🔥 Trending CVEs - Last 30 Days

1,198 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,536
Total CVEs Published
282
Critical Severity
916
High Severity
⚠️
Critical Alert
282 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-15041 7.2

This vulnerability in the BackWPup WordPress plugin allows authenticated attackers with subscriber-level access or higher to modify WordPress site opt...

📅 19 days ago • Feb 19, 2026
CVE-2025-14452 7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts via the 'wpcr3_fname' parameter in the WP Customer Reviews WordPress p...

📅 19 days ago • Feb 19, 2026
CVE-2025-12975 7.2

This vulnerability allows authenticated attackers with Shop Manager or higher WordPress roles to install arbitrary plugins via the CTX Feed plugin. Th...

📅 19 days ago • Feb 19, 2026
CVE-2026-2670 7.2

This CVE describes a remote command injection vulnerability in Advantech WISE-6610 devices. Attackers can execute arbitrary operating system commands ...

📅 19 days ago • Feb 18, 2026
CVE-2026-27177 7.2

MajorDoMo contains an unauthenticated stored XSS vulnerability that allows attackers to inject malicious JavaScript into property values. When adminis...

📅 19 days ago • Feb 18, 2026
CVE-2026-2296 7.2

This vulnerability allows authenticated attackers with Shop Manager or higher WordPress roles to execute arbitrary PHP code on the server. The flaw ex...

📅 20 days ago • Feb 18, 2026
CVE-2026-1931 7.2

The Rent Fetch WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in the 'keyword' parameter that allows unauthenticated atta...

📅 20 days ago • Feb 18, 2026
CVE-2026-2615 7.2

This CVE-2026-2615 is a command injection vulnerability in Wavlink WL-NU516U1 routers that allows remote attackers to execute arbitrary commands on af...

📅 21 days ago • Feb 17, 2026
CVE-2026-1216 7.2

The RSS Aggregator WordPress plugin is vulnerable to reflected cross-site scripting (XSS) via the 'template' parameter. Unauthenticated attackers can ...

📅 21 days ago • Feb 17, 2026
CVE-2026-2566 7.2

A remote stack-based buffer overflow vulnerability exists in Wavlink WL-NU516U1 routers through firmware version 130/260. Attackers can exploit this b...

📅 22 days ago • Feb 16, 2026
CVE-2019-25394 7.2

This stored XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript through modem.cgi POST parameters. When users acce...

📅 22 days ago • Feb 16, 2026
CVE-2019-25379 7.2

This stored and reflected XSS vulnerability in Smoothwall Express allows attackers to inject malicious JavaScript via the urlfilter.cgi endpoint. When...

📅 22 days ago • Feb 16, 2026
CVE-2026-26930 7.2

This cross-site scripting (XSS) vulnerability in SmarterMail allows attackers to inject malicious scripts via MAPI requests. It affects organizations ...

📅 22 days ago • Feb 16, 2026
CVE-2026-1843 7.2

The Super Page Cache WordPress plugin has a stored cross-site scripting vulnerability in its Activity Log feature. Unauthenticated attackers can injec...

📅 24 days ago • Feb 14, 2026
CVE-2026-0745 7.2

The User Language Switch WordPress plugin contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated administrators to make...

📅 24 days ago • Feb 14, 2026
CVE-2026-0753 7.2

This vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in victims' browsers via the 'sscf_name' parameter in the Super Si...

📅 24 days ago • Feb 14, 2026
CVE-2026-1841 7.2

The PixelYourSite WordPress plugin is vulnerable to stored cross-site scripting (XSS) via insufficient input sanitization in the 'pysTrafficSource' an...

📅 24 days ago • Feb 13, 2026
CVE-2026-1320 7.2

The Secure Copy Content Protection and Content Locking WordPress plugin is vulnerable to stored cross-site scripting (XSS) via the 'X-Forwarded-For' H...

📅 26 days ago • Feb 12, 2026
CVE-2026-1316 7.2

This stored XSS vulnerability in the Customer Reviews for WooCommerce WordPress plugin allows attackers to inject malicious scripts into web pages via...

📅 26 days ago • Feb 12, 2026
CVE-2025-15440 7.2

The iONE360 configurator WordPress plugin has a stored XSS vulnerability in its contact form parameters that allows unauthenticated attackers to injec...

📅 27 days ago • Feb 11, 2026
CVE-2025-14541 7.2

The Lucky Wheel Giveaway WordPress plugin contains a remote code execution vulnerability in all versions up to 1.0.22. Authenticated attackers with Ad...

📅 27 days ago • Feb 11, 2026
CVE-2026-1866 7.2

The Name Directory WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts via public submis...

📅 28 days ago • Feb 10, 2026
CVE-2026-2260 7.2

This CVE describes a remote command injection vulnerability in D-Link DCS-931L IP cameras. Attackers can execute arbitrary operating system commands b...

📅 28 days ago • Feb 10, 2026
CVE-2026-0845 7.2

This vulnerability allows authenticated attackers with Shop Manager or higher privileges in WordPress to modify arbitrary site options due to missing ...

📅 28 days ago • Feb 10, 2026
CVE-2026-25951 7.2

CVE-2026-25951 is a path traversal vulnerability in FUXA web-based SCADA/HMI software that allows authenticated administrators to bypass directory pro...

📅 28 days ago • Feb 9, 2026
CVE-2026-25498 7.2

This is a Remote Code Execution vulnerability in Craft CMS that allows authenticated administrators to execute arbitrary system commands on the server...

📅 29 days ago • Feb 9, 2026
CVE-2026-2210 7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by m...

📅 29 days ago • Feb 9, 2026
CVE-2026-2191 7.2

A stack-based buffer overflow vulnerability exists in Tenda AC9 routers running firmware version 15.03.06.42_multi. Remote attackers can exploit this ...

📅 29 days ago • Feb 8, 2026
CVE-2026-2192 7.2

This CVE describes a stack-based buffer overflow vulnerability in Tenda AC9 routers' formGetRebootTimer function. Attackers can exploit this remotely ...

📅 29 days ago • Feb 8, 2026
CVE-2026-2188 7.2

This vulnerability allows remote attackers to execute arbitrary operating system commands on UTT 进取 521G devices through command injection in the ...

📅 29 days ago • Feb 8, 2026
CVE-2026-30926 7.1

A privilege escalation vulnerability in SiYuan Note's publish service allows authenticated users with read-only publish accounts (RoleReader) to modif...

🔥 Today • Mar 10, 2026
CVE-2026-28494 7.1

A stack buffer overflow vulnerability in ImageMagick's morphology kernel parsing functions allows attackers to corrupt the stack by providing speciall...

🔥 Today • Mar 10, 2026
CVE-2026-29778 7.1

This vulnerability in pyLoad allows attackers to bypass directory traversal protections in the edit_package() function using recursive path sequences ...

📅 3 days ago • Mar 7, 2026
CVE-2018-25191 7.1

Facturation System 1.0 contains an SQL injection vulnerability in the editar_producto.php endpoint that allows authenticated attackers to execute arbi...

📅 4 days ago • Mar 6, 2026
CVE-2018-25180 7.1

Maitra 1.7.2 contains an SQL injection vulnerability in the mailid parameter of outmail and inmail modules, allowing authenticated attackers to execut...

📅 4 days ago • Mar 6, 2026
CVE-2018-25165 7.1

Galaxy Forces MMORPG 0.5.8 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries through the 't...

📅 4 days ago • Mar 6, 2026
CVE-2026-28713 7.1

This vulnerability involves default credentials for a local privileged user in Acronis Cyber Protect virtual appliances. Attackers can gain administra...

📅 4 days ago • Mar 6, 2026
CVE-2026-28482 7.1

OpenClaw versions before 2026.2.12 have a path traversal vulnerability where authenticated attackers can use unsanitized sessionId or sessionFile para...

📅 4 days ago • Mar 5, 2026
CVE-2026-28477 7.1

OpenClaw versions before 2026.2.14 have an OAuth state validation bypass in the manual Chutes login flow that allows attackers to bypass CSRF protecti...

📅 4 days ago • Mar 5, 2026
CVE-2026-28459 7.1

OpenClaw versions before 2026.2.12 have an arbitrary file write vulnerability where authenticated gateway clients can manipulate the sessionFile path ...

📅 4 days ago • Mar 5, 2026
CVE-2026-29077 7.1

This vulnerability in Frappe framework allows authenticated users to share documents with permissions they don't possess, potentially granting unautho...

📅 5 days ago • Mar 5, 2026
CVE-2026-28548 7.1

This CVE describes an improper verification vulnerability in Huawei email applications that could allow attackers to access sensitive information. The...

📅 5 days ago • Mar 5, 2026
CVE-2019-25503 7.1

CVE-2019-25503 is an unauthenticated SQL injection vulnerability in PHPads 2.0 that allows attackers to execute arbitrary SQL queries through the bann...

📅 6 days ago • Mar 4, 2026
CVE-2019-25505 7.1

Tradebox 5.4 contains an SQL injection vulnerability in the monthly_deposit endpoint's symbol parameter that allows authenticated attackers to execute...

📅 6 days ago • Mar 4, 2026
CVE-2026-1567 7.1

This XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server allows attackers to read sensitive files from the server by exploiti...

📅 7 days ago • Mar 3, 2026
CVE-2025-64427 7.1

This vulnerability allows authenticated local users in ZimaOS to craft requests targeting internal IP addresses and services, potentially accessing HT...

📅 8 days ago • Mar 2, 2026
CVE-2025-47378 7.1

This cryptographic vulnerability in Qualcomm chipsets allows the High-Level Operating System (HLOS) to access the boot loader's certificate chain thro...

📅 8 days ago • Mar 2, 2026
CVE-2026-27967 7.1

Zed code editor versions before 0.225.9 have a symlink escape vulnerability that allows reading and writing files outside the project directory when s...

📅 12 days ago • Feb 26, 2026
CVE-2026-27692 7.1

A heap buffer overflow vulnerability in iccDEV allows reading past allocated memory boundaries when parsing ICC profile XML text description tags. Thi...

📅 13 days ago • Feb 25, 2026
CVE-2026-26103 7.1

A local privilege escalation vulnerability in udisks allows unprivileged users to trigger the root-owned daemon to overwrite LUKS encryption headers. ...

📅 13 days ago • Feb 25, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free