🔥 Trending CVEs - Last 90 Days

4,406 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,120
Total CVEs Published
970
Critical Severity
3,436
High Severity
⚠️
Critical Alert
970 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-25495 8.8

This CVE describes a SQL injection vulnerability in Craft CMS affecting the element-indexes/get-elements endpoint. Attackers with Control Panel access...

📅 29 days ago • Feb 9, 2026
CVE-2026-25497 8.8

This CVE describes a privilege escalation vulnerability in Craft CMS's GraphQL API where authenticated users with write access to one asset volume can...

📅 29 days ago • Feb 9, 2026
CVE-2026-1486 8.8

This vulnerability allows attackers to bypass disabled Identity Provider (IdP) checks in Keycloak's JWT authorization grant flow. An attacker with a d...

📅 29 days ago • Feb 9, 2026
CVE-2025-10465 8.8

This vulnerability allows attackers to upload malicious files (like web shells) to Sensaway web servers without proper file type validation. It affect...

📅 29 days ago • Feb 9, 2026
CVE-2026-2202 8.8

A buffer overflow vulnerability in Tenda AC8 routers allows remote attackers to execute arbitrary code by manipulating the shareSpeed parameter in the...

📅 29 days ago • Feb 9, 2026
CVE-2026-2203 8.8

A buffer overflow vulnerability exists in Tenda AC8 routers version 16.03.33.05. Remote attackers can exploit this by sending specially crafted reques...

📅 29 days ago • Feb 9, 2026
CVE-2026-2185 8.8

A stack-based buffer overflow vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code by manipulating device name paramet...

📅 30 days ago • Feb 8, 2026
CVE-2026-2186 8.8

This vulnerability in Tenda RX3 routers allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the fromSetIpMacBind fu...

📅 30 days ago • Feb 8, 2026
CVE-2026-2187 8.8

This CVE describes a stack-based buffer overflow vulnerability in Tenda RX3 routers. Attackers can remotely exploit this vulnerability by manipulating...

📅 30 days ago • Feb 8, 2026
CVE-2026-2180 8.8

A stack-based buffer overflow vulnerability exists in Tenda RX3 routers version 16.03.13.11. Attackers can remotely exploit this by manipulating the s...

📅 30 days ago • Feb 8, 2026
CVE-2026-2181 8.8

A stack-based buffer overflow vulnerability exists in Tenda RX3 router firmware version 16.03.13.11. Attackers can remotely exploit this by manipulati...

📅 30 days ago • Feb 8, 2026
CVE-2026-2140 8.8

A buffer overflow vulnerability exists in Tenda TX9 routers through firmware version 22.03.02.10_multi. Attackers can remotely exploit this vulnerabil...

📅 30 days ago • Feb 8, 2026
CVE-2026-2139 8.8

A buffer overflow vulnerability in Tenda TX9 routers allows remote attackers to execute arbitrary code by manipulating the ssid parameter in the fast_...

📅 30 days ago • Feb 8, 2026
CVE-2026-2138 8.8

A buffer overflow vulnerability in Tenda TX9 routers allows remote attackers to execute arbitrary code by manipulating the list argument in the SetSta...

📅 30 days ago • Feb 8, 2026
CVE-2026-2137 8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda TX3 routers via a buffer overflow in the SetIpMacBind function. Attacker...

📅 30 days ago • Feb 8, 2026
CVE-2025-15100 8.8

The JAY Login & Register WordPress plugin contains a privilege escalation vulnerability that allows authenticated users with Subscriber-level access o...

📅 30 days ago • Feb 8, 2026
CVE-2026-25857 8.8

This CVE describes an OS command injection vulnerability in Tenda G300-F router firmware that allows remote attackers to execute arbitrary commands on...

📅 31 days ago • Feb 7, 2026
CVE-2026-2086 8.8

A buffer overflow vulnerability in the UTT HiPER 810G firewall's management interface allows remote attackers to execute arbitrary code or crash the d...

📅 31 days ago • Feb 7, 2026
CVE-2026-2071 8.8

A buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by exploiting the s...

📅 31 days ago • Feb 7, 2026
CVE-2026-2070 8.8

A buffer overflow vulnerability in UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by exploitin...

📅 31 days ago • Feb 6, 2026
CVE-2026-2068 8.8

This CVE describes a remote buffer overflow vulnerability in UTT 进取 520W firmware version 1.7.7-180627. Attackers can exploit this by sending spec...

📅 32 days ago • Feb 6, 2026
CVE-2026-25533 8.8

This vulnerability allows attackers to bypass multiple security layers in Enclave, a JavaScript sandbox for AI agent code execution. Attackers can esc...

📅 32 days ago • Feb 6, 2026
CVE-2026-2066 8.8

A buffer overflow vulnerability exists in the UTT 进取 520W router firmware version 1.7.7-180627, specifically in the formIpGroupConfig function. At...

📅 32 days ago • Feb 6, 2026
CVE-2026-2067 8.8

A buffer overflow vulnerability in the UTT 进取 520W router firmware version 1.7.7-180627 allows remote attackers to execute arbitrary code by manip...

📅 32 days ago • Feb 6, 2026
CVE-2025-69212 8.8

OpenSTAManager versions 2.9.8 and earlier contain a critical OS command injection vulnerability in the P7M file decoding functionality. Authenticated ...

📅 32 days ago • Feb 6, 2026
CVE-2025-69214 8.8

OpenSTAManager versions 2.9.8 and earlier contain an SQL injection vulnerability in the ajax_select.php endpoint. Authenticated attackers can execute ...

📅 32 days ago • Feb 6, 2026
CVE-2026-24851 8.8

OpenFGA versions 1.8.5 to 1.11.2 have an improper policy enforcement vulnerability that can allow unauthorized access when specific authorization mode...

📅 32 days ago • Feb 6, 2026
CVE-2025-64175 8.8

Gogs versions 0.13.3 and earlier have a critical authentication bypass vulnerability where 2FA recovery codes are not scoped to specific users. An att...

📅 32 days ago • Feb 6, 2026
CVE-2025-15566 8.8

This CVE allows attackers to inject malicious configuration into ingress-nginx via the auth-proxy-set-headers annotation, potentially leading to arbit...

📅 32 days ago • Feb 6, 2026
CVE-2025-15330 8.8

CVE-2025-15330 is an improper input validation vulnerability in Tanium Deploy that could allow attackers to execute arbitrary code or commands. This a...

📅 33 days ago • Feb 5, 2026
CVE-2025-15557 8.8

An improper certificate validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows attackers on the same network segment to intercept an...

📅 33 days ago • Feb 5, 2026
CVE-2025-69906 8.8

Monstra CMS v3.0.4 contains an arbitrary file upload vulnerability in the Files Manager plugin that allows attackers to upload malicious files to web-...

📅 33 days ago • Feb 5, 2026
CVE-2020-37117 8.8

This vulnerability allows authenticated administrators in jizhiCMS 1.6.7 to download arbitrary files from the server by exploiting the admin plugins u...

📅 33 days ago • Feb 5, 2026
CVE-2025-68722 8.8

This CSRF vulnerability in Axigen Mail Server's WebAdmin interface allows attackers to craft malicious URLs that execute administrative actions when c...

📅 33 days ago • Feb 5, 2026
CVE-2025-10314 8.8

This vulnerability allows a local attacker to replace service executable files or DLLs in the FREQSHIP-mini installation directory with malicious file...

📅 33 days ago • Feb 5, 2026
CVE-2026-25521 8.8

Locutus versions 2.0.12 through 2.0.38 contain a prototype pollution vulnerability that allows attackers to modify JavaScript object prototypes via cr...

📅 34 days ago • Feb 4, 2026
CVE-2026-25538 8.8

This vulnerability in Devtron allows any authenticated user, including low-privileged CI/CD developers, to retrieve the global API token signing key. ...

📅 34 days ago • Feb 4, 2026
CVE-2026-25512 8.8

This CVE describes a remote code execution vulnerability in Group-Office where an authenticated attacker can execute arbitrary system commands on the ...

📅 34 days ago • Feb 4, 2026
CVE-2026-25514 8.8

FacturaScripts contains a critical SQL injection vulnerability in the autocomplete functionality that allows authenticated attackers to extract sensit...

📅 34 days ago • Feb 4, 2026
CVE-2026-25513 8.8

FacturaScripts contains a critical SQL injection vulnerability in its REST API that allows authenticated API users to execute arbitrary SQL queries th...

📅 34 days ago • Feb 4, 2026
CVE-2026-25161 8.8

This path traversal vulnerability in Alist allows authenticated attackers to bypass directory-level authorization by injecting traversal sequences int...

📅 34 days ago • Feb 4, 2026
CVE-2025-69213 8.8

OpenSTAManager versions 2.9.8 and earlier contain a SQL injection vulnerability in the ajax_complete.php endpoint. Authenticated attackers can execute...

📅 34 days ago • Feb 4, 2026
CVE-2025-69215 8.8

OpenSTAManager versions 2.9.8 and earlier contain a SQL injection vulnerability in the Stampe Module that allows attackers to execute arbitrary SQL co...

📅 34 days ago • Feb 4, 2026
CVE-2026-25056 8.8

This vulnerability in n8n's Merge node allows authenticated users with workflow creation/modification permissions to write arbitrary files to the serv...

📅 34 days ago • Feb 4, 2026
CVE-2026-20098 8.8

This vulnerability in Cisco Meeting Management allows authenticated attackers with video operator privileges to upload malicious files through the web...

📅 34 days ago • Feb 4, 2026
CVE-2025-15368 8.8

The SportsPress WordPress plugin has a Local File Inclusion vulnerability in all versions up to 2.7.26. Authenticated attackers with contributor-level...

📅 34 days ago • Feb 4, 2026
CVE-2026-1819 8.8

This stored XSS vulnerability in Karel Electronics ViPort allows attackers to inject malicious scripts into web pages that are then executed when othe...

📅 34 days ago • Feb 4, 2026
CVE-2026-1756 8.8

The WP FOFT Loader WordPress plugin has a vulnerability that allows authenticated attackers with Author-level access or higher to upload arbitrary fil...

📅 34 days ago • Feb 4, 2026
CVE-2026-1580 8.8

This vulnerability in ingress-nginx allows attackers to inject malicious configuration via the auth-method annotation, leading to arbitrary code execu...

📅 34 days ago • Feb 3, 2026
CVE-2026-24512 8.8

This CVE describes a configuration injection vulnerability in ingress-nginx where attackers can inject malicious nginx configuration through the `rule...

📅 34 days ago • Feb 3, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free