Code that allows attackers to bypass write protection in sensitive directories like .c...

📅 31 days ago • Feb 6, 2026
CVE-2019-25298 9.1

CVE-2019-25298 is an SQL injection vulnerability in html5_snmp 1.11 that allows attackers to manipulate database queries through Router_ID and Router_...

📅 31 days ago • Feb 6, 2026
CVE-2026-25539 9.1

This vulnerability allows authenticated users of SiYuan personal knowledge management system to write files to arbitrary locations on the filesystem d...

📅 33 days ago • Feb 4, 2026
CVE-2026-25160 9.1

Alist file list program versions before 3.57.0 disable TLS certificate verification by default for all outgoing storage communications, making all dat...

📅 33 days ago • Feb 4, 2026
CVE-2026-25139 9.1

CVE-2026-25139 is an out-of-bounds read vulnerability in RIOT OS's 6LoWPAN stack that allows unauthenticated attackers to read adjacent memory or cras...

📅 33 days ago • Feb 4, 2026
CVE-2026-1632 9.1

MOMA Seismic Station versions v2.4.2520 and earlier expose their web management interface without requiring authentication. This allows unauthenticate...

📅 34 days ago • Feb 3, 2026
CVE-2026-25233 9.1

This vulnerability in PEAR (PHP Extension and Application Repository) allows non-lead maintainers to create, update, or delete roadmaps due to a logic...

📅 34 days ago • Feb 3, 2026
CVE-2026-25137 9.1

The NixOS Odoo package exposes the database manager without authentication, allowing unauthorized actors to delete or download the entire database and...

📅 35 days ago • Feb 2, 2026
CVE-2024-5986 9.1

This vulnerability in h2o-3 allows remote attackers to write arbitrary data to any file on the server, potentially leading to remote code execution an...

📅 36 days ago • Feb 2, 2026
CVE-2026-22806 9.1

This vulnerability in vCluster Platform allows users with scoped access keys to bypass scope restrictions and access resources outside their intended ...

📅 39 days ago • Jan 29, 2026
CVE-2025-69602 9.1

A session fixation vulnerability in 66biolinks v62.0.0 allows attackers to hijack authenticated user sessions by setting or predicting session IDs bef...

📅 40 days ago • Jan 28, 2026
CVE-2025-57794 9.1

Explorance Blue versions before 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. This allows at...

📅 40 days ago • Jan 28, 2026
CVE-2026-24838 9.1

This vulnerability allows attackers to inject malicious scripts into DNN module titles, which execute in users' browsers when viewing affected pages. ...

📅 41 days ago • Jan 28, 2026
CVE-2026-24785 9.1

Clatter versions before 2.2.0 have a protocol compliance vulnerability where post-quantum handshake patterns violate the PSK validity rule, allowing P...

📅 41 days ago • Jan 28, 2026
CVE-2026-24736 9.1

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Squidex's webhook functionality that allows attackers to make the server send...

📅 41 days ago • Jan 27, 2026
CVE-2026-24874 9.1

This is a type confusion vulnerability in the xray-monolith software that allows attackers to access memory with incompatible types, potentially leadi...

📅 41 days ago • Jan 27, 2026
CVE-2025-68670 9.1

CVE-2025-68670 is an unauthenticated stack-based buffer overflow vulnerability in xrdp (open source RDP server) that allows remote attackers to execut...

📅 41 days ago • Jan 27, 2026
CVE-2026-24346 9.1

This vulnerability allows attackers to access protected administrative areas of the EZCast Pro II web application using well-known default credentials...

📅 42 days ago • Jan 27, 2026
CVE-2026-24400 9.1

This XXE vulnerability in AssertJ allows attackers to read local files, perform SSRF attacks, or cause denial of service when untrusted XML is process...

📅 42 days ago • Jan 26, 2026
CVE-2025-70985 9.1

This vulnerability in RuoYi v4.8.2 allows unauthorized attackers to modify data they shouldn't have access to due to improper access control in the up...

📅 45 days ago • Jan 23, 2026
CVE-2025-66719 9.1

This vulnerability in Free5gc NRF 1.4.0 allows attackers to bypass scope validation during access token generation by using a crafted targetNF value. ...

📅 45 days ago • Jan 23, 2026
CVE-2026-20912 9.1

Gitea versions before 1.25.4 have an improper access control vulnerability where attachments uploaded to private repositories can be linked to release...

📅 46 days ago • Jan 22, 2026
CVE-2026-20897 9.1

CVE-2026-20897 is an improper access control vulnerability in Gitea where users with write access to any repository can delete Git LFS locks belonging...

📅 46 days ago • Jan 22, 2026
CVE-2026-20750 9.1

Gitea contains an authorization bypass vulnerability where users with project write access in one organization can modify projects belonging to other ...

📅 46 days ago • Jan 22, 2026
CVE-2026-24379 9.1

This CVE describes an authorization bypass vulnerability in the WP Job Portal WordPress plugin where attackers can manipulate user-controlled keys to ...

📅 46 days ago • Jan 22, 2026
CVE-2026-22482 9.1

This SSRF vulnerability in wbolt.com IMGspider WordPress plugin allows attackers to make the server send unauthorized requests to internal or external...

📅 46 days ago • Jan 22, 2026
CVE-2025-69312 9.1

This vulnerability allows attackers to upload arbitrary files, including web shells, to WordPress sites using the Xpro Elementor Addons plugin. Attack...

📅 46 days ago • Jan 22, 2026
CVE-2025-67944 9.1

This vulnerability allows attackers to execute arbitrary code on WordPress sites running the vulnerable Nelio AB Testing plugin. Attackers can inject ...

📅 46 days ago • Jan 22, 2026
CVE-2025-62741 9.1

This SSRF vulnerability in the Pool Services WordPress theme allows attackers to make unauthorized requests from the vulnerable server to internal or ...

📅 46 days ago • Jan 22, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free