🔥 Trending CVEs - Last 90 Days

4,506 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,257
Total CVEs Published
984
Critical Severity
3,522
High Severity
⚠️
Critical Alert
984 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-20944 8.4

This vulnerability allows an attacker to read memory outside the intended buffer in Microsoft Office Word, potentially leading to arbitrary code execu...

📅 56 days ago • Jan 13, 2026
CVE-2025-13447 8.4

This vulnerability allows authenticated attackers with 'User Administration' permissions to execute arbitrary operating system commands on Progress Lo...

📅 57 days ago • Jan 13, 2026
CVE-2025-13444 8.4

This CVE describes an OS command injection vulnerability in Progress LoadMaster's API that allows authenticated attackers with 'User Administration' p...

📅 57 days ago • Jan 13, 2026
CVE-2026-0507 8.4

This CVE describes an OS command injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK. An authenticated attacker with a...

📅 57 days ago • Jan 13, 2026
CVE-2025-47345 8.4

A cryptographic vulnerability in license data encryption could allow attackers to decrypt or manipulate license information. This affects systems usin...

📅 63 days ago • Jan 7, 2026
CVE-2025-49495 8.4

A buffer overflow vulnerability in the WiFi driver of Samsung Exynos 1380, 1480, 2400, and 1580 mobile processors allows attackers to execute arbitrar...

📅 64 days ago • Jan 5, 2026
CVE-2025-53966 8.4

A buffer overflow vulnerability in Samsung Exynos mobile processors allows attackers to execute arbitrary code or cause denial of service by sending s...

📅 64 days ago • Jan 5, 2026
CVE-2026-21451 8.4

A stored Cross-Site Scripting (XSS) vulnerability in Bagisto eCommerce platform allows attackers to inject malicious JavaScript into CMS pages by bypa...

📅 67 days ago • Jan 2, 2026
CVE-2023-53973 8.4

This vulnerability in Zillya Total Security allows low-privileged users to escalate privileges by exploiting the quarantine module's file restoration ...

📅 78 days ago • Dec 22, 2025
CVE-2023-53965 8.4

CVE-2023-53965 is an unquoted service path vulnerability in SOUND4 Server Service 4.1.102 that allows local non-privileged users to escalate privilege...

📅 78 days ago • Dec 22, 2025
CVE-2022-50688 8.4

CVE-2022-50688 is an unquoted service path vulnerability in Cobian Backup Gravity that allows local attackers to execute arbitrary code with SYSTEM pr...

📅 78 days ago • Dec 22, 2025
CVE-2022-50690 8.4

Wondershare MirrorGo 2.0.11.346 has insecure file permissions on ElevationService.exe, allowing local unprivileged users to replace it with malicious ...

📅 78 days ago • Dec 22, 2025
CVE-2025-14096 8.4

This vulnerability in Radiometer medical analyzers allows attackers with physical access to extract credential information due to insufficient credent...

📅 84 days ago • Dec 17, 2025
CVE-2025-67750 8.4

CVE-2025-67750 is a remote code execution vulnerability in Lightning Flow Scanner where maliciously crafted flow metadata files can execute arbitrary ...

📅 88 days ago • Dec 12, 2025
CVE-2026-28476 8.3

OpenClaw versions before 2026.2.14 contain a server-side request forgery vulnerability in the Tlon Urbit extension. Attackers who can influence the co...

📅 5 days ago • Mar 5, 2026
CVE-2026-27802 8.3

This vulnerability allows managers in Vaultwarden to escalate their privileges by modifying permissions for collections they shouldn't have access to....

📅 6 days ago • Mar 4, 2026
CVE-2025-52482 8.3

A stored cross-site scripting (XSS) vulnerability in Chamilo LMS allows teachers to inject malicious JavaScript into the glossary function, which exec...

📅 9 days ago • Mar 2, 2026
CVE-2026-1367 8.3

This vulnerability allows authenticated attackers to execute arbitrary SQL commands through the search report option in ManageEngine ADSelfService Plu...

📅 16 days ago • Feb 23, 2026
CVE-2026-27203 8.3

The eBay API MCP Server is vulnerable to environment variable injection through the updateEnvFile function, which doesn't validate input for newlines ...

📅 18 days ago • Feb 21, 2026
CVE-2025-10174 8.3

This vulnerability in PanCafe Pro allows attackers to flood the system by exploiting cleartext transmission of sensitive information, potentially caus...

📅 28 days ago • Feb 11, 2026
CVE-2025-10913 8.3

This CVE describes a Cross-Site Scripting (XSS) vulnerability in Saastech Cleaning and Internet Services Inc.'s TemizlikYolda software. Attackers can ...

📅 28 days ago • Feb 11, 2026
CVE-2025-62514 8.3

This vulnerability in Parsec's RustCrypto backend allows man-in-the-middle attackers to bypass cryptographic authentication by providing weak order po...

📅 40 days ago • Jan 29, 2026
CVE-2026-0603 8.3

A second-order SQL injection vulnerability in Hibernate's InlineIdsOrClauseBuilder allows remote attackers with low privileges to execute arbitrary SQ...

📅 47 days ago • Jan 23, 2026
CVE-2025-68137 8.3

An integer overflow vulnerability in EVerest EV charging software allows attackers to trigger either infinite loops or stack buffer overflows by sendi...

📅 48 days ago • Jan 21, 2026
CVE-2026-22850 8.3

Koko Analytics WordPress plugin versions before 2.1.3 allow arbitrary SQL execution through unescaped analytics data and permissive SQL import functio...

📅 50 days ago • Jan 19, 2026
CVE-2025-67843 8.3

This Server-Side Template Injection vulnerability in Mintlify's MDX Rendering Engine allows attackers to execute arbitrary code by injecting malicious...

📅 82 days ago • Dec 19, 2025
CVE-2025-64675 8.3

This cross-site scripting (XSS) vulnerability in Azure Cosmos DB allows attackers to inject malicious scripts into web pages generated by the database...

📅 82 days ago • Dec 19, 2025
CVE-2025-66397 8.3

This vulnerability allows any authenticated user in ChurchCRM to perform Kiosk Manager actions like allowing/accepting kiosk registrations, reloading ...

📅 83 days ago • Dec 17, 2025
CVE-2025-14727 8.3

A vulnerability in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation allows path traversal attacks. This affects Kubernetes cl...

📅 83 days ago • Dec 17, 2025
CVE-2024-44599 8.3

FNT Command 13.4.0 contains a directory traversal vulnerability (CWE-434) that allows attackers to access files outside the intended directory. This a...

📅 85 days ago • Dec 15, 2025
CVE-2026-31824 8.2

This TOCTOU race condition vulnerability in Sylius eCommerce Framework allows attackers to bypass promotion and coupon usage limits by sending concurr...

🔥 Today • Mar 10, 2026
CVE-2026-27826 8.2

CVE-2026-27826 allows unauthenticated attackers to force the MCP Atlassian server to make arbitrary outbound HTTP requests by sending two custom HTTP ...

🔥 Today • Mar 10, 2026
CVE-2026-29193 8.2

This vulnerability in ZITADEL's login interface allows users to bypass configured security policies and self-register accounts or use password authent...

📅 4 days ago • Mar 7, 2026
CVE-2026-29064 8.2

A path traversal vulnerability in Zarf's archive extraction allows malicious packages to create symlinks pointing outside the destination directory, e...

📅 4 days ago • Mar 6, 2026
CVE-2018-25199 8.2

OOP CMS BLOG 1.0 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries through search,...

📅 5 days ago • Mar 6, 2026
CVE-2018-25196 8.2

CVE-2018-25196 is an SQL injection vulnerability in ServerZilla 1.0 that allows unauthenticated attackers to manipulate database queries through the e...

📅 5 days ago • Mar 6, 2026
CVE-2018-25187 8.2

CVE-2018-25187 allows unauthenticated attackers to directly download the kim.db database file containing user credentials and password hashes, and exe...

📅 5 days ago • Mar 6, 2026
CVE-2018-25189 8.2

CVE-2018-25189 is an SQL injection vulnerability in Data Center Audit 2.6.2 that allows unauthenticated attackers to execute arbitrary SQL queries thr...

📅 5 days ago • Mar 6, 2026
CVE-2018-25182 8.2

CVE-2018-25182 is an SQL injection vulnerability in Silurus Classifieds Script 2.0 that allows unauthenticated attackers to execute arbitrary SQL quer...

📅 5 days ago • Mar 6, 2026
CVE-2018-25175 8.2

CVE-2018-25175 is an SQL injection vulnerability in Alienor Web Libre 2.0 that allows unauthenticated attackers to execute arbitrary SQL queries throu...

📅 5 days ago • Mar 6, 2026
CVE-2018-25171 8.2

CVE-2018-25171 is an unauthenticated SQL injection vulnerability in EdTv 2 that allows attackers to execute arbitrary SQL queries through the 'id' par...

📅 5 days ago • Mar 6, 2026
CVE-2018-25173 8.2

Rmedia SMS 1.0 contains an unauthenticated SQL injection vulnerability in the editgrp.php endpoint. Attackers can extract database schema information ...

📅 5 days ago • Mar 6, 2026
CVE-2018-25167 8.2

CVE-2018-25167 is an SQL injection vulnerability in Net-Billetterie 2.9 that allows unauthenticated attackers to execute arbitrary SQL queries through...

📅 5 days ago • Mar 6, 2026
CVE-2018-25163 8.2

CVE-2018-25163 is an SQL injection vulnerability in BitZoom 1.0 that allows unauthenticated attackers to execute arbitrary SQL queries through the rol...

📅 5 days ago • Mar 6, 2026
CVE-2018-25161 8.2

Warranty Tracking System 11.06.3 contains an SQL injection vulnerability in SearchCustomer.php that allows attackers to execute arbitrary SQL queries ...

📅 5 days ago • Mar 6, 2026
CVE-2026-28787 8.2

This vulnerability in OneUptime allows attackers to bypass two-factor authentication by replaying stolen WebAuthn assertions. The flaw occurs because ...

📅 5 days ago • Mar 6, 2026
CVE-2019-25507 8.2

Ashop Shopping Cart Software contains an unauthenticated SQL injection vulnerability in the 'shop' parameter of index.php. Attackers can extract sensi...

📅 6 days ago • Mar 4, 2026
CVE-2019-25498 8.2

Simple Job Script contains an unauthenticated SQL injection vulnerability in the landing_location parameter of the searched endpoint. Attackers can se...

📅 6 days ago • Mar 4, 2026
CVE-2019-25500 8.2

Simple Job Script contains an unauthenticated SQL injection vulnerability in the register-recruiters endpoint via the employerid parameter. Attackers ...

📅 6 days ago • Mar 4, 2026
CVE-2026-28562 8.2

CVE-2026-28562 is an unauthenticated SQL injection vulnerability in wpForo WordPress plugin versions 2.4.14 and earlier. Attackers can exploit the wpf...

📅 10 days ago • Feb 28, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free