🔥 Trending CVEs - Last 90 Days

4,508 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,268
Total CVEs Published
984
Critical Severity
3,524
High Severity
⚠️
Critical Alert
984 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-15274 8.8

A heap-based buffer overflow vulnerability in FontForge's SFD file parser allows remote attackers to execute arbitrary code when users open malicious ...

📅 69 days ago • Dec 31, 2025
CVE-2025-15275 8.8

A heap-based buffer overflow vulnerability in FontForge's SFD file parser allows remote attackers to execute arbitrary code when users open malicious ...

📅 69 days ago • Dec 31, 2025
CVE-2025-15269 8.8

A use-after-free vulnerability in FontForge's SFD file parser allows remote attackers to execute arbitrary code when users open malicious SFD files or...

📅 69 days ago • Dec 31, 2025
CVE-2025-15270 8.8

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SFD font files or visiting malicious web...

📅 69 days ago • Dec 31, 2025
CVE-2022-50804 8.8

CVE-2022-50804 is a CSRF vulnerability in JM-DATA ONU JF511-TV version 1.0.67 that allows attackers to trick authenticated administrators into unknowi...

📅 70 days ago • Dec 30, 2025
CVE-2022-50793 8.8

This vulnerability allows authenticated attackers to execute arbitrary system commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems through command inject...

📅 70 days ago • Dec 30, 2025
CVE-2025-15356 8.8

A buffer overflow vulnerability in Tenda AC20 routers allows remote attackers to execute arbitrary code by sending specially crafted requests to the P...

📅 70 days ago • Dec 30, 2025
CVE-2025-68976 8.8

This CVE describes a Missing Authorization vulnerability in the Eagle Booking WordPress plugin that allows attackers to change plugin settings without...

📅 70 days ago • Dec 30, 2025
CVE-2025-68981 8.8

This CVE describes a Missing Authorization vulnerability in the HomeFix Elementor Portfolio WordPress plugin that allows attackers to bypass access co...

📅 70 days ago • Dec 30, 2025
CVE-2025-15234 8.8

This CVE describes a heap-based buffer overflow vulnerability in Tenda M3 routers version 1.0.0.13(4903). Attackers can remotely exploit this vulnerab...

📅 70 days ago • Dec 30, 2025
CVE-2025-15232 8.8

A stack-based buffer overflow vulnerability in Tenda M3 routers allows remote attackers to execute arbitrary code by manipulating the mac/terminal par...

📅 70 days ago • Dec 30, 2025
CVE-2025-15233 8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda M3 routers via a heap-based buffer overflow in the web interface. Attack...

📅 70 days ago • Dec 30, 2025
CVE-2025-15231 8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda M3 routers via a stack-based buffer overflow in the formSetRemoteVlanInf...

📅 70 days ago • Dec 30, 2025
CVE-2025-15230 8.8

This vulnerability allows remote attackers to execute arbitrary code on Tenda M3 routers via a heap-based buffer overflow in the formSetVlanPolicy fun...

📅 70 days ago • Dec 30, 2025
CVE-2025-15218 8.8

This vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code via a buffer overflow in the lanMask parameter of the /gof...

📅 71 days ago • Dec 30, 2025
CVE-2025-15216 8.8

A stack-based buffer overflow vulnerability in Tenda AC23 routers allows remote attackers to execute arbitrary code by manipulating the bindnum parame...

📅 71 days ago • Dec 30, 2025
CVE-2025-15217 8.8

A buffer overflow vulnerability in Tenda AC23 routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST request...

📅 71 days ago • Dec 30, 2025
CVE-2025-15215 8.8

A buffer overflow vulnerability in Tenda AC10U routers allows remote attackers to execute arbitrary code by sending specially crafted HTTP POST reques...

📅 71 days ago • Dec 30, 2025
CVE-2024-30855 8.8

DedeCMS v5.7 contains a CSRF vulnerability in the makehtml_list_action.php file that allows attackers to trick authenticated administrators into perfo...

📅 71 days ago • Dec 29, 2025
CVE-2025-67255 8.8

NagiosXI 2026R1.0.1 build 1762361101 contains a SQL injection vulnerability in dashboard parameters that lacks proper input filtering. Any authenticat...

📅 71 days ago • Dec 29, 2025
CVE-2025-55061 8.8

CVE-2025-55061 is an unrestricted file upload vulnerability (CWE-434) that allows attackers to upload malicious files to vulnerable systems. This coul...

📅 71 days ago • Dec 29, 2025
CVE-2025-15193 8.8

A buffer overflow vulnerability in D-Link DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter ...

📅 71 days ago • Dec 29, 2025
CVE-2025-15190 8.8

A stack-based buffer overflow vulnerability exists in D-Link DWR-M920 routers through firmware version 1.1.50. Remote attackers can exploit this by ma...

📅 71 days ago • Dec 29, 2025
CVE-2025-15189 8.8

A buffer overflow vulnerability in D-Link DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter....

📅 71 days ago • Dec 29, 2025
CVE-2025-15137 8.8

This vulnerability allows remote attackers to execute arbitrary commands on TRENDnet TEW-800MB routers through command injection in the NTPSyncWithHos...

📅 72 days ago • Dec 28, 2025
CVE-2025-15136 8.8

This vulnerability allows remote attackers to execute arbitrary commands on TRENDnet TEW-800MB routers by injecting malicious commands through the man...

📅 72 days ago • Dec 28, 2025
CVE-2025-67729 8.8

LMDeploy versions before 0.11.1 have an insecure deserialization vulnerability where torch.load() is called without the weights_only=True parameter wh...

📅 74 days ago • Dec 26, 2025
CVE-2025-66738 8.8

A command injection vulnerability in Yealink T21P_E2 phones allows remote attackers with normal privileges to execute arbitrary code via crafted reque...

📅 74 days ago • Dec 26, 2025
CVE-2025-15092 8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 512W devices through a buffer overflow in the ConfigExceptMSN funct...

📅 75 days ago • Dec 26, 2025
CVE-2025-15091 8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 512W devices through a buffer overflow in the formPictureUrl functi...

📅 75 days ago • Dec 26, 2025
CVE-2025-15089 8.8

This vulnerability allows remote attackers to execute arbitrary code on UTT 进取 512W devices via a buffer overflow in the strcpy function in the /g...

📅 75 days ago • Dec 25, 2025
CVE-2025-15090 8.8

This vulnerability allows remote attackers to execute arbitrary code on affected UTT 进取 512W devices via a buffer overflow in the formConfigNotice...

📅 75 days ago • Dec 25, 2025
CVE-2025-2155 8.8

This vulnerability allows attackers to upload malicious files to Specto CM systems, potentially leading to remote code execution. It affects all Spect...

📅 76 days ago • Dec 24, 2025
CVE-2025-68608 8.8

This CVE describes a Missing Authorization vulnerability in the Userpro WordPress plugin by DeluxeThemes. It allows attackers to bypass access control...

📅 76 days ago • Dec 24, 2025
CVE-2025-68596 8.8

This CVE describes a Missing Authorization vulnerability in the Bit Assist WordPress plugin that allows attackers to bypass access controls. It affect...

📅 76 days ago • Dec 24, 2025
CVE-2025-68601 8.8

This CSRF vulnerability in the Five Star Restaurant Reservations WordPress plugin allows attackers to trick authenticated administrators into performi...

📅 76 days ago • Dec 24, 2025
CVE-2025-68592 8.8

This CVE describes a missing authorization vulnerability in the WP Adminify WordPress plugin that allows attackers to bypass access controls. It affec...

📅 76 days ago • Dec 24, 2025
CVE-2025-68593 8.8

This CVE describes a missing authorization vulnerability in the WP Adminify WordPress plugin that allows attackers to bypass access controls and perfo...

📅 76 days ago • Dec 24, 2025
CVE-2025-68595 8.8

This CVE describes a Missing Authorization vulnerability in the Trustindex Widgets for Social Photo Feed WordPress plugin. It allows attackers to expl...

📅 76 days ago • Dec 24, 2025
CVE-2025-68580 8.8

This CSRF vulnerability in the Advanced Classifieds & Directory Pro WordPress plugin allows attackers to trick authenticated administrators into perfo...

📅 76 days ago • Dec 24, 2025
CVE-2025-68582 8.8

This CVE describes a Missing Authorization vulnerability in the Funnelforms Free WordPress plugin that allows attackers to bypass access controls. Att...

📅 76 days ago • Dec 24, 2025
CVE-2025-68583 8.8

This CSRF vulnerability in the Tikweb Management Fast User Switching WordPress plugin allows attackers to trick authenticated administrators into perf...

📅 76 days ago • Dec 24, 2025
CVE-2025-68584 8.8

This CSRF vulnerability in the Vimeotheque WordPress plugin allows attackers to trick authenticated administrators into performing unintended actions ...

📅 76 days ago • Dec 24, 2025
CVE-2025-68585 8.8

This CVE describes a missing authorization vulnerability in the WP Document Revisions WordPress plugin that allows attackers to bypass access controls...

📅 76 days ago • Dec 24, 2025
CVE-2025-68586 8.8

This CVE describes a missing authorization vulnerability in the Cooked WordPress plugin that allows attackers to bypass access controls. It affects al...

📅 76 days ago • Dec 24, 2025
CVE-2025-68571 8.8

This CVE describes a Missing Authorization vulnerability in the SALESmanago WordPress plugin that allows attackers to bypass access controls. It affec...

📅 76 days ago • Dec 24, 2025
CVE-2025-68572 8.8

This CVE describes a Missing Authorization vulnerability in the Spider Themes BBP Core WordPress plugin that allows attackers to bypass access control...

📅 76 days ago • Dec 24, 2025
CVE-2025-68573 8.8

This CSRF vulnerability in the Simple Keyword to Link WordPress plugin allows attackers to trick authenticated administrators into performing unintend...

📅 76 days ago • Dec 24, 2025
CVE-2025-68575 8.8

This CVE describes a Missing Authorization vulnerability in the Wappointment WordPress plugin that allows attackers to bypass access controls. It affe...

📅 76 days ago • Dec 24, 2025
CVE-2025-68577 8.8

This CVE describes a missing authorization vulnerability in the Virusdie WordPress plugin that allows attackers to bypass access controls. Attackers c...

📅 76 days ago • Dec 24, 2025

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free