🔥 Trending CVEs - Last 90 Days

4,493 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,156
Total CVEs Published
993
Critical Severity
3,500
High Severity
⚠️
Critical Alert
993 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-49365 8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Jack Well WordPress theme. Attackers can read ...

📅 83 days ago • Dec 18, 2025
CVE-2025-49366 8.1

This vulnerability allows attackers to include local PHP files through improper filename control in the Hanani WordPress theme. Attackers can potentia...

📅 83 days ago • Dec 18, 2025
CVE-2025-49359 8.1

This vulnerability allows attackers to include local files on the server through PHP's include/require statements in the ShieldGroup WordPress theme. ...

📅 83 days ago • Dec 18, 2025
CVE-2025-68147 8.1

A stored XSS vulnerability in Open Source Point of Sale allows attackers with administrative access to inject malicious JavaScript into the Return Pol...

📅 84 days ago • Dec 17, 2025
CVE-2025-34438 8.1

AVideo versions before 20.1 contain an insecure direct object reference vulnerability that allows authenticated users with upload permissions to modif...

📅 84 days ago • Dec 17, 2025
CVE-2025-68154 8.1

CVE-2025-68154 is an OS command injection vulnerability in the systeminformation library for Node.js. On Windows systems, the fsSize() function improp...

📅 85 days ago • Dec 16, 2025
CVE-2025-14002 8.1

The WPCOM Member WordPress plugin has an authentication bypass vulnerability that allows attackers to brute-force 6-digit OTP codes within a 10-minute...

📅 85 days ago • Dec 16, 2025
CVE-2023-53881 8.1

CVE-2023-53881 is an unencrypted CWMP communication vulnerability in ReyeeOS that allows attackers to perform man-in-the-middle attacks. Attackers can...

📅 86 days ago • Dec 15, 2025
CVE-2025-65778 8.1

This vulnerability allows attackers to upload malicious attachments that are served with HTML content types, enabling cross-site scripting (XSS) attac...

📅 86 days ago • Dec 15, 2025
CVE-2025-14549 8.1

This vulnerability in Eclipse OMR's compiler component causes incorrect handling of NUL characters during charset translation on Z processors, leading...

📅 86 days ago • Dec 15, 2025
CVE-2025-67900 8.1

NXLog Agent versions before 6.11 can be forced to load an attacker-controlled OpenSSL configuration file via the OPENSSL_CONF environment variable. Th...

📅 87 days ago • Dec 14, 2025
CVE-2025-14475 8.1

This vulnerability allows unauthenticated attackers to execute arbitrary PHP code on WordPress sites using the Extensive VC Addons plugin. Attackers c...

📅 88 days ago • Dec 13, 2025
CVE-2025-58137 8.1

This CVE describes an authorization bypass vulnerability in Apache Fineract where attackers can manipulate user-controlled keys to access unauthorized...

📅 89 days ago • Dec 12, 2025
CVE-2026-21311 8.0

This stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce allows high-privileged attackers to inject malicious JavaScript into vulnerable...

⚡ Yesterday • Mar 11, 2026
CVE-2026-28405 8.0

This vulnerability allows cross-site scripting (XSS) attacks in MarkUs assignment submission system. Attackers can inject malicious scripts into stude...

📅 6 days ago • Mar 5, 2026
CVE-2026-0752 8.0

This vulnerability allows unauthenticated attackers to inject arbitrary scripts into GitLab's Mermaid diagram sandbox UI, potentially leading to cross...

📅 14 days ago • Feb 25, 2026
CVE-2025-33179 8.0

This vulnerability in NVIDIA Cumulus Linux and NVOS allows low-privileged users to execute unauthorized commands through the NVUE interface, potential...

📅 15 days ago • Feb 24, 2026
CVE-2026-27099 8.0

This stored cross-site scripting (XSS) vulnerability in Jenkins allows attackers with Agent/Configure or Agent/Disconnect permissions to inject malici...

📅 21 days ago • Feb 18, 2026
CVE-2026-26268 8.0

This CVE describes a sandbox escape vulnerability in Cursor code editor versions prior to 2.5. A malicious AI agent could write to improperly protecte...

📅 26 days ago • Feb 13, 2026
CVE-2026-2360 8.0

PostgreSQL Anonymizer extension contains a privilege escalation vulnerability where users can create malicious operators in schemas with CREATE permis...

📅 28 days ago • Feb 11, 2026
CVE-2025-7659 8.0

This vulnerability in GitLab allows unauthenticated attackers to bypass validation in the Web IDE feature, potentially stealing authentication tokens ...

📅 28 days ago • Feb 11, 2026
CVE-2026-21523 8.0

A time-of-check time-of-use race condition vulnerability in GitHub Copilot and Visual Studio allows authenticated attackers to execute arbitrary code ...

📅 29 days ago • Feb 10, 2026
CVE-2026-21229 8.0

This vulnerability allows an authorized attacker to exploit improper input validation in Power BI to execute arbitrary code remotely over a network. O...

📅 29 days ago • Feb 10, 2026
CVE-2025-62673 8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows attackers on the same network to crash the device or potentially...

📅 36 days ago • Feb 3, 2026
CVE-2025-58455 8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

📅 36 days ago • Feb 3, 2026
CVE-2025-59482 8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

📅 36 days ago • Feb 3, 2026
CVE-2025-59487 8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

📅 36 days ago • Feb 3, 2026
CVE-2025-61944 8.0

A heap-based buffer overflow in TP-Link Archer AX53 v1.0's tmpserver modules allows authenticated attackers on the same network to crash the device or...

📅 36 days ago • Feb 3, 2026
CVE-2025-61983 8.0

A heap-based buffer overflow in TP-Link Archer AX53 v1.0's tmpserver modules allows authenticated attackers on the same network to crash the device or...

📅 36 days ago • Feb 3, 2026
CVE-2025-62404 8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

📅 36 days ago • Feb 3, 2026
CVE-2025-62405 8.0

A heap-based buffer overflow vulnerability in TP-Link Archer AX53 v1.0 routers allows authenticated attackers on the same network to crash the device ...

📅 36 days ago • Feb 3, 2026
CVE-2025-58077 8.0

This CVE describes a heap-based buffer overflow in the tmpserver modules of TP-Link Archer AX53 v1.0 routers. Authenticated attackers on the same loca...

📅 36 days ago • Feb 3, 2026
CVE-2026-23997 8.0

A stored XSS vulnerability in FacturaScripts allows attackers to inject malicious JavaScript into the Observations field, which executes when administ...

📅 37 days ago • Feb 2, 2026
CVE-2026-22223 8.0

An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. This coul...

📅 37 days ago • Feb 2, 2026
CVE-2026-22221 8.0

An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. This coul...

📅 37 days ago • Feb 2, 2026
CVE-2026-22222 8.0

An authenticated OS command injection vulnerability in TP-Link Archer BE230 routers allows attackers on the same network to execute arbitrary commands...

📅 37 days ago • Feb 2, 2026
CVE-2026-0630 8.0

An authenticated OS command injection vulnerability in TP-Link Archer BE230 routers allows attackers on the same network to execute arbitrary commands...

📅 37 days ago • Feb 2, 2026
CVE-2026-0631 8.0

An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. Successfu...

📅 37 days ago • Feb 2, 2026
CVE-2025-9974 8.0

CVE-2025-9974 is an OS command injection vulnerability in the unified WEBUI application of Nokia ONT/Beacon devices. Authenticated attackers with low ...

📅 37 days ago • Feb 2, 2026
CVE-2025-7016 8.0

An improper access control vulnerability in Akın Software's QR Menu allows attackers to abuse authentication mechanisms, potentially gaining unauthor...

📅 41 days ago • Jan 29, 2026
CVE-2026-24840 8.0

Dokploy versions before 0.26.6 contain hardcoded database credentials in the installation script, allowing attackers with network access to the databa...

📅 43 days ago • Jan 28, 2026
CVE-2025-3839 8.0

Epiphany browser's external URL handler feature can be abused to exploit vulnerabilities in external applications, making them appear remotely exploit...

📅 48 days ago • Jan 23, 2026
CVE-2026-24129 8.0

CVE-2026-24129 is a command injection vulnerability in Runtipi that allows authenticated users to execute arbitrary system commands on the host server...

📅 48 days ago • Jan 22, 2026
CVE-2025-4764 8.0

This SQL injection vulnerability in Aida Computer Information Technology's Hotel Guest Hotspot software allows attackers to execute arbitrary SQL comm...

📅 48 days ago • Jan 22, 2026
CVE-2026-24010 8.0

Horilla HRMS versions before 1.5.0 contain a critical file upload vulnerability that allows authenticated users to upload malicious HTML files disguis...

📅 49 days ago • Jan 22, 2026
CVE-2026-20960 8.0

This vulnerability in Microsoft Power Apps allows authenticated attackers to execute arbitrary code remotely due to improper authorization checks. It ...

📅 54 days ago • Jan 16, 2026
CVE-2026-23535 8.0

This vulnerability in the Weblate command-line client (wlc) allows a malicious Weblate server to write files to arbitrary locations on a client's syst...

📅 54 days ago • Jan 16, 2026
CVE-2026-1010 8.0

A stored XSS vulnerability in Altium Workflow Engine allows authenticated users to inject malicious JavaScript into workflow data. When administrators...

📅 55 days ago • Jan 15, 2026
CVE-2025-68958 8.0

A race condition vulnerability in the card framework module allows attackers to disrupt system availability through multi-threaded exploitation. This ...

📅 57 days ago • Jan 14, 2026
CVE-2025-68955 8.0

A race condition vulnerability in Huawei's card framework module allows attackers to disrupt system availability through multi-threaded exploitation. ...

📅 57 days ago • Jan 14, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free