🔥 Trending CVEs - Last 90 Days

4,668 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
12,065
Total CVEs Published
1,037
Critical Severity
3,631
High Severity
⚠️
Critical Alert
1,037 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-69301 9.8

This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting insecure deserialization in the PhotoMe WordP...

📅 14 days ago • Feb 20, 2026
CVE-2025-68541 9.8

This vulnerability in the BoldThemes Ippsum WordPress theme allows attackers to inject malicious objects through deserialization of untrusted data. It...

📅 14 days ago • Feb 20, 2026
CVE-2025-67996 9.8

This CVE describes a PHP object injection vulnerability in the BoldThemes Nestin WordPress theme. Attackers can exploit insecure deserialization to ex...

📅 14 days ago • Feb 20, 2026
CVE-2025-10970 9.8

This is a critical SQL injection vulnerability in Kolay Software Inc.'s Talentics platform that allows attackers to execute arbitrary SQL commands. It...

📅 15 days ago • Feb 20, 2026
CVE-2025-30410 9.8

This critical vulnerability allows attackers to access and manipulate sensitive data without authentication in Acronis Cyber Protect products. It affe...

📅 15 days ago • Feb 20, 2026
CVE-2026-27002 9.8

OpenClaw's Docker sandbox configuration injection vulnerability allows attackers to escape container isolation and access the host system. This affect...

📅 15 days ago • Feb 20, 2026
CVE-2026-27476 9.8

RustFly 2.0.0 contains a critical command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP po...

📅 15 days ago • Feb 19, 2026
CVE-2025-67305 9.8

RUCKUS Network Director (RND) OVA appliances contain identical hardcoded SSH keys for the postgres user across all deployments, allowing attackers wit...

📅 15 days ago • Feb 19, 2026
CVE-2026-26339 9.8

CVE-2026-26339 is a critical argument injection vulnerability in Hyland Alfresco Transformation Service that allows unauthenticated attackers to execu...

📅 15 days ago • Feb 19, 2026
CVE-2025-71243 9.8

The Saisies plugin for SPIP contains a critical Remote Code Execution vulnerability (CWE-94: Improper Control of Generation of Code) that allows attac...

📅 15 days ago • Feb 19, 2026
CVE-2025-8350 9.8

This vulnerability in BiEticaret CMS allows attackers to bypass authentication and manipulate HTTP responses through Execution After Redirect and Miss...

📅 16 days ago • Feb 19, 2026
CVE-2025-15559 9.8

CVE-2025-15559 is an unauthenticated OS command injection vulnerability in NesterSoft WorkTime server's client generation API. Attackers can execute a...

📅 16 days ago • Feb 19, 2026
CVE-2026-23542 9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the Grand Restaurant WordPress theme. Suc...

📅 16 days ago • Feb 19, 2026
CVE-2026-23549 9.8

This vulnerability allows attackers to inject malicious objects through deserialization of untrusted data in the WpEvently mage-eventpress WordPress p...

📅 16 days ago • Feb 19, 2026
CVE-2026-1994 9.8

The s2Member WordPress plugin has a critical vulnerability that allows unauthenticated attackers to change any user's password, including administrato...

📅 16 days ago • Feb 19, 2026
CVE-2026-1405 9.8

The Slider Future WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This vulnerability ...

📅 16 days ago • Feb 19, 2026
CVE-2026-0926 9.8

The Prodigy Commerce WordPress plugin has a Local File Inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execut...

📅 16 days ago • Feb 19, 2026
CVE-2025-13851 9.8

The Buyent Classified plugin for WordPress allows unauthenticated attackers to register accounts with administrator privileges by manipulating the use...

📅 16 days ago • Feb 19, 2026
CVE-2025-13563 9.8

This vulnerability allows unauthenticated attackers to register as administrators on WordPress sites using the Lizza LMS Pro plugin. All WordPress sit...

📅 16 days ago • Feb 19, 2026
CVE-2025-12882 9.8

The Clasifico Listing WordPress plugin allows unauthenticated attackers to register accounts with administrator privileges by manipulating the 'listin...

📅 16 days ago • Feb 19, 2026
CVE-2026-2686 9.8

This CVE describes a remote command injection vulnerability in SECCN Dingcheng G10 software version 3.1.0.181203. Attackers can execute arbitrary oper...

📅 16 days ago • Feb 19, 2026
CVE-2026-27180 9.8

CVE-2026-27180 allows unauthenticated attackers to execute arbitrary code on MajorDoMo systems by poisoning the update URL. Attackers can deploy websh...

📅 16 days ago • Feb 18, 2026
CVE-2026-27174 9.8

CVE-2026-27174 allows unauthenticated attackers to execute arbitrary PHP code on MajorDoMo home automation systems via the admin panel's PHP console. ...

📅 16 days ago • Feb 18, 2026
CVE-2019-25364 9.8

MailCarrier 2.51 contains a critical buffer overflow vulnerability in its POP3 service that allows remote attackers to execute arbitrary code by sendi...

📅 16 days ago • Feb 18, 2026
CVE-2019-25360 9.8

CVE-2019-25360 is a critical buffer overflow vulnerability in Aida64 Engineer's CSV logging configuration that allows remote code execution. Attackers...

📅 16 days ago • Feb 18, 2026
CVE-2019-25362 9.8

CVE-2019-25362 is a critical buffer overflow vulnerability in WMV to AVI MPEG DVD WMV Convertor 4.6.1217 that allows remote attackers to execute arbit...

📅 16 days ago • Feb 18, 2026
CVE-2025-70152 9.8

CVE-2025-70152 is an unauthenticated SQL injection vulnerability in the Community Project Scholars Tracking System 1.0 that allows attackers to execut...

📅 16 days ago • Feb 18, 2026
CVE-2025-70150 9.8

CVE-2025-70150 is a critical missing authentication vulnerability in CodeAstro Membership Management System 1.0 that allows unauthenticated attackers ...

📅 16 days ago • Feb 18, 2026
CVE-2025-70149 9.8

CodeAstro Membership Management System 1.0 contains a SQL injection vulnerability in the print_membership_card.php file via the ID parameter. This all...

📅 16 days ago • Feb 18, 2026
CVE-2025-65791 9.8

CVE-2025-65791 is a critical command injection vulnerability in ZoneMinder's image.php component that allows attackers to execute arbitrary commands o...

📅 16 days ago • Feb 18, 2026
CVE-2025-70998 9.8

This vulnerability allows remote attackers to gain root access to UTT HiPER 810 / nv810v4 routers via telnet using insecure default credentials. Attac...

📅 16 days ago • Feb 18, 2026
CVE-2026-2329 9.8

An unauthenticated stack-based buffer overflow vulnerability in Grandstream GXP1600 series VoIP phones allows remote attackers to execute arbitrary co...

📅 17 days ago • Feb 18, 2026
CVE-2026-1937 9.8

The YayMail WordPress plugin has a privilege escalation vulnerability that allows authenticated attackers with Shop Manager access or higher to modify...

📅 17 days ago • Feb 18, 2026
CVE-2026-1670 9.8

This vulnerability allows unauthenticated attackers to remotely change the password recovery email address via an exposed API endpoint. This affects H...

📅 17 days ago • Feb 17, 2026
CVE-2026-23647 9.8

CVE-2026-23647 allows attackers to remotely authenticate to Glory RBG-100 recycler systems using hard-coded Linux credentials, including administrativ...

📅 17 days ago • Feb 17, 2026
CVE-2026-2439 9.8

CVE-2026-2439 is a session ID generation vulnerability in Concierge::Sessions for Perl that allows attackers to guess session identifiers and gain una...

📅 18 days ago • Feb 16, 2026
CVE-2026-2550 9.8

This vulnerability allows remote attackers to upload arbitrary files without restrictions to EFM iptime A6004MX routers via the commit_vpncli_file_upl...

📅 19 days ago • Feb 16, 2026
CVE-2026-26369 9.8

CVE-2026-26369 is a privilege escalation vulnerability in eNet SMART HOME server where low-privileged users can elevate themselves to administrative p...

📅 19 days ago • Feb 15, 2026
CVE-2026-26366 9.8

eNet SMART HOME server versions 2.2.1 and 2.3.1 ship with active default credentials (user:user, admin:admin) that don't require password changes duri...

📅 19 days ago • Feb 15, 2026
CVE-2026-1490 9.8

This vulnerability allows unauthenticated attackers to bypass authorization and install arbitrary WordPress plugins via reverse DNS spoofing. It affec...

📅 20 days ago • Feb 15, 2026
CVE-2025-8572 9.8

The Truelysell Core WordPress plugin allows unauthenticated attackers to create administrator accounts due to insufficient validation of the user_role...

📅 21 days ago • Feb 14, 2026
CVE-2026-1306 9.8

The midi-Synth WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing validation in the 'export' AJAX action. This...

📅 21 days ago • Feb 14, 2026
CVE-2026-26273 9.8

Known social publishing platform versions 1.6.2 and earlier contain a critical authentication bypass vulnerability where password reset tokens are exp...

📅 21 days ago • Feb 13, 2026
CVE-2026-26333 9.8

Calero VeraSMART versions before 2022 R1 expose an unauthenticated .NET Remoting service on port 8001, allowing remote attackers to read/write arbitra...

📅 21 days ago • Feb 13, 2026
CVE-2026-26335 9.8

This vulnerability allows attackers to achieve remote code execution on Calero VeraSMART servers by exploiting static ASP.NET machine keys. Attackers ...

📅 21 days ago • Feb 13, 2026
CVE-2026-26190 9.8

This critical vulnerability in Milvus vector database allows unauthenticated attackers to bypass authentication and execute arbitrary operations. Atta...

📅 21 days ago • Feb 13, 2026
CVE-2019-25337 9.8

CVE-2019-25337 is a username enumeration vulnerability in ownCloud that allows remote attackers to discover valid user accounts by sending crafted req...

📅 22 days ago • Feb 12, 2026
CVE-2019-25327 9.8

CVE-2019-25327 is a critical buffer overflow vulnerability in Prime95 version 29.8 build 6 that allows remote attackers to execute arbitrary code by c...

📅 22 days ago • Feb 12, 2026
CVE-2019-25319 9.8

CVE-2019-25319 is a critical stack overflow vulnerability in Domain Quester Pro 6.02 that allows remote attackers to execute arbitrary code by exploit...

📅 22 days ago • Feb 12, 2026
CVE-2019-25321 9.8

CVE-2019-25321 is a critical stack overflow vulnerability in FTP Navigator 8.03 that allows attackers to execute arbitrary code by exploiting Structur...

📅 22 days ago • Feb 12, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free