🔥 Trending CVEs - Last 7 Days

192 critical and high-severity vulnerabilities discovered in the last 7 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
339
Total CVEs Published
42
Critical Severity
150
High Severity
⚠️
Critical Alert
42 critical vulnerabilities published in the last 7 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-28447 8.1

OpenClaw versions 2026.1.29-beta.1 through 2026.2.1 contain a path traversal vulnerability in plugin installation. Attackers can craft malicious plugi...

⚡ Yesterday • Mar 5, 2026
CVE-2026-1321 8.1

This vulnerability in the WordPress Restrict Content plugin allows unauthenticated attackers to register with any membership level, including inactive...

⚡ Yesterday • Mar 5, 2026
CVE-2026-20002 8.1

This SQL injection vulnerability in Cisco Secure FMC's web management interface allows authenticated attackers to execute arbitrary SQL commands. Atta...

📅 2 days ago • Mar 4, 2026
CVE-2026-20777 8.1

A heap-based buffer overflow vulnerability in libbiosig's Nicolet WFT file parser allows arbitrary code execution when processing malicious .wft files...

📅 3 days ago • Mar 3, 2026
CVE-2026-28405 8.0

This vulnerability allows cross-site scripting (XSS) attacks in MarkUs assignment submission system. Attackers can inject malicious scripts into stude...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28727 7.8

This vulnerability allows local attackers to escalate privileges on macOS systems by exploiting insecure Unix socket permissions in Acronis Cyber Prot...

⚡ Yesterday • Mar 6, 2026
CVE-2026-26034 7.8

CVE-2026-26034 is an incorrect default permissions vulnerability in Dell UPS Multi-UPS Management Console (MUMC) that allows attackers to execute arbi...

📅 2 days ago • Mar 5, 2026
CVE-2026-3094 7.8

Delta Electronics CNCSoft-G2 has a file parsing vulnerability that allows out-of-bounds write when processing malicious files. This enables remote cod...

📅 2 days ago • Mar 4, 2026
CVE-2026-28518 7.8

OpenViking versions 0.2.1 and earlier contain a path traversal vulnerability in .ovpack import handling that allows attackers to write arbitrary files...

📅 3 days ago • Mar 3, 2026
CVE-2026-21385 7.8

This CVE describes a memory corruption vulnerability in alignment-based memory allocation functions. Attackers can exploit this to execute arbitrary c...

📅 4 days ago • Mar 2, 2026
CVE-2025-59600 7.8

This CVE describes a buffer overflow vulnerability in Qualcomm software where user-supplied data is added without proper bounds checking, leading to m...

📅 4 days ago • Mar 2, 2026
CVE-2025-47385 7.8

This vulnerability allows memory corruption when accessing the trusted execution environment (TEE) without proper privilege checks. Attackers could po...

📅 4 days ago • Mar 2, 2026
CVE-2025-47381 7.8

This vulnerability allows memory corruption when multiple processes concurrently access shared buffers through IOCTL calls in Qualcomm drivers. Attack...

📅 4 days ago • Mar 2, 2026
CVE-2025-47376 7.8

This vulnerability allows memory corruption when multiple processes concurrently access a shared buffer during IOCTL calls in Qualcomm components. Att...

📅 4 days ago • Mar 2, 2026
CVE-2025-47373 7.8

This CVE describes a memory corruption vulnerability in Qualcomm Trusted Application (TA) invocation where accessing buffers with invalid length can l...

📅 4 days ago • Mar 2, 2026
CVE-2026-30822 7.7

Flowise versions before 3.0.13 contain an unauthenticated database injection vulnerability that allows attackers to manipulate internal database field...

🔥 Today • Mar 7, 2026
CVE-2026-28468 7.7

OpenClaw sandbox browser bridge server accepts requests without gateway authentication, allowing local attackers to access browser control endpoints. ...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28393 7.7

OpenClaw versions 2.0.0-beta3 through 2026.2.13 contain a path traversal vulnerability in the hook transform module loading mechanism. Attackers with ...

⚡ Yesterday • Mar 5, 2026
CVE-2026-20100 7.7

This vulnerability allows authenticated remote attackers with VPN access to cause Cisco ASA/FTD devices to crash and reload by sending specially craft...

📅 2 days ago • Mar 4, 2026
CVE-2026-20049 7.7

This vulnerability allows authenticated remote attackers to cause denial of service on Cisco ASA and FTD firewalls by sending specially crafted GCM-en...

📅 2 days ago • Mar 4, 2026
CVE-2026-20014 7.7

This vulnerability in Cisco Secure Firewall ASA and FTD software allows authenticated VPN users to send specially crafted IKEv2 packets that cause mem...

📅 2 days ago • Mar 4, 2026
CVE-2026-29053 7.6

Ghost CMS versions 0.7.2 through 6.19.0 contain a vulnerability where malicious themes can execute arbitrary code on the server. This allows attackers...

📅 2 days ago • Mar 5, 2026
CVE-2026-28403 7.6

Textream macOS teleprompter app versions before 1.5.1 have a WebSocket server that doesn't validate the Origin header, allowing malicious web pages to...

📅 4 days ago • Mar 2, 2026
CVE-2026-2020 7.5

The JS Archive List WordPress plugin is vulnerable to PHP object injection through the 'included' shortcode attribute. Authenticated attackers with Co...

🔥 Today • Mar 7, 2026
CVE-2025-14353 7.5

This SQL injection vulnerability in the WordPress ZIP Code Based Content Protection plugin allows unauthenticated attackers to inject malicious SQL qu...

🔥 Today • Mar 7, 2026
CVE-2026-29087 7.5

This vulnerability allows attackers to bypass route-based middleware protections in @hono/node-server applications by using URL-encoded slashes (%2F) ...

🔥 Today • Mar 6, 2026
CVE-2026-24696 7.5

This vulnerability allows attackers to bypass rate limiting on WebSocket authentication requests, enabling denial-of-service attacks that disrupt legi...

🔥 Today • Mar 6, 2026
CVE-2026-26018 7.5

A denial of service vulnerability in CoreDNS's loop detection plugin allows attackers to crash DNS servers by sending specially crafted DNS queries. T...

🔥 Today • Mar 6, 2026
CVE-2026-2753 7.5

An absolute path traversal vulnerability in Navtor NavBox allows unauthenticated remote attackers to read arbitrary files from the filesystem. This af...

🔥 Today • Mar 6, 2026
CVE-2018-25193 7.5

Mongoose Web Server 6.9 contains a denial of service vulnerability where remote attackers can crash the service by establishing multiple socket connec...

🔥 Today • Mar 6, 2026
CVE-2018-25178 7.5

Easyndexer 1.0 contains an unauthenticated arbitrary file download vulnerability that allows attackers to retrieve sensitive system files by manipulat...

🔥 Today • Mar 6, 2026
CVE-2018-25169 7.5

AMPPS 2.7 contains a denial of service vulnerability where remote attackers can crash the service by sending malformed data to the default HTTP port. ...

🔥 Today • Mar 6, 2026
CVE-2026-29074 7.5

SVGO versions 2.1.0-2.8.0, 3.0.0-3.3.2, and before 4.0.1 are vulnerable to XML entity expansion attacks. Attackers can craft small malicious SVG files...

🔥 Today • Mar 6, 2026
CVE-2026-28429 7.5

This CVE describes a path traversal vulnerability in Talishar, a fan-made Flesh and Blood project, where the ParseGamestate.php component can be acces...

⚡ Yesterday • Mar 6, 2026
CVE-2026-27778 7.5

This CVE describes a WebSocket API vulnerability where missing rate limiting on authentication requests allows attackers to conduct denial-of-service ...

⚡ Yesterday • Mar 6, 2026
CVE-2026-28479 7.5

OpenClaw versions before 2026.2.15 use deprecated SHA-1 hashing for sandbox identifier cache keys, making them vulnerable to collision attacks. Attack...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28469 7.5

OpenClaw versions before 2026.2.14 have a webhook routing vulnerability in the Google Chat monitor component that allows attackers to misroute webhook...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28462 7.5

OpenClaw versions before 2026.2.13 contain a path traversal vulnerability in browser control API endpoints that handle trace and download files. Attac...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28454 7.5

OpenClaw versions before 2026.2.2 fail to validate Telegram webhook secrets, allowing unauthenticated attackers to send forged Telegram updates. This ...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28789 7.5

CVE-2026-28789 is an unauthenticated denial-of-service vulnerability in OliveTin's OAuth2 login flow. Attackers can crash the service by sending concu...

⚡ Yesterday • Mar 5, 2026
CVE-2026-28342 7.5

CVE-2026-28342 is an unauthenticated denial-of-service vulnerability in OliveTin's PasswordHash API endpoint. Attackers can send concurrent password h...

⚡ Yesterday • Mar 5, 2026
CVE-2026-29054 7.5

This vulnerability allows remote unauthenticated attackers to bypass Traefik's protection mechanisms and remove critical X-Forwarded headers that iden...

⚡ Yesterday • Mar 5, 2026
CVE-2026-26999 7.5

This vulnerability allows remote unauthenticated attackers to cause denial of service in Traefik by exploiting a TLS handshake flaw. Attackers can sen...

⚡ Yesterday • Mar 5, 2026
CVE-2026-1605 7.5

This vulnerability in Eclipse Jetty's GzipHandler causes a memory leak when processing compressed HTTP requests without compressed responses. Attacker...

⚡ Yesterday • Mar 5, 2026
CVE-2026-29045 7.5

This vulnerability in Hono web framework allows attackers to bypass route-based middleware protections (like authentication) for static files by using...

📅 2 days ago • Mar 4, 2026
CVE-2026-28435 7.5

This vulnerability in cpp-httplib allows attackers to bypass configured payload size limits by sending compressed HTTP requests. When using streaming ...

📅 2 days ago • Mar 4, 2026
CVE-2026-26514 7.5

An argument injection vulnerability in bird-lg-go's traceroute module allows remote attackers to inject arbitrary command-line flags via the q paramet...

📅 2 days ago • Mar 4, 2026
CVE-2023-7337 7.5

This SQL injection vulnerability in the JS Help Desk WordPress plugin allows unauthenticated attackers to inject malicious SQL queries via a cookie pa...

📅 2 days ago • Mar 4, 2026
CVE-2026-27932 7.5

This vulnerability allows unauthenticated attackers to cause CPU exhaustion denial-of-service by sending specially crafted JWE tokens with extremely h...

📅 3 days ago • Mar 3, 2026
CVE-2024-55019 7.5

This vulnerability allows unauthenticated attackers to download arbitrary files from Weintek cMT-3072XH2 HMI devices via the download_wb.cgi component...

📅 3 days ago • Mar 3, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free