🔥 Trending CVEs - Last 90 Days
4,505 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
This SQL injection vulnerability in the AA-Team Amazon Affiliates Addon for WPBakery Page Builder allows attackers to execute arbitrary SQL commands t...
📅 69 days ago • Dec 31, 2025This SQL injection vulnerability in the Traveler WordPress theme allows attackers to execute arbitrary SQL commands against the database. It affects a...
📅 83 days ago • Dec 18, 2025This SQL injection vulnerability in the Roxnor PopupKit WordPress plugin allows attackers to execute arbitrary SQL commands through the popup-builder-...
📅 83 days ago • Dec 18, 2025This SQL injection vulnerability in the LambertGroup CountDown With Image or Video Background WordPress plugin allows attackers to execute arbitrary S...
📅 85 days ago • Dec 16, 2025This SQL injection vulnerability in the Themefic Hydra Booking WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It...
📅 85 days ago • Dec 16, 2025This SQL injection vulnerability in the LambertGroup LBG Zoominoutslider WordPress plugin allows attackers to execute arbitrary SQL commands on the da...
📅 85 days ago • Dec 16, 2025This SQL injection vulnerability in the LambertGroup xPromoter WordPress plugin allows attackers to execute arbitrary SQL commands through the top_bar...
📅 85 days ago • Dec 16, 2025This SQL injection vulnerability in the All In One SEO Pack WordPress plugin allows attackers to execute arbitrary SQL commands on the database. It af...
📅 85 days ago • Dec 16, 2025This vulnerability allows an attacker to execute arbitrary code on a victim's system by exploiting an untrusted pointer dereference in Microsoft Offic...
🔥 Today • Mar 10, 2026This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Excel, potentially leading to information disclosure or ...
🔥 Today • Mar 10, 2026CVE-2026-21882 is a local privilege escalation vulnerability in theshit command-line utility that allows attackers to gain root privileges by exploiti...
📅 8 days ago • Mar 2, 2026This vulnerability allows DAG authors with existing permissions to manipulate Airflow's database to execute arbitrary code in the web-server context w...
📅 15 days ago • Feb 24, 2026This CVE describes a command injection vulnerability in the systeminformation Node.js library's wifiNetworks() function. Attackers can execute arbitra...
📅 19 days ago • Feb 19, 2026This critical vulnerability allows attackers with admin privileges to inject and execute arbitrary template code in server-side templates due to a vul...
📅 20 days ago • Feb 19, 2026Saturn Remote Mouse Server has a critical command injection vulnerability that allows unauthenticated attackers on the local network to execute arbitr...
📅 20 days ago • Feb 18, 2026Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field. Attackers can exploit this...
📅 20 days ago • Feb 18, 2026CVE-2020-37167 is a critical vulnerability in ClamAV's bytecode interpreter that allows attackers to manipulate function names through weak input vali...
📅 26 days ago • Feb 12, 2026CVE-2019-25336 is a local buffer overflow vulnerability in SpotAuditor's Base64 Encrypted Password tool that allows attackers to execute arbitrary cod...
📅 26 days ago • Feb 12, 2026CVE-2019-25332 is a local stack overflow vulnerability in FTP Commander Pro that allows attackers to execute arbitrary code by overwriting the EIP reg...
📅 26 days ago • Feb 12, 2026OpenClaw personal AI assistant versions before 2026.1.20 contain a command injection vulnerability. Unauthenticated local clients can exploit the Gate...
📅 32 days ago • Feb 6, 2026This CVE describes an out-of-bounds write vulnerability in Huawei camera modules that could allow attackers to crash affected systems. The vulnerabili...
📅 33 days ago • Feb 6, 2026This CVE describes a use-after-free concurrency vulnerability in the graphics module that could allow an attacker to cause system instability or crash...
📅 33 days ago • Feb 6, 2026This vulnerability in the Compressing library allows attackers to write files to arbitrary locations on the host filesystem by exploiting improper sym...
📅 34 days ago • Feb 4, 2026Boltz 2.0.0 contains a critical insecure deserialization vulnerability that allows arbitrary code execution when loading malicious pickle files. Attac...
📅 35 days ago • Feb 3, 2026This vulnerability allows a local user with filesystem access to escalate privileges on IBM Db2 for Windows systems due to an unquoted search path ele...
📅 39 days ago • Jan 30, 2026A stack-based buffer overflow vulnerability in GnuPG's tpm2daemon component allows attackers to execute arbitrary code or cause denial of service when...
📅 42 days ago • Jan 27, 2026This vulnerability in dataSIMS Avionics ARINC 664-1 version 4.5.3 allows attackers to execute arbitrary code on Windows systems by exploiting a local ...
📅 46 days ago • Jan 23, 2026A NULL pointer dereference vulnerability in SIPp allows remote attackers to crash the application via specially crafted SIP messages, causing denial o...
📅 47 days ago • Jan 23, 2026IBM Sterling Connect:Direct for UNIX contains hard-coded credentials that could allow attackers to authenticate to the system, communicate with extern...
📅 49 days ago • Jan 20, 2026CVE-2025-12985 is a privilege escalation vulnerability in IBM Licensing Operator where incorrect file permissions allow local attackers to gain root p...
📅 49 days ago • Jan 20, 2026The @fastify/express plugin vulnerability allows attackers to bypass middleware protection by using URL-encoded characters in paths. This affects appl...
📅 50 days ago • Jan 19, 2026This vulnerability allows attackers to bypass middleware protection in @fastify/middie by using URL-encoded characters in paths. Attackers can access ...
📅 50 days ago • Jan 19, 2026This vulnerability in Supermicro BMC firmware allows attackers to bypass validation checks and install malicious firmware images on affected systems. ...
📅 54 days ago • Jan 16, 2026CVE-2021-47775 is a buffer overflow vulnerability in YouTube Video Grabber (YouTube Downloader) that allows attackers to execute arbitrary code by ove...
📅 54 days ago • Jan 15, 2026An integer overflow vulnerability in GNU C Library's memalign functions (memalign, posix_memalign, aligned_alloc) can lead to heap corruption when bot...
📅 55 days ago • Jan 14, 2026A race condition vulnerability in the video framework module allows attackers to cause denial of service by exploiting multi-threading timing issues. ...
📅 56 days ago • Jan 14, 2026A race condition vulnerability in the card framework module allows attackers to disrupt system availability through multi-threaded exploitation. This ...
📅 56 days ago • Jan 14, 2026CVE-2023-54336 is an unquoted service path vulnerability in Mediconta 3.7.27 that allows local attackers to execute arbitrary code with LocalSystem pr...
📅 56 days ago • Jan 13, 2026CVE-2023-54338 is an unquoted service path vulnerability in Tftpd32 SE 4.60 that allows local attackers to execute arbitrary code with SYSTEM privileg...
📅 56 days ago • Jan 13, 2026CVE-2022-50938 is an unquoted service path vulnerability in CONTPAQi AdminPAQ 14.0.0 that allows attackers to inject malicious code into the service b...
📅 56 days ago • Jan 13, 2026CVE-2023-53984 is an unquoted service path vulnerability in Clevo HotKey Clipboard 2.1.0.6 that allows local non-privileged users to escalate privileg...
📅 56 days ago • Jan 13, 2026CVE-2022-50929 is an unquoted service path vulnerability in Connectify Hotspot 2018 that allows local attackers to execute arbitrary code with elevate...
📅 56 days ago • Jan 13, 2026CVE-2022-50930 is an unquoted service path vulnerability in Emerson PAC Machine Edition 9.80's TrapiServer service that allows local attackers to exec...
📅 56 days ago • Jan 13, 2026CVE-2022-50924 is an unquoted service path vulnerability in Private Internet Access VPN client version 3.3 that allows local attackers to execute arbi...
📅 56 days ago • Jan 13, 2026CVE-2022-50918 is an unquoted service path vulnerability in VIVE Runtime Service that allows local attackers to execute arbitrary code with SYSTEM pri...
📅 56 days ago • Jan 13, 2026CVE-2022-50920 is an unquoted service path vulnerability in Sandboxie-Plus's SbieSvc Windows service. This allows local attackers to place malicious e...
📅 56 days ago • Jan 13, 2026CVE-2022-50913 is an unquoted service path vulnerability in ITeC ITeCProteccioAppServer that allows local attackers to execute arbitrary code with SYS...
📅 56 days ago • Jan 13, 2026CVE-2022-50914 is an unquoted service path vulnerability in EaseUS Data Recovery 15.1.0.0 that allows attackers to place malicious executables in the ...
📅 56 days ago • Jan 13, 2026This CVE describes a use-after-free vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code on a victim's sys...
📅 56 days ago • Jan 13, 2026This CVE describes a use-after-free vulnerability in Microsoft Office that allows an unauthorized attacker to execute arbitrary code on a victim's sys...
📅 56 days ago • Jan 13, 2026Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats