🔥 Trending CVEs - Last 90 Days
4,483 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
This CVE describes a remote code execution vulnerability in PHPUnit's PHPT test execution when code coverage instrumentation is enabled. Attackers wit...
📅 43 days ago • Jan 27, 2026An integer overflow vulnerability in yoyofr modizer allows attackers to cause memory corruption by providing specially crafted input. This affects all...
📅 43 days ago • Jan 27, 2026An out-of-bounds read vulnerability in Rinnegatamante's lpp-vita software allows attackers to read memory beyond allocated buffers. This affects PlayS...
📅 43 days ago • Jan 27, 2026This vulnerability allows attackers to cause denial-of-service or memory corruption by exhausting the ThreadX RTOS counter pool. When the pool is depl...
📅 43 days ago • Jan 27, 2026This vulnerability allows a local low-privileged attacker to bypass authentication in the Device Manager user interface, enabling them to perform priv...
📅 44 days ago • Jan 27, 2026CVE-2026-1361 is a stack-based buffer overflow vulnerability in Delta Electronics' ASDA-Soft software that allows attackers to execute arbitrary code ...
📅 44 days ago • Jan 27, 2026This vulnerability in Microsoft Office allows an attacker to bypass local security features by manipulating untrusted inputs. It affects users running...
📅 44 days ago • Jan 26, 2026An out-of-bounds write vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open malicious EPRT files. This aff...
📅 44 days ago • Jan 26, 2026A heap-based buffer overflow vulnerability in SOLIDWORKS eDrawings allows attackers to execute arbitrary code when users open malicious EPRT files. Th...
📅 44 days ago • Jan 26, 2026A use-after-free vulnerability in the Linux kernel's Tegra ADMA driver allows memory corruption when audio streams terminate during XRUN conditions. T...
📅 45 days ago • Jan 25, 2026A local OS command injection vulnerability in the com.sprd.engineermode component on Doogee Note59 series devices allows attackers with ADB shell acce...
📅 47 days ago • Jan 23, 2026Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service, which runs with LocalSystem privileges. Attackers c...
📅 47 days ago • Jan 23, 2026CVE-2021-47896 is an unquoted service path vulnerability in PDF Complete Corporate Edition's pdfcDispatcher service. Local attackers can exploit this ...
📅 47 days ago • Jan 23, 2026Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to execute ...
📅 47 days ago • Jan 23, 2026LogonExpert 8.1 contains an unquoted service path vulnerability in the LogonExpertSvc service. Attackers can place malicious executables in intermedia...
📅 47 days ago • Jan 23, 2026A race condition in the Linux kernel's ublk driver allows use-after-free when partition scanning occurs during device teardown. This vulnerability cou...
📅 47 days ago • Jan 23, 2026This CVE describes a race condition vulnerability in the Linux kernel's NFS server (nfsd) that can lead to use-after-free memory corruption. The issue...
📅 47 days ago • Jan 23, 2026This Linux kernel vulnerability in the DSA (Distributed Switch Architecture) subsystem mishandles reference counting for conduit network devices, pote...
📅 47 days ago • Jan 23, 2026This CVE addresses a memory corruption vulnerability in the KVM (Kernel-based Virtual Machine) subsystem for s390 architecture in the Linux kernel. Mi...
📅 47 days ago • Jan 23, 2026A race condition vulnerability in the Linux kernel's gve (Google Virtual Ethernet) driver where interrupts could fire before NAPI (New API) context in...
📅 47 days ago • Jan 23, 2026A reference counting vulnerability in the Linux kernel's RDMA subsystem could lead to resource exhaustion or kernel instability. The issue occurs when...
📅 47 days ago • Jan 23, 2026A use-after-free vulnerability in the Linux kernel's USB PHY driver (isp1301) allows potential kernel memory corruption when handling non-OF (Open Fir...
📅 47 days ago • Jan 23, 2026This is a command injection vulnerability in the mcp-server-siri-shortcuts software that allows local attackers to escalate privileges. Attackers with...
📅 48 days ago • Jan 23, 2026This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious SKP files in Trimble SketchUp. Attackers...
📅 48 days ago • Jan 23, 2026This vulnerability allows remote attackers to execute arbitrary code on Anritsu ShockLine systems by tricking users into opening malicious CHX files. ...
📅 48 days ago • Jan 23, 2026A deserialization vulnerability in Anritsu VectorStar's CHX file parser allows remote attackers to execute arbitrary code when a user opens a maliciou...
📅 48 days ago • Jan 23, 2026This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CHX files or visiting malicious pages. I...
📅 48 days ago • Jan 23, 2026A directory traversal vulnerability in 7-Zip's ZIP file parsing allows remote attackers to execute arbitrary code by crafting malicious ZIP archives c...
📅 48 days ago • Jan 23, 2026This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious PSP files in GIMP. The heap-based buffer...
📅 48 days ago • Jan 23, 2026This vulnerability allows arbitrary file write through path traversal in archive extraction functions. Attackers can place malicious archives that ext...
📅 48 days ago • Jan 23, 2026CVE-2026-1260 is an invalid memory access vulnerability in Sentencepiece versions before 0.2.1 that occurs when processing specially crafted model fil...
📅 48 days ago • Jan 22, 2026CVE-2021-47887 is an unquoted service path vulnerability in OKI Print Job Accounting 4.4.10 that allows local attackers to execute arbitrary code with...
📅 49 days ago • Jan 21, 2026FreeLAN 2.2 on Windows contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with LocalSystem privileg...
📅 49 days ago • Jan 21, 2026CVE-2021-47883 is an unquoted service path vulnerability in Sandboxie Plus's SbieSvc service that allows local attackers to execute arbitrary code wit...
📅 49 days ago • Jan 21, 2026CVE-2021-47884 is an unquoted service path vulnerability in OKI Configuration Tool 1.6.53 that allows local attackers to execute arbitrary code with e...
📅 49 days ago • Jan 21, 2026CVE-2021-47886 is an unquoted service path vulnerability in Pingzapper 2.3.1 that allows local attackers to execute arbitrary code with elevated privi...
📅 49 days ago • Jan 21, 2026CVE-2021-47879 is an unquoted service path vulnerability in eBeam Interactive Suite 3.6's eBeam Stylus Driver service. Local attackers can place malic...
📅 49 days ago • Jan 21, 2026CVE-2021-47880 is an unquoted service path vulnerability in Realtek Wireless LAN Utility that allows local attackers to execute arbitrary code with SY...
📅 49 days ago • Jan 21, 2026CVE-2021-47878 is an unquoted service path vulnerability in eBeam Education Suite's Device Service that allows local attackers to execute arbitrary co...
📅 49 days ago • Jan 21, 2026CVE-2021-47874 is an unquoted service path vulnerability in VFS for Git's GVFS.Service Windows service that allows local attackers to execute arbitrar...
📅 49 days ago • Jan 21, 2026CVE-2021-47868 is an unquoted service path vulnerability in WIN-PACK PRO 4.8's WPCommandFileService that allows local attackers to execute arbitrary c...
📅 49 days ago • Jan 21, 2026CVE-2021-47869 is an unquoted service path vulnerability in Brother BRAdmin Professional 3.75's BRA_Scheduler service. This allows local attackers to ...
📅 49 days ago • Jan 21, 2026CVE-2021-47864 is an unquoted service path vulnerability in OSAS Traverse Extension 11's TravExtensionHostSvc service. Attackers with local access can...
📅 49 days ago • Jan 21, 2026WIN-PACK PRO 4.8 contains an unquoted service path vulnerability in GuardTourService that allows local attackers to execute arbitrary code with SYSTEM...
📅 49 days ago • Jan 21, 2026CVE-2021-47867 is an unquoted service path vulnerability in WIN-PACK PRO 4.8's ScheduleService that allows local attackers to execute arbitrary code w...
📅 49 days ago • Jan 21, 2026Event Log Explorer 4.9.3 has an unquoted service path vulnerability that allows local attackers to execute arbitrary code with SYSTEM privileges. Atta...
📅 49 days ago • Jan 21, 2026CVE-2021-47862 is an unquoted service path vulnerability in Hi-Rez Studios' HiPatchService that allows local attackers to execute arbitrary code with ...
📅 49 days ago • Jan 21, 2026CVE-2021-47863 is an unquoted service path vulnerability in MacPaw Encrypto that allows local attackers to execute arbitrary code with elevated privil...
📅 49 days ago • Jan 21, 2026CVE-2021-47859 is an unquoted service path vulnerability in ActivIdentity 8.2's ac.sharedstore service that allows local attackers to execute arbitrar...
📅 49 days ago • Jan 21, 2026This vulnerability allows attackers to execute arbitrary code with administrator privileges by exploiting insecure DLL loading in the ServerView Agent...
📅 50 days ago • Jan 21, 2026Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats