🔥 Trending CVEs - Last 7 Days

191 critical and high-severity vulnerabilities discovered in the last 7 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
338
Total CVEs Published
42
Critical Severity
149
High Severity
⚠️
Critical Alert
42 critical vulnerabilities published in the last 7 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-3539 8.8

This vulnerability allows attackers to exploit heap corruption in Google Chrome's DevTools through malicious extensions. Users who install untrusted C...

📅 2 days ago • Mar 4, 2026
CVE-2026-24502 8.8

Dell Command | Intel vPro Out of Band versions before 4.7.0 have a path traversal vulnerability that allows local low-privileged attackers to execute ...

📅 3 days ago • Mar 3, 2026
CVE-2025-12345 8.8

A remote buffer overflow vulnerability in LLM-Claw's agent deployment component allows attackers to execute arbitrary code or crash the system. This a...

📅 3 days ago • Mar 3, 2026
CVE-2026-1566 8.8

This vulnerability allows authenticated attackers with Agent-level access in the LatePoint WordPress plugin to escalate privileges by linking customer...

📅 4 days ago • Mar 3, 2026
CVE-2026-21853 8.8

This CVE describes a one-click remote code execution vulnerability in AFFiNE workspace software. Attackers can exploit it by tricking users into visit...

📅 4 days ago • Mar 2, 2026
CVE-2026-3132 8.8

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to execute arbitrary code on servers running the Master...

📅 4 days ago • Mar 2, 2026
CVE-2025-52468 8.8

This vulnerability allows attackers to inject malicious scripts into Chamilo LMS user profiles via CSV import. When other users view these profiles, t...

📅 4 days ago • Mar 2, 2026
CVE-2026-3400 8.8

A stack-based buffer overflow vulnerability in Tenda AC15 routers allows remote attackers to execute arbitrary code by manipulating the wpapsk_crypto2...

📅 5 days ago • Mar 2, 2026
CVE-2026-3399 8.8

A buffer overflow vulnerability in Tenda F453 routers allows remote attackers to execute arbitrary code or cause denial of service by sending speciall...

📅 5 days ago • Mar 1, 2026
CVE-2026-3398 8.8

A buffer overflow vulnerability in Tenda F453 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the h...

📅 5 days ago • Mar 1, 2026
CVE-2026-3380 8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda F453 routers by exploiting a buffer overflow in the frmL7ImForm function...

📅 6 days ago • Mar 1, 2026
CVE-2026-3378 8.8

CVE-2026-3378 is a remote buffer overflow vulnerability in Tenda F453 routers affecting the qossetting function. Attackers can exploit this flaw remot...

📅 6 days ago • Mar 1, 2026
CVE-2026-3377 8.8

A buffer overflow vulnerability in Tenda F453 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the fr...

📅 6 days ago • Mar 1, 2026
CVE-2026-3376 8.8

A buffer overflow vulnerability in Tenda F453 routers allows remote attackers to execute arbitrary code by manipulating the 'page' parameter in the Sa...

📅 6 days ago • Feb 28, 2026
CVE-2026-28683 8.7

This vulnerability allows authenticated attackers to upload malicious SVG files and create hotlinks that execute stored cross-site scripting (XSS) att...

🔥 Today • Mar 6, 2026
CVE-2026-26022 8.7

This stored XSS vulnerability in Gogs allows authenticated users to inject malicious JavaScript via data: URIs in comments and issue descriptions. The...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28679 8.6

CVE-2026-28679 is a path traversal vulnerability in Home-Gallery.org that allows attackers to download sensitive system files outside the intended med...

🔥 Today • Mar 6, 2026
CVE-2026-26125 8.6

This vulnerability allows attackers to elevate privileges in Payment Orchestrator Service, potentially gaining unauthorized access to payment processi...

⚡ Yesterday • Mar 5, 2026
CVE-2026-0847 8.6

This vulnerability in NLTK allows attackers to read arbitrary files on the server through path traversal attacks in multiple CorpusReader classes. It ...

📅 2 days ago • Mar 4, 2026
CVE-2026-20103 8.6

An unauthenticated remote attacker can send crafted packets to Cisco ASA/FTD Remote Access SSL VPN servers to exhaust device memory, causing denial of...

📅 2 days ago • Mar 4, 2026
CVE-2026-20039 8.6

An unauthenticated remote attacker can cause Cisco ASA/FTD firewall devices to reload by sending crafted HTTP requests to the VPN web server, resultin...

📅 2 days ago • Mar 4, 2026
CVE-2026-30242 8.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Plane project management software. Attackers with workspace ADMIN privileges ...

🔥 Today • Mar 6, 2026
CVE-2026-28442 8.5

CVE-2026-28442 allows authenticated users to delete critical system files in ZimaOS by manipulating API requests, bypassing frontend restrictions. Thi...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28286 8.5

This vulnerability allows attackers to bypass frontend restrictions and create files or directories in sensitive system locations like /etc and /usr v...

📅 4 days ago • Mar 2, 2026
CVE-2026-21882 8.4

CVE-2026-21882 is a local privilege escalation vulnerability in theshit command-line utility that allows attackers to gain root privileges by exploiti...

📅 4 days ago • Mar 2, 2026
CVE-2026-28476 8.3

OpenClaw versions before 2026.2.14 contain a server-side request forgery vulnerability in the Tlon Urbit extension. Attackers who can influence the co...

⚡ Yesterday • Mar 5, 2026
CVE-2026-27802 8.3

This vulnerability allows managers in Vaultwarden to escalate their privileges by modifying permissions for collections they shouldn't have access to....

📅 2 days ago • Mar 4, 2026
CVE-2025-52482 8.3

A stored cross-site scripting (XSS) vulnerability in Chamilo LMS allows teachers to inject malicious JavaScript into the glossary function, which exec...

📅 4 days ago • Mar 2, 2026
CVE-2026-29064 8.2

A path traversal vulnerability in Zarf's archive extraction allows malicious packages to create symlinks pointing outside the destination directory, e...

🔥 Today • Mar 6, 2026
CVE-2018-25199 8.2

OOP CMS BLOG 1.0 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries through search,...

🔥 Today • Mar 6, 2026
CVE-2018-25196 8.2

CVE-2018-25196 is an SQL injection vulnerability in ServerZilla 1.0 that allows unauthenticated attackers to manipulate database queries through the e...

🔥 Today • Mar 6, 2026
CVE-2018-25187 8.2

CVE-2018-25187 allows unauthenticated attackers to directly download the kim.db database file containing user credentials and password hashes, and exe...

🔥 Today • Mar 6, 2026
CVE-2018-25189 8.2

CVE-2018-25189 is an SQL injection vulnerability in Data Center Audit 2.6.2 that allows unauthenticated attackers to execute arbitrary SQL queries thr...

🔥 Today • Mar 6, 2026
CVE-2018-25182 8.2

CVE-2018-25182 is an SQL injection vulnerability in Silurus Classifieds Script 2.0 that allows unauthenticated attackers to execute arbitrary SQL quer...

🔥 Today • Mar 6, 2026
CVE-2018-25175 8.2

CVE-2018-25175 is an SQL injection vulnerability in Alienor Web Libre 2.0 that allows unauthenticated attackers to execute arbitrary SQL queries throu...

🔥 Today • Mar 6, 2026
CVE-2018-25171 8.2

CVE-2018-25171 is an unauthenticated SQL injection vulnerability in EdTv 2 that allows attackers to execute arbitrary SQL queries through the 'id' par...

🔥 Today • Mar 6, 2026
CVE-2018-25173 8.2

Rmedia SMS 1.0 contains an unauthenticated SQL injection vulnerability in the editgrp.php endpoint. Attackers can extract database schema information ...

🔥 Today • Mar 6, 2026
CVE-2018-25167 8.2

CVE-2018-25167 is an SQL injection vulnerability in Net-Billetterie 2.9 that allows unauthenticated attackers to execute arbitrary SQL queries through...

🔥 Today • Mar 6, 2026
CVE-2018-25163 8.2

CVE-2018-25163 is an SQL injection vulnerability in BitZoom 1.0 that allows unauthenticated attackers to execute arbitrary SQL queries through the rol...

🔥 Today • Mar 6, 2026
CVE-2018-25161 8.2

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability in SearchCustomer.php that allows attackers to execute arbitrary SQL queries ...

🔥 Today • Mar 6, 2026
CVE-2026-28787 8.2

This vulnerability in OneUptime allows attackers to bypass two-factor authentication by replaying stolen WebAuthn assertions. The flaw occurs because ...

🔥 Today • Mar 6, 2026
CVE-2019-25507 8.2

Ashop Shopping Cart Software contains an unauthenticated SQL injection vulnerability in the 'shop' parameter of index.php. Attackers can extract sensi...

📅 2 days ago • Mar 4, 2026
CVE-2019-25498 8.2

Simple Job Script contains an unauthenticated SQL injection vulnerability in the landing_location parameter of the searched endpoint. Attackers can se...

📅 2 days ago • Mar 4, 2026
CVE-2019-25500 8.2

Simple Job Script contains an unauthenticated SQL injection vulnerability in the register-recruiters endpoint via the employerid parameter. Attackers ...

📅 2 days ago • Mar 4, 2026
CVE-2026-28562 8.2

CVE-2026-28562 is an unauthenticated SQL injection vulnerability in wpForo WordPress plugin versions 2.4.14 and earlier. Attackers can exploit the wpf...

📅 6 days ago • Feb 28, 2026
CVE-2026-29091 8.1

This vulnerability allows remote code execution in applications using Locutus library versions before 3.0.0. Attackers can inject arbitrary JavaScript...

🔥 Today • Mar 6, 2026
CVE-2026-29093 8.1

This vulnerability exposes memcached session storage without authentication in WWBN AVideo's Docker configuration, allowing attackers to hijack sessio...

⚡ Yesterday • Mar 6, 2026
CVE-2025-59541 8.1

This CSRF vulnerability in Chamilo LMS allows attackers to trick authenticated trainers into deleting projects within courses without their consent. T...

⚡ Yesterday • Mar 6, 2026
CVE-2026-28710 8.1

CVE-2026-28710 allows attackers to access and manipulate sensitive information in Acronis Cyber Protect 17 due to improper authentication. This affect...

⚡ Yesterday • Mar 6, 2026
CVE-2026-28472 8.1

OpenClaw versions before 2026.2.2 have an authentication bypass vulnerability in the WebSocket gateway connection handshake. Attackers can connect wit...

⚡ Yesterday • Mar 5, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free