🔥 Trending CVEs - Last 90 Days

4,466 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,272
Total CVEs Published
986
Critical Severity
3,480
High Severity
⚠️
Critical Alert
986 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-62754 9.1

This CVE describes a Missing Authorization vulnerability in the Payment Gateway bKash for WC WordPress plugin that allows attackers to bypass access c...

📅 46 days ago • Jan 22, 2026
CVE-2026-23966 9.1

A private key recovery vulnerability exists in sm-crypto's SM2 decryption implementation, allowing attackers to fully extract private keys through sev...

📅 47 days ago • Jan 22, 2026
CVE-2025-55130 9.1

A Node.js permissions model vulnerability allows attackers to bypass file system access restrictions using crafted relative symlink paths. This enable...

📅 48 days ago • Jan 20, 2026
CVE-2026-23722 9.1

This is a reflected cross-site scripting (XSS) vulnerability in WeGIA web management software that allows unauthenticated attackers to inject maliciou...

📅 52 days ago • Jan 16, 2026
CVE-2025-67647 9.1

SvelteKit versions 2.19.0 through 2.49.4 are vulnerable to server-side request forgery (SSRF) and denial of service (DoS) attacks. The vulnerability a...

📅 53 days ago • Jan 15, 2026
CVE-2026-22908 9.1

This vulnerability allows remote attackers to gain full system access by uploading unvalidated container images to affected systems. It compromises bo...

📅 54 days ago • Jan 15, 2026
CVE-2026-22855 9.1

A heap out-of-bounds read vulnerability in FreeRDP's smartcard SetAttrib path allows attackers to read memory beyond allocated buffers. This affects F...

📅 54 days ago • Jan 14, 2026
CVE-2026-22858 9.1

This CVE describes a global buffer overflow vulnerability in FreeRDP's Base64 decoding implementation. On Arm/AArch64 architectures, signedness issues...

📅 54 days ago • Jan 14, 2026
CVE-2026-22859 9.1

This vulnerability in FreeRDP allows remote attackers to cause an out-of-bounds read by sending specially crafted MSUSB_INTERFACE_DESCRIPTOR values. T...

📅 54 days ago • Jan 14, 2026
CVE-2023-54337 9.1

Sysax Multi Server 6.95 contains a denial of service vulnerability where attackers can crash the application by sending 800 bytes of repeated characte...

📅 55 days ago • Jan 13, 2026
CVE-2025-25176 9.1

This vulnerability allows non-secure applications to exfiltrate intermediate register values from secure workloads, potentially exposing sensitive dat...

📅 55 days ago • Jan 13, 2026
CVE-2025-11250 9.1

This authentication bypass vulnerability in ManageEngine ADSelfService Plus allows attackers to circumvent login protections and gain unauthorized acc...

📅 56 days ago • Jan 13, 2026
CVE-2025-14829 9.1

The E-xact Hosted Payment WordPress plugin through version 2.0 contains an arbitrary file deletion vulnerability due to insufficient file path validat...

📅 56 days ago • Jan 13, 2026
CVE-2026-22252 9.1

This critical vulnerability in LibreChat allows authenticated users to execute arbitrary shell commands as root within the container via a single API ...

📅 56 days ago • Jan 12, 2026
CVE-2025-14741 9.1

The Frontend Admin by DynamiApps WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to delete any conten...

📅 60 days ago • Jan 9, 2026
CVE-2025-61546 9.1

This vulnerability in Print Shop Pro WebDesk allows remote attackers to purchase items with negative quantities, creating financial discrepancies by m...

📅 60 days ago • Jan 8, 2026
CVE-2025-56425 9.1

This vulnerability allows authenticated remote attackers to inject arbitrary SMTP commands via crafted input to the /osrest/api/organization/sendmail ...

📅 60 days ago • Jan 8, 2026
CVE-2025-22726 9.1

This SSRF vulnerability in the nK Themes Helper WordPress plugin allows attackers to make the vulnerable server send unauthorized requests to internal...

📅 61 days ago • Jan 8, 2026
CVE-2026-21881 9.1

This critical authentication bypass vulnerability in Kanboard allows attackers to impersonate any user, including administrators, by sending spoofed H...

📅 61 days ago • Jan 8, 2026
CVE-2025-69222 9.1

LibreChat version 0.8.1-rc2 has a server-side request forgery (SSRF) vulnerability in its Actions feature that allows attackers to make unauthorized r...

📅 61 days ago • Jan 7, 2026
CVE-2025-68637 9.1

This vulnerability allows attackers to perform Man-in-the-Middle attacks on all REST API communications between Uniffle CLI/client and Coordinator ser...

📅 62 days ago • Jan 7, 2026
CVE-2025-68456 9.1

Unauthenticated attackers can trigger database backup operations in vulnerable Craft CMS versions, potentially causing resource exhaustion or exposing...

📅 63 days ago • Jan 5, 2026
CVE-2025-67397 9.1

CVE-2025-67397 is a command injection vulnerability in Passy v1.6.3 that allows authenticated remote attackers to execute arbitrary commands on affect...

📅 63 days ago • Jan 5, 2026
CVE-2025-27807 9.1

A critical vulnerability in multiple Samsung Exynos processors allows attackers to execute arbitrary code or cause denial of service via malformed NAS...

📅 63 days ago • Jan 5, 2026
CVE-2026-21445 9.1

CVE-2026-21445 is a critical authentication bypass vulnerability in Langflow that allows unauthenticated attackers to access sensitive user conversati...

📅 66 days ago • Jan 2, 2026
CVE-2025-68620 9.1

Signal K Server versions before 2.19.0 allow unauthenticated attackers to steal JWT authentication tokens through two chained vulnerabilities: unauthe...

📅 67 days ago • Jan 1, 2026
CVE-2025-69288 9.1

This vulnerability allows any authenticated admin user in Titra time tracking software to execute arbitrary code on the server by manipulating timeEnt...

📅 68 days ago • Dec 31, 2025
CVE-2025-56332 9.1

CVE-2025-56332 is an authentication bypass vulnerability in fosrl/pangolin v1.6.2 and earlier that allows attackers to access protected resources due ...

📅 69 days ago • Dec 30, 2025
CVE-2025-15359 9.1

This vulnerability in Delta Electronics DVP-12SE11T PLC modules allows attackers to write data beyond allocated memory boundaries, potentially leading...

📅 70 days ago • Dec 30, 2025
CVE-2025-15102 9.1

CVE-2025-15102 is a password protection bypass vulnerability in Delta Electronics DVP-12SE11T PLC modules. Attackers can bypass authentication mechani...

📅 70 days ago • Dec 30, 2025
CVE-2025-69234 9.1

This vulnerability in Whale browser allows attackers to escape iframe sandbox restrictions in sidebar environments, potentially executing malicious co...

📅 70 days ago • Dec 30, 2025
CVE-2024-25181 9.1

CVE-2024-25181 is a critical vulnerability in givanz VvvebJs 1.7.2 that allows attackers to perform Server-Side Request Forgery (SSRF) and read arbitr...

📅 70 days ago • Dec 29, 2025
CVE-2025-68916 9.1

This vulnerability allows attackers to perform directory traversal through the certsupload.cgi endpoint in Riello UPS NetMan 208 Application, enabling...

📅 75 days ago • Dec 24, 2025
CVE-2025-68600 9.1

This Server-Side Request Forgery (SSRF) vulnerability in the Link Library WordPress plugin allows attackers to make unauthorized requests from the vul...

📅 76 days ago • Dec 24, 2025
CVE-2025-68535 9.1

This CVE describes a missing authorization vulnerability in the Sunshine Photo Cart WordPress plugin that allows attackers to bypass access controls. ...

📅 76 days ago • Dec 24, 2025
CVE-2025-68500 9.1

This SSRF vulnerability in the bdthemes Prime Slider WordPress plugin allows attackers to make unauthorized requests from the vulnerable server to int...

📅 76 days ago • Dec 24, 2025
CVE-2025-68508 9.1

This CVE describes a missing authorization vulnerability in the Brave Popup Builder WordPress plugin that allows attackers to bypass access controls. ...

📅 76 days ago • Dec 24, 2025
CVE-2025-68511 9.1

This CVE describes a missing authorization vulnerability in the Gutenverse Form WordPress plugin that allows attackers to bypass access controls. It a...

📅 76 days ago • Dec 24, 2025
CVE-2025-67623 9.1

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in the 6Storage Rentals WordPress plugin. Attackers can exploit this to make the...

📅 76 days ago • Dec 24, 2025
CVE-2025-1928 9.1

This vulnerability allows attackers to bypass password recovery rate limiting in Restajet's Online Food Delivery System, enabling brute-force attacks ...

📅 81 days ago • Dec 19, 2025
CVE-2025-68398 9.1

This vulnerability in Weblate allows remote attackers to overwrite Git configuration settings, potentially altering Git behavior and enabling further ...

📅 81 days ago • Dec 18, 2025
CVE-2025-34449 9.1

A buffer overflow vulnerability in scrcpy allows a compromised Android device to send crafted messages that cause memory corruption on the host system...

📅 81 days ago • Dec 18, 2025
CVE-2025-63386 9.1

A CORS misconfiguration in Dify v1.9.1 allows arbitrary external domains to make authenticated requests to the /console/api/setup endpoint. This enabl...

📅 81 days ago • Dec 18, 2025
CVE-2025-63388 9.1

This CVE describes a CORS misconfiguration in Dify v1.9.1 that allows any external domain to make authenticated cross-origin requests to the /console/...

📅 81 days ago • Dec 18, 2025
CVE-2025-66078 9.1

This vulnerability allows remote attackers to execute arbitrary code on WordPress sites running the Hotel Booking Lite plugin. Attackers can inject ma...

📅 82 days ago • Dec 18, 2025
CVE-2025-68435 9.1

Zerobyte backup automation tool versions before 0.18.5 and 0.19.0 have an authentication bypass vulnerability where certain API endpoints don't proper...

📅 82 days ago • Dec 17, 2025
CVE-2025-68118 9.1

This vulnerability in FreeRDP allows attackers to cause heap-based out-of-bounds memory reads by controlling hostnames in certificate cache filenames....

📅 82 days ago • Dec 17, 2025
CVE-2025-68109 9.1

ChurchCRM versions before 6.5.3 have a critical vulnerability in the Database Restore functionality that allows attackers to upload malicious files wi...

📅 82 days ago • Dec 17, 2025
CVE-2025-34434 9.1

AVideo versions before 20.1 with the ImageGallery plugin enabled are vulnerable to unauthenticated file upload and deletion. Attackers can upload mali...

📅 82 days ago • Dec 17, 2025
CVE-2025-65318 9.1

Canary Mail versions 5.1.40 and below fail to apply Mark-of-the-Web (MOTW) tags to downloaded attachments, allowing attackers to bypass Windows and th...

📅 83 days ago • Dec 16, 2025

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free