🔥 Trending CVEs - Last 30 Days

1,268 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,796
Total CVEs Published
306
Critical Severity
962
High Severity
⚠️
Critical Alert
306 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-2764 9.8

This CVE describes a use-after-free vulnerability in Firefox's JavaScript JIT compiler that could allow arbitrary code execution. It affects Firefox v...

📅 10 days ago • Feb 24, 2026
CVE-2026-2766 9.8

A use-after-free vulnerability in Firefox's JavaScript JIT engine allows attackers to execute arbitrary code by tricking users into visiting malicious...

📅 10 days ago • Feb 24, 2026
CVE-2026-2634 9.8

This vulnerability in Firefox for iOS allows malicious scripts to desynchronize the address bar from actual web content before a server response arriv...

📅 10 days ago • Feb 24, 2026
CVE-2025-14577 9.8

Slican NCP/IPL/IPM/IPU devices contain a PHP function injection vulnerability in the /webcti/session_ajax.php endpoint. Unauthenticated remote attacke...

📅 10 days ago • Feb 24, 2026
CVE-2026-1229 9.8

A cryptographic vulnerability in CIRCL's P-384 elliptic curve implementation produces incorrect CombinedMult results for specific inputs. This affects...

📅 11 days ago • Feb 24, 2026
CVE-2026-26198 9.8

CVE-2026-26198 is a critical SQL injection vulnerability in Ormar ORM for Python that allows attackers to execute arbitrary SQL queries. Unauthorized ...

📅 11 days ago • Feb 24, 2026
CVE-2025-13942 9.8

A remote command injection vulnerability in Zyxel EX3510-B0 devices allows attackers to execute arbitrary operating system commands by sending special...

📅 11 days ago • Feb 24, 2026
CVE-2026-24494 9.8

An unauthenticated SQL injection vulnerability in Order Up Online Ordering System 1.0 allows attackers to execute arbitrary SQL commands via the store...

📅 12 days ago • Feb 23, 2026
CVE-2019-25459 9.8

CVE-2019-25459 is an unauthenticated SQL injection vulnerability in Web Ofisi Emlak V2 real estate software. Attackers can inject SQL code through mul...

📅 12 days ago • Feb 22, 2026
CVE-2026-27194 9.8

CVE-2026-27194 is a remote code execution vulnerability in D-Tale's /save-column-filter endpoint that allows attackers to execute arbitrary code on vu...

📅 14 days ago • Feb 21, 2026
CVE-2026-2635 9.8

CVE-2026-2635 is an authentication bypass vulnerability in MLflow that allows remote attackers to gain administrative access without credentials. The ...

📅 14 days ago • Feb 20, 2026
CVE-2026-2038 9.8

This vulnerability allows remote attackers to bypass authentication on GFI Archiver installations without requiring credentials. The flaw exists in th...

📅 14 days ago • Feb 20, 2026
CVE-2019-25441 9.8

CVE-2019-25441 is a critical command injection vulnerability in thesystem 1.0 that allows unauthenticated attackers to execute arbitrary system comman...

📅 14 days ago • Feb 20, 2026
CVE-2026-26725 9.8

A privilege escalation vulnerability in edu Business Solutions Print Shop Pro WebDesk allows remote attackers to gain elevated privileges by manipulat...

📅 14 days ago • Feb 20, 2026
CVE-2026-25715 9.8

This vulnerability allows network-adjacent attackers to gain full administrative control of affected devices by setting administrator credentials to b...

📅 14 days ago • Feb 20, 2026
CVE-2025-70831 9.8

An unauthenticated remote code execution vulnerability exists in Smanga 3.2.7 where the /php/path/rescan.php interface fails to sanitize the mediaId p...

📅 14 days ago • Feb 20, 2026
CVE-2025-69405 9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the ThemeREX Lorem Ipsum | Books & Media ...

📅 14 days ago • Feb 20, 2026
CVE-2025-69371 9.8

This CVE describes a PHP object injection vulnerability in the KindlyCare WordPress theme where untrusted data can be deserialized, potentially allowi...

📅 14 days ago • Feb 20, 2026
CVE-2025-69329 9.8

This CVE describes a PHP object injection vulnerability in the Jthemes Prestige WordPress theme, caused by insecure deserialization of untrusted data....

📅 14 days ago • Feb 20, 2026
CVE-2025-69301 9.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting insecure deserialization in the PhotoMe WordP...

📅 14 days ago • Feb 20, 2026
CVE-2025-68541 9.8

This vulnerability in the BoldThemes Ippsum WordPress theme allows attackers to inject malicious objects through deserialization of untrusted data. It...

📅 14 days ago • Feb 20, 2026
CVE-2025-67996 9.8

This CVE describes a PHP object injection vulnerability in the BoldThemes Nestin WordPress theme. Attackers can exploit insecure deserialization to ex...

📅 14 days ago • Feb 20, 2026
CVE-2025-10970 9.8

This is a critical SQL injection vulnerability in Kolay Software Inc.'s Talentics platform that allows attackers to execute arbitrary SQL commands. It...

📅 14 days ago • Feb 20, 2026
CVE-2025-30410 9.8

This critical vulnerability allows attackers to access and manipulate sensitive data without authentication in Acronis Cyber Protect products. It affe...

📅 15 days ago • Feb 20, 2026
CVE-2026-27002 9.8

OpenClaw's Docker sandbox configuration injection vulnerability allows attackers to escape container isolation and access the host system. This affect...

📅 15 days ago • Feb 20, 2026
CVE-2026-27476 9.8

RustFly 2.0.0 contains a critical command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP po...

📅 15 days ago • Feb 19, 2026
CVE-2025-67305 9.8

RUCKUS Network Director (RND) OVA appliances contain identical hardcoded SSH keys for the postgres user across all deployments, allowing attackers wit...

📅 15 days ago • Feb 19, 2026
CVE-2026-26339 9.8

CVE-2026-26339 is a critical argument injection vulnerability in Hyland Alfresco Transformation Service that allows unauthenticated attackers to execu...

📅 15 days ago • Feb 19, 2026
CVE-2025-71243 9.8

The Saisies plugin for SPIP contains a critical Remote Code Execution vulnerability (CWE-94: Improper Control of Generation of Code) that allows attac...

📅 15 days ago • Feb 19, 2026
CVE-2025-8350 9.8

This vulnerability in BiEticaret CMS allows attackers to bypass authentication and manipulate HTTP responses through Execution After Redirect and Miss...

📅 15 days ago • Feb 19, 2026
CVE-2025-15559 9.8

CVE-2025-15559 is an unauthenticated OS command injection vulnerability in NesterSoft WorkTime server's client generation API. Attackers can execute a...

📅 16 days ago • Feb 19, 2026
CVE-2026-23542 9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Grand Restaurant WordPress theme. Suc...

📅 16 days ago • Feb 19, 2026
CVE-2026-23549 9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WpEvently mage-eventpress WordPress p...

📅 16 days ago • Feb 19, 2026
CVE-2026-1994 9.8

The s2Member WordPress plugin has a critical vulnerability that allows unauthenticated attackers to change any user's password, including administrato...

📅 16 days ago • Feb 19, 2026
CVE-2026-1405 9.8

The Slider Future WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability ...

📅 16 days ago • Feb 19, 2026
CVE-2026-0926 9.8

The Prodigy Commerce WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execut...

📅 16 days ago • Feb 19, 2026
CVE-2025-13851 9.8

The Buyent Classified plugin for WordPress allows unauthenticated attackers to register accounts with administrator privileges by manipulating the use...

📅 16 days ago • Feb 19, 2026
CVE-2025-13563 9.8

This vulnerability allows unauthenticated attackers to register as administrators on WordPress sites using the Lizza LMS Pro plugin. All WordPress sit...

📅 16 days ago • Feb 19, 2026
CVE-2025-12882 9.8

The Clasifico Listing WordPress plugin allows unauthenticated attackers to register accounts with administrator privileges by manipulating the 'listin...

📅 16 days ago • Feb 19, 2026
CVE-2026-2686 9.8

This CVE describes a remote command injection vulnerability in SECCN Dingcheng G10 software version 3.1.0.181203. Attackers can execute arbitrary oper...

📅 16 days ago • Feb 19, 2026
CVE-2026-27180 9.8

CVE-2026-27180 allows unauthenticated attackers to execute arbitrary code on MajorDoMo systems by poisoning the update URL. Attackers can deploy websh...

📅 16 days ago • Feb 18, 2026
CVE-2026-27174 9.8

CVE-2026-27174 allows unauthenticated attackers to execute arbitrary PHP code on MajorDoMo home automation systems via the admin panel's PHP console. ...

📅 16 days ago • Feb 18, 2026
CVE-2019-25364 9.8

MailCarrier 2.51 contains a critical buffer overflow vulnerability in its POP3 service that allows remote attackers to execute arbitrary code by sendi...

📅 16 days ago • Feb 18, 2026
CVE-2019-25360 9.8

CVE-2019-25360 is a critical buffer overflow vulnerability in Aida64 Engineer's CSV logging configuration that allows remote code execution. Attackers...

📅 16 days ago • Feb 18, 2026
CVE-2019-25362 9.8

CVE-2019-25362 is a critical buffer overflow vulnerability in WMV to AVI MPEG DVD WMV Convertor 4.6.1217 that allows remote attackers to execute arbit...

📅 16 days ago • Feb 18, 2026
CVE-2025-70152 9.8

CVE-2025-70152 is an unauthenticated SQL injection vulnerability in the Community Project Scholars Tracking System 1.0 that allows attackers to execut...

📅 16 days ago • Feb 18, 2026
CVE-2025-70150 9.8

CVE-2025-70150 is a critical missing authentication vulnerability in CodeAstro Membership Management System 1.0 that allows unauthenticated attackers ...

📅 16 days ago • Feb 18, 2026
CVE-2025-70149 9.8

CodeAstro Membership Management System 1.0 contains a SQL injection vulnerability in the print_membership_card.php file via the ID parameter. This all...

📅 16 days ago • Feb 18, 2026
CVE-2025-65791 9.8

CVE-2025-65791 is a critical command injection vulnerability in ZoneMinder's image.php component that allows attackers to execute arbitrary commands o...

📅 16 days ago • Feb 18, 2026
CVE-2025-70998 9.8

This vulnerability allows remote attackers to gain root access to UTT HiPER 810 / nv810v4 routers via telnet using insecure default credentials. Attac...

📅 16 days ago • Feb 18, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free