🔥 Trending CVEs - Last 90 Days

4,492 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,154
Total CVEs Published
993
Critical Severity
3,499
High Severity
⚠️
Critical Alert
993 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-68956 8.0

A race condition vulnerability in the card framework module allows attackers to cause denial of service by exploiting multi-threading issues. This aff...

📅 57 days ago • Jan 14, 2026
CVE-2026-20931 8.0

This vulnerability in Windows Telephony Service allows an authorized attacker on the same network to manipulate file paths, potentially leading to pri...

📅 57 days ago • Jan 13, 2026
CVE-2026-0408 8.0

A path traversal vulnerability in NETGEAR WiFi range extenders allows authenticated LAN attackers to access sensitive webproc files containing router ...

📅 57 days ago • Jan 13, 2026
CVE-2026-0403 8.0

An insufficient input validation vulnerability in NETGEAR Orbi routers allows attackers on the local network to execute arbitrary OS commands through ...

📅 57 days ago • Jan 13, 2026
CVE-2026-0404 8.0

An insufficient input validation vulnerability in NETGEAR Orbi routers' DHCPv6 functionality allows authenticated attackers on the same network (WiFi ...

📅 57 days ago • Jan 13, 2026
CVE-2026-0406 8.0

An insufficient input validation vulnerability in NETGEAR XR1000v2 routers allows attackers on the local network to execute arbitrary operating system...

📅 57 days ago • Jan 13, 2026
CVE-2026-0407 8.0

This CVE describes an authentication bypass vulnerability in NETGEAR WiFi range extenders that allows attackers on the same network to access the admi...

📅 57 days ago • Jan 13, 2026
CVE-2026-0878 8.0

This CVE describes a sandbox escape vulnerability in the Graphics: CanvasWebGL component due to incorrect boundary conditions. It allows attackers to ...

📅 57 days ago • Jan 13, 2026
CVE-2026-22704 8.0

HAX CMS versions 11.0.6 through 24.x are vulnerable to stored cross-site scripting (XSS), allowing attackers to inject malicious scripts that persist ...

📅 60 days ago • Jan 10, 2026
CVE-2025-13761 8.0

This is a cross-site scripting (XSS) vulnerability in GitLab that allows an unauthenticated attacker to execute arbitrary JavaScript code in the conte...

📅 61 days ago • Jan 9, 2026
CVE-2025-66620 8.0

An unused webshell in MicroServer allows unlimited login attempts with sudo rights on certain files and directories. Attackers with admin access can g...

📅 63 days ago • Jan 7, 2026
CVE-2025-64421 8.0

This vulnerability allows low-privileged users in Coolify to invite themselves as administrators through a race condition exploit. By clicking the inv...

📅 65 days ago • Jan 5, 2026
CVE-2025-59158 8.0

This stored XSS vulnerability in Coolify allows authenticated low-privilege users to inject malicious JavaScript into project names. When administrato...

📅 65 days ago • Jan 5, 2026
CVE-2025-14737 8.0

This CVE describes a command injection vulnerability in TP-Link WA850RE range extenders' httpd modules. Authenticated attackers on the same network ca...

📅 83 days ago • Dec 18, 2025
CVE-2023-53905 8.0

ProjectSend r1605 contains a CSV injection vulnerability where authenticated users can embed malicious formulas in user profile names. When administra...

📅 84 days ago • Dec 17, 2025
CVE-2025-13970 8.0

OpenPLC_V3 lacks CSRF protection, allowing attackers to trick logged-in administrators into clicking malicious links that modify PLC settings or uploa...

📅 89 days ago • Dec 13, 2025
CVE-2026-24844 7.9

This vulnerability allows attackers to execute arbitrary shell commands in melange pipelines when they can provide build input values. The issue occur...

📅 35 days ago • Feb 4, 2026
CVE-2026-21569 7.9

This XXE vulnerability in Crowd Data Center and Server allows authenticated attackers to read local files and potentially access remote content via XM...

📅 43 days ago • Jan 28, 2026
CVE-2025-0647 7.9

This CVE describes a CPU-level vulnerability in certain Arm processors where a specific instruction (CPP RCTX) can prevent proper TLB invalidation, ca...

📅 56 days ago • Jan 14, 2026
CVE-2025-61916 7.9

Spinnaker versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery (SSRF) that allows attackers to fetch data ...

📅 65 days ago • Jan 5, 2026
CVE-2026-30902 7.8

This vulnerability in Zoom Clients for Windows allows authenticated local users to escalate their privileges on the system. Attackers could gain highe...

🔥 Today • Mar 11, 2026
CVE-2026-30900 7.8

This vulnerability in Zoom Clients for Windows allows authenticated local users to escalate privileges by exploiting improper minimum version checks d...

🔥 Today • Mar 11, 2026
CVE-2026-27271 7.8

This CVE describes a heap-based buffer overflow vulnerability in Adobe Illustrator that could allow an attacker to execute arbitrary code with the pri...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27267 7.8

A stack-based buffer overflow vulnerability in Adobe Illustrator allows attackers to execute arbitrary code when a user opens a malicious file. This a...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27278 7.8

A use-after-free vulnerability in Adobe Acrobat Reader allows attackers to execute arbitrary code when a user opens a malicious PDF file. This affects...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27220 7.8

A use-after-free vulnerability in Adobe Acrobat Reader allows attackers to execute arbitrary code when a user opens a malicious PDF file. This affects...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27279 7.8

CVE-2026-27279 is an out-of-bounds write vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious f...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27274 7.8

Substance3D Stager versions 3.1.7 and earlier contain an out-of-bounds write vulnerability that could allow arbitrary code execution when a user opens...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27276 7.8

CVE-2026-27276 is a use-after-free vulnerability in Substance3D Stager that could allow arbitrary code execution when a user opens a malicious file. T...

⚡ Yesterday • Mar 10, 2026
CVE-2026-27269 7.8

CVE-2026-27269 is an out-of-bounds read vulnerability in Adobe Premiere Pro that could allow an attacker to execute arbitrary code when a user opens a...

⚡ Yesterday • Mar 10, 2026
CVE-2026-3483 7.8

An exposed dangerous method in Ivanti DSM allows local authenticated attackers to escalate privileges. This affects all Ivanti DSM installations befor...

⚡ Yesterday • Mar 10, 2026
CVE-2026-31795 7.8

A stack buffer overflow vulnerability in iccDEV's CIccXform3DLut::Apply() function allows attackers to corrupt stack memory or cause crashes. This aff...

⚡ Yesterday • Mar 10, 2026
CVE-2026-30987 7.8

A stack buffer overflow vulnerability in iccDEV's CIccTagNum<>::GetValues() function allows attackers to corrupt stack memory or cause crashes. This a...

⚡ Yesterday • Mar 10, 2026
CVE-2026-30983 7.8

A stack buffer overflow vulnerability in iccDEV's icFixXml() function allows attackers to corrupt stack memory or cause crashes via strcpy. This affec...

⚡ Yesterday • Mar 10, 2026
CVE-2026-30985 7.8

A heap-based buffer overflow vulnerability in iccDEV's CIccMatrixMath::SetRange() function allows attackers to write beyond allocated memory boundarie...

⚡ Yesterday • Mar 10, 2026
CVE-2026-30978 7.8

A heap-use-after-free vulnerability in iccDEV's CIccCmm::AddXform() function allows attackers to cause crashes or potentially execute arbitrary code b...

⚡ Yesterday • Mar 10, 2026
CVE-2026-26131 7.8

This CVE describes an incorrect default permissions vulnerability in .NET that allows an authenticated attacker to escalate privileges on the local sy...

⚡ Yesterday • Mar 10, 2026
CVE-2026-26134 7.8

An integer overflow vulnerability in Microsoft Office allows authenticated attackers to escalate privileges on local systems. This affects users runni...

⚡ Yesterday • Mar 10, 2026
CVE-2026-26117 7.8

This vulnerability allows an authenticated attacker to bypass authentication mechanisms in Azure Windows Virtual Machine Agent, enabling local privile...

⚡ Yesterday • Mar 10, 2026
CVE-2026-26128 7.8

This vulnerability in Windows SMB Server allows authenticated attackers to bypass proper authentication checks and gain elevated privileges on the loc...

⚡ Yesterday • Mar 10, 2026
CVE-2026-26107 7.8

This vulnerability is a use-after-free flaw in Microsoft Office Excel that allows an unauthorized attacker to execute arbitrary code on a victim's sys...

⚡ Yesterday • Mar 10, 2026
CVE-2026-25189 7.8

CVE-2026-25189 is a use-after-free vulnerability in Windows Desktop Window Manager (DWM) Core Library that allows an authenticated attacker to execute...

⚡ Yesterday • Mar 10, 2026
CVE-2026-25187 7.8

This vulnerability in Windows Winlogon allows an authenticated attacker to exploit improper link resolution to gain elevated local privileges. Attacke...

⚡ Yesterday • Mar 10, 2026
CVE-2026-25174 7.8

CVE-2026-25174 is an out-of-bounds read vulnerability in Windows Extensible File Allocation that allows authenticated attackers to read memory beyond ...

⚡ Yesterday • Mar 10, 2026
CVE-2026-25176 7.8

This vulnerability allows an authenticated attacker to escalate privileges on Windows systems by exploiting improper access control in the Ancillary F...

⚡ Yesterday • Mar 10, 2026
CVE-2026-25165 7.8

A null pointer dereference vulnerability in Windows Performance Counters allows authenticated attackers to execute arbitrary code with elevated privil...

⚡ Yesterday • Mar 10, 2026
CVE-2026-24293 7.8

This vulnerability is a null pointer dereference in Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to execute arb...

⚡ Yesterday • Mar 10, 2026
CVE-2026-24289 7.8

This CVE describes a use-after-free vulnerability in the Windows Kernel that allows an authenticated attacker to execute arbitrary code with elevated ...

⚡ Yesterday • Mar 10, 2026
CVE-2026-24291 7.8

This vulnerability allows an authorized attacker with local access to exploit incorrect permissions in Windows Accessibility Infrastructure (ATBroker....

⚡ Yesterday • Mar 10, 2026
CVE-2026-23673 7.8

This vulnerability is an out-of-bounds read in Windows Resilient File System (ReFS) that allows an authenticated attacker to read memory beyond alloca...

⚡ Yesterday • Mar 10, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free