🔥 Trending CVEs - Last 30 Days

1,265 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,787
Total CVEs Published
305
Critical Severity
960
High Severity
⚠️
Critical Alert
305 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-2096 9.8

Agentflow software by Flowring has a Missing Authentication vulnerability (CWE-288) that allows unauthenticated remote attackers to directly access da...

📅 25 days ago • Feb 10, 2026
CVE-2026-2095 9.8

Agentflow software from Flowring contains an authentication bypass vulnerability that allows unauthenticated remote attackers to obtain arbitrary user...

📅 25 days ago • Feb 10, 2026
CVE-2026-25938 9.8

An authentication bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to execute arbitrary code on the s...

📅 25 days ago • Feb 9, 2026
CVE-2026-25893 9.8

An authentication bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to gain administrative access via ...

📅 25 days ago • Feb 9, 2026
CVE-2026-25894 9.8

An insecure default configuration in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to gain administrative access and execu...

📅 25 days ago • Feb 9, 2026
CVE-2026-25895 9.8

CVE-2026-25895 is a path traversal vulnerability in FUXA web-based SCADA/HMI software that allows unauthenticated remote attackers to write arbitrary ...

📅 25 days ago • Feb 9, 2026
CVE-2026-25814 9.8

PlaciPy version 1.0.0 passes user-controlled query parameters directly into DynamoDB query/filter construction without validation or sanitization. Thi...

📅 25 days ago • Feb 9, 2026
CVE-2026-25875 9.8

This vulnerability allows attackers to bypass authorization in PlaciPy placement management systems by manipulating JWT claims. Attackers can escalate...

📅 25 days ago • Feb 9, 2026
CVE-2026-25809 9.8

This vulnerability in PlaciPy version 1.0.0 allows attackers to execute code evaluation outside of intended assessment windows due to missing lifecycl...

📅 25 days ago • Feb 9, 2026
CVE-2025-6830 9.8

This SQL injection vulnerability in Xpoda Studio allows attackers to execute arbitrary SQL commands on the database. All users running Xpoda Studio ve...

📅 26 days ago • Feb 9, 2026
CVE-2026-22904 9.8

This critical vulnerability allows unauthenticated remote attackers to trigger a stack buffer overflow by sending oversized cookie values. Successful ...

📅 26 days ago • Feb 9, 2026
CVE-2026-22906 9.8

This vulnerability allows unauthenticated remote attackers to decrypt stored user credentials by accessing configuration files containing AES-ECB encr...

📅 26 days ago • Feb 9, 2026
CVE-2026-22903 9.8

An unauthenticated remote attacker can crash or potentially execute arbitrary code on lighttpd web servers by sending a specially crafted HTTP request...

📅 26 days ago • Feb 9, 2026
CVE-2026-1615 9.8

The jsonpath package is vulnerable to arbitrary code execution via malicious JSON Path expressions. Attackers can inject JavaScript code that gets exe...

📅 26 days ago • Feb 9, 2026
CVE-2025-66602 9.8

This vulnerability in Yokogawa's FAST/TOOLS allows web servers to be accessed directly by IP address, making them susceptible to automated scanning an...

📅 26 days ago • Feb 9, 2026
CVE-2025-66603 9.8

The OPTIONS method vulnerability in Yokogawa FAST/TOOLS web servers exposes HTTP method information that could aid attackers in reconnaissance and sub...

📅 26 days ago • Feb 9, 2026
CVE-2025-15027 9.8

The JAY Login & Register WordPress plugin allows unauthenticated attackers to update arbitrary user metadata through a vulnerable AJAX function, enabl...

📅 27 days ago • Feb 8, 2026
CVE-2026-25858 9.8

This vulnerability allows unauthenticated attackers to reset passwords for any user account by exploiting a flawed OTP verification process in the pas...

📅 27 days ago • Feb 7, 2026
CVE-2020-37162 9.8

CVE-2020-37162 is a critical buffer overflow vulnerability in Wedding Slideshow Studio 1.36 that allows remote attackers to execute arbitrary code by ...

📅 28 days ago • Feb 7, 2026
CVE-2020-37161 9.8

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability in the registration name field that allows attackers to execute arbitrary code....

📅 28 days ago • Feb 7, 2026
CVE-2026-25803 9.8

3DP-MANAGER versions 2.0.1 and earlier automatically create an administrative account with default credentials (admin/admin) on first initialization. ...

📅 28 days ago • Feb 6, 2026
CVE-2026-25544 9.8

This is a critical SQL injection vulnerability in Payload CMS versions before 3.73.0 that allows unauthenticated attackers to extract sensitive data a...

📅 28 days ago • Feb 6, 2026
CVE-2026-1731 9.8

BeyondTrust Remote Support and older Privileged Remote Access versions contain a critical pre-authentication remote code execution vulnerability. Unau...

📅 28 days ago • Feb 6, 2026
CVE-2026-25753 9.8

PlaciPy placement management system version 1.0.0 uses a hard-coded default password for all newly created student accounts, enabling attackers to log...

📅 28 days ago • Feb 6, 2026
CVE-2025-64111 9.8

This vulnerability allows attackers to modify files in the .git directory of Gogs installations, potentially leading to remote command execution. It a...

📅 28 days ago • Feb 6, 2026
CVE-2026-2017 9.8

A critical stack-based buffer overflow vulnerability in IP-COM W30AP access points allows remote attackers to execute arbitrary code or crash the devi...

📅 29 days ago • Feb 6, 2026
CVE-2026-21643 9.8

An unauthenticated SQL injection vulnerability in Fortinet FortiClientEMS allows attackers to execute arbitrary SQL commands via crafted HTTP requests...

📅 29 days ago • Feb 6, 2026
CVE-2026-1499 9.8

The WP Duplicate plugin for WordPress has a critical vulnerability that allows authenticated attackers with subscriber-level access to upload arbitrar...

📅 29 days ago • Feb 6, 2026
CVE-2026-24300 9.8

This critical vulnerability in Azure Front Door allows attackers to bypass authentication and authorization controls, potentially gaining unauthorized...

📅 29 days ago • Feb 5, 2026
CVE-2020-37125 9.8

CVE-2020-37125 is a critical remote code execution vulnerability in Edimax EW-7438RPn-v3 Mini range extenders that allows unauthenticated attackers to...

📅 29 days ago • Feb 5, 2026
CVE-2026-28536 9.6

This CVE describes an authentication bypass vulnerability in Huawei device authentication modules that allows attackers to bypass authentication mecha...

📅 2 days ago • Mar 5, 2026
CVE-2025-69969 9.6

This critical vulnerability in Pebble Prism Ultra v2.9.2 allows attackers within Bluetooth range to execute arbitrary commands, intercept data, and hi...

📅 2 days ago • Mar 4, 2026
CVE-2025-69771 9.6

This vulnerability in asbplayer v1.13.0 allows attackers to upload malicious subtitle files that can execute arbitrary code on the system. Users of as...

📅 9 days ago • Feb 25, 2026
CVE-2026-22208 9.6

OpenS100 (S-100 viewer reference implementation) contains a remote code execution vulnerability where untrusted portrayal catalogues can execute arbit...

📅 18 days ago • Feb 17, 2026
CVE-2026-0509 9.6

This vulnerability allows authenticated low-privileged users in SAP NetWeaver ABAP systems to execute unauthorized background Remote Function Calls, b...

📅 25 days ago • Feb 10, 2026
CVE-2025-66606 9.6

A URL encoding vulnerability in Yokogawa's FAST/TOOLS industrial control system allows attackers to manipulate web pages or execute malicious scripts....

📅 26 days ago • Feb 9, 2026
CVE-2026-26288 9.4

This vulnerability allows unauthenticated attackers to impersonate legitimate charging stations by connecting to WebSocket endpoints without proper au...

🔥 Today • Mar 6, 2026
CVE-2026-26051 9.4

This CVE describes a critical authentication bypass vulnerability in WebSocket endpoints used for OCPP (Open Charge Point Protocol) communication. Att...

⚡ Yesterday • Mar 6, 2026
CVE-2026-22552 9.4

This vulnerability allows unauthenticated attackers to impersonate legitimate charging stations by connecting to WebSocket endpoints without proper au...

⚡ Yesterday • Mar 6, 2026
CVE-2026-1678 9.4

This vulnerability in Zephyr RTOS's DNS resolver allows an out-of-bounds write when processing malicious DNS responses. Attackers can exploit this to ...

📅 2 days ago • Mar 5, 2026
CVE-2026-26980 9.4

CVE-2026-26980 is an SQL injection vulnerability in Ghost CMS that allows unauthenticated attackers to read arbitrary data from the database. This aff...

📅 15 days ago • Feb 20, 2026
CVE-2025-8668 9.4

This is a reflected cross-site scripting (XSS) vulnerability in Turboard software that allows attackers to inject malicious scripts into web pages. Us...

📅 24 days ago • Feb 11, 2026
CVE-2025-66630 9.4

Fiber web framework versions before 2.52.11 on Go versions prior to 1.24 may generate predictable UUIDs when crypto/rand fails to obtain secure random...

📅 25 days ago • Feb 9, 2026
CVE-2026-1709 9.4

Keylime versions 7.12.0 and later have a critical authentication bypass vulnerability where the registrar fails to enforce client-side TLS certificate...

📅 28 days ago • Feb 6, 2026
CVE-2026-29183 9.3

An unauthenticated reflected XSS vulnerability in SiYuan's dynamic icon API allows attackers to inject malicious JavaScript via crafted SVG images. Wh...

⚡ Yesterday • Mar 6, 2026
CVE-2026-28680 9.3

Ghostfolio versions before 2.245.0 contain a server-side request forgery (SSRF) vulnerability in the manual asset import feature. Attackers can exploi...

⚡ Yesterday • Mar 6, 2026
CVE-2026-26266 9.3

A stored cross-site scripting (XSS) vulnerability in AliasVault Web Client allows attackers to inject malicious JavaScript into emails sent to any Ali...

📅 3 days ago • Mar 3, 2026
CVE-2026-27614 9.3

This is a stored cross-site scripting (XSS) vulnerability in Bugsink error tracking software. Unauthenticated attackers who can submit error events to...

📅 10 days ago • Feb 25, 2026
CVE-2026-27593 9.3

This vulnerability in Statmatic CMS allows attackers to hijack password reset tokens and take over user accounts. Attackers need a valid email address...

📅 10 days ago • Feb 24, 2026
CVE-2026-25896 9.3

CVE-2026-25896 is a vulnerability in fast-xml-parser where a dot (.) in a DOCTYPE entity name is treated as a regex wildcard during entity replacement...

📅 14 days ago • Feb 20, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free