🔥 Trending CVEs - Last 90 Days

4,506 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,243
Total CVEs Published
986
Critical Severity
3,520
High Severity
⚠️
Critical Alert
986 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-27700 8.2

This vulnerability in Hono framework versions 4.12.0-4.12.1 allows attackers to bypass IP-based access controls when using the AWS Lambda adapter behi...

📅 14 days ago • Feb 25, 2026
CVE-2026-25794 8.2

This vulnerability in ImageMagick allows attackers to trigger an integer overflow when processing large UHDR images, leading to heap buffer overflow a...

📅 15 days ago • Feb 24, 2026
CVE-2019-25440 8.2

This SQL injection vulnerability in WebIncorp ERP allows unauthenticated attackers to manipulate database queries through the prod_id parameter in pro...

📅 17 days ago • Feb 22, 2026
CVE-2019-25443 8.2

Inventory Webapp contains an unauthenticated SQL injection vulnerability in the add-item.php endpoint. Attackers can inject malicious SQL code through...

📅 17 days ago • Feb 22, 2026
CVE-2019-25433 8.2

XOOPS CMS 2.5.9 contains an unauthenticated SQL injection vulnerability in the gerar_pdf.php endpoint via the cid parameter. Attackers can execute arb...

📅 17 days ago • Feb 22, 2026
CVE-2019-25366 8.2

CVE-2019-25366 is an SQL injection vulnerability in microASP Portal+ CMS that allows unauthenticated attackers to execute arbitrary SQL queries by inj...

📅 17 days ago • Feb 22, 2026
CVE-2026-2818 8.2

CVE-2026-2818 is a zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality that allows attackers to write arbitrary...

📅 18 days ago • Feb 20, 2026
CVE-2026-26723 8.2

A Cross-Site Scripting (XSS) vulnerability in Key Systems Inc Global Facilities Management Software allows remote attackers to inject malicious script...

📅 18 days ago • Feb 20, 2026
CVE-2026-21535 8.2

CVE-2026-21535 is an improper access control vulnerability in Microsoft Teams that allows unauthorized attackers to access and disclose sensitive info...

📅 19 days ago • Feb 19, 2026
CVE-2026-26337 8.2

CVE-2026-26337 is an absolute path traversal vulnerability in Hyland Alfresco Transformation Service that allows unauthenticated attackers to read arb...

📅 19 days ago • Feb 19, 2026
CVE-2026-27179 8.2

MajorDoMo contains an unauthenticated SQL injection vulnerability in the commands module that allows attackers to execute arbitrary SQL queries withou...

📅 20 days ago • Feb 18, 2026
CVE-2019-25359 8.2

This SQL injection vulnerability in SD.NET RIM allows attackers to execute arbitrary SQL commands through POST parameters 'idtyp' and 'idgremium' at t...

📅 20 days ago • Feb 18, 2026
CVE-2026-24708 8.2

This vulnerability in OpenStack Nova allows authenticated users to trigger unsafe image resize operations by writing malicious QCOW headers to root or...

📅 20 days ago • Feb 18, 2026
CVE-2025-1924 8.2

A vulnerability in Yokogawa's Vnet/IP Interface Package allows attackers to cause denial of service or execute arbitrary code by sending maliciously c...

📅 26 days ago • Feb 13, 2026
CVE-2019-25325 8.2

CVE-2019-25325 is an SQL injection vulnerability in Thrive Smart Home 1.1 that allows unauthenticated attackers to bypass authentication by injecting ...

📅 26 days ago • Feb 12, 2026
CVE-2026-23857 8.2

This vulnerability in Dell Update Package (DUP) Framework allows low-privileged local attackers to elevate their privileges to higher levels. It affec...

📅 27 days ago • Feb 12, 2026
CVE-2025-9986 8.2

This vulnerability in Vadi Corporate Information Systems' DIGIKENT software exposes sensitive system information to unauthorized parties. It affects a...

📅 28 days ago • Feb 11, 2026
CVE-2025-59023 8.2

This vulnerability in PowerDNS Recursor allows attackers to poison cached DNS delegations by sending crafted delegations or IP fragments. This affects...

📅 30 days ago • Feb 9, 2026
CVE-2026-25847 8.2

A DOM-based cross-site scripting (XSS) vulnerability in JetBrains PyCharm's Jupyter viewer page allows attackers to execute arbitrary JavaScript in th...

📅 30 days ago • Feb 9, 2026
CVE-2026-25636 8.2

A path traversal vulnerability in Calibre's EPUB conversion allows malicious EPUB files to corrupt arbitrary files writable by the Calibre process. At...

📅 32 days ago • Feb 6, 2026
CVE-2026-23989 8.2

This vulnerability in REVA's GRPC authorization middleware allows attackers to bypass scope verification on public links. Malicious users can exploit ...

📅 32 days ago • Feb 6, 2026
CVE-2026-21532 8.2

This vulnerability in Azure Functions allows unauthorized access to sensitive information such as environment variables, configuration files, or appli...

📅 33 days ago • Feb 5, 2026
CVE-2025-13192 8.2

This SQL injection vulnerability in the Popup Builder WordPress plugin allows unauthenticated attackers to inject malicious SQL queries through REST A...

📅 34 days ago • Feb 5, 2026
CVE-2026-24843 8.2

CVE-2026-24843 is a path traversal vulnerability in melange that allows attackers to write files outside the intended workspace directory. Attackers w...

📅 34 days ago • Feb 4, 2026
CVE-2020-37110 8.2

CVE-2020-37110 is an SQL injection vulnerability in 60CycleCMS 2.5.2 that allows attackers to manipulate database queries through unvalidated user inp...

📅 35 days ago • Feb 3, 2026
CVE-2026-1117 8.2

This vulnerability allows unauthenticated attackers to trigger resource-intensive text generation operations and manipulate server state in the lollms...

📅 37 days ago • Feb 2, 2026
CVE-2025-1395 8.2

This CVE describes an information disclosure vulnerability in HeyGarson software where error messages reveal sensitive information during fuzzing atta...

📅 40 days ago • Jan 30, 2026
CVE-2026-0805 8.2

An input neutralization vulnerability in Crafty Controller's Backup Configuration component allows authenticated attackers to perform path traversal a...

📅 40 days ago • Jan 30, 2026
CVE-2026-24842 8.2

CVE-2026-24842 is a path traversal vulnerability in node-tar, a Node.js library for handling TAR archives, affecting versions prior to 7.5.7. It allow...

📅 42 days ago • Jan 28, 2026
CVE-2025-55292 8.2

This vulnerability allows attackers to impersonate legitimate nodes in Meshtastic mesh networks by forging NodeInfo packets that claim HAM mode is ena...

📅 42 days ago • Jan 28, 2026
CVE-2021-47902 8.2

CVE-2021-47902 is a SQL injection vulnerability in Testa Online Test Management System that allows attackers to inject malicious SQL code through the ...

📅 43 days ago • Jan 27, 2026
CVE-2026-21227 8.2

This path traversal vulnerability in Azure Logic Apps allows unauthorized attackers to access restricted directories and elevate privileges over the n...

📅 47 days ago • Jan 22, 2026
CVE-2025-69040 8.2

This CVE describes a Local File Inclusion vulnerability in the Bfres WordPress theme that allows attackers to include arbitrary PHP files from the ser...

📅 48 days ago • Jan 22, 2026
CVE-2025-69042 8.2

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

📅 48 days ago • Jan 22, 2026
CVE-2025-69043 8.2

This vulnerability allows attackers to include local PHP files through improper filename control in the Rashy WordPress theme. Attackers can read sens...

📅 48 days ago • Jan 22, 2026
CVE-2025-67956 8.2

This CVE describes a missing authorization vulnerability in the WordPress User Registration plugin that allows attackers to bypass access controls. It...

📅 48 days ago • Jan 22, 2026
CVE-2021-47848 8.2

Blitar Tourism 1.0 contains an SQL injection vulnerability in the login mechanism that allows attackers to bypass authentication and gain administrati...

📅 48 days ago • Jan 21, 2026
CVE-2021-47846 8.2

CVE-2021-47846 is a critical SQL injection vulnerability in Digital Crime Report Management System 1.0 that allows unauthenticated attackers to bypass...

📅 48 days ago • Jan 21, 2026
CVE-2026-20045 8.2

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected Cisco Unified Communications systems by ...

📅 49 days ago • Jan 21, 2026
CVE-2026-22022 8.2

Apache Solr deployments using RuleBasedAuthorizationPlugin with specific configurations are vulnerable to unauthorized API access. Attackers can bypas...

📅 49 days ago • Jan 21, 2026
CVE-2026-21987 8.2

A high-severity vulnerability in Oracle VM VirtualBox allows attackers with local high-privilege access to compromise the virtualization software, pot...

📅 49 days ago • Jan 20, 2026
CVE-2026-21988 8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to completely compromise the Virtual...

📅 49 days ago • Jan 20, 2026
CVE-2026-21990 8.2

This vulnerability in Oracle VM VirtualBox allows a high-privileged attacker with local access to the host system to completely compromise the Virtual...

📅 49 days ago • Jan 20, 2026
CVE-2025-14844 8.2

This vulnerability allows unauthenticated attackers to access Stripe SetupIntent client_secret values for any membership in the Restrict Content WordP...

📅 54 days ago • Jan 16, 2026
CVE-2025-67823 8.2

An unauthenticated cross-site scripting (XSS) vulnerability in Mitel's Multimedia Email component allows attackers to execute arbitrary scripts in vic...

📅 54 days ago • Jan 15, 2026
CVE-2025-70298 8.2

CVE-2025-70298 is an out-of-bounds read vulnerability in GPAC's OGG demuxer that could allow attackers to read sensitive memory contents or cause appl...

📅 55 days ago • Jan 15, 2026
CVE-2021-47777 8.2

Build Smart ERP 21.0817 contains an unauthenticated SQL injection vulnerability in the login validation endpoint. Attackers can execute arbitrary SQL ...

📅 55 days ago • Jan 15, 2026
CVE-2021-47763 8.2

Aimeos 2021.10 LTS contains a SQL injection vulnerability in the JSON API's 'sort' parameter that allows attackers to execute arbitrary SQL queries. A...

📅 55 days ago • Jan 15, 2026
CVE-2023-54340 8.2

WorkOrder CMS 0.1.0 contains an unauthenticated SQL injection vulnerability in login parameters that allows attackers to bypass authentication and exe...

📅 56 days ago • Jan 13, 2026
CVE-2023-54333 8.2

Social-Share-Buttons 2.2.3 contains a critical SQL injection vulnerability in the project_id parameter that allows unauthenticated attackers to execut...

📅 56 days ago • Jan 13, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free