🔥 Trending CVEs - Last 90 Days

4,484 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,079
Total CVEs Published
990
Critical Severity
3,494
High Severity
⚠️
Critical Alert
990 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-25181 7.5

This vulnerability in Windows GDI+ allows attackers to read memory beyond intended boundaries, potentially leaking sensitive information. It affects W...

📅 2 days ago • Mar 10, 2026
CVE-2026-23662 7.5

CVE-2026-23662 is a missing authentication vulnerability in Azure IoT Explorer that allows unauthorized attackers to access sensitive information over...

📅 2 days ago • Mar 10, 2026
CVE-2026-28691 7.5

An uninitialized pointer dereference vulnerability in ImageMagick's JBIG decoder allows attackers to cause denial of service or potentially execute ar...

📅 2 days ago • Mar 10, 2026
CVE-2025-62166 7.5

FreshRSS versions before 1.28.0 contain an authentication bypass vulnerability in master token logic. When anonymous viewing is enabled, attackers can...

📅 3 days ago • Mar 9, 2026
CVE-2025-61614 7.5

This vulnerability in nr modem allows remote attackers to cause a system crash through improper input validation, leading to denial of service without...

📅 3 days ago • Mar 9, 2026
CVE-2025-61616 7.5

This vulnerability in nr modem software allows remote attackers to cause a system crash through improper input validation, leading to denial of servic...

📅 3 days ago • Mar 9, 2026
CVE-2025-69279 7.5

This vulnerability in nr modem allows remote attackers to cause a system crash through improper input validation, leading to denial of service. It aff...

📅 3 days ago • Mar 9, 2026
CVE-2025-41772 7.5

An unauthenticated remote attacker can steal valid session tokens from UBR devices because tokens are exposed in plaintext within URL parameters of th...

📅 3 days ago • Mar 9, 2026
CVE-2025-61612 7.5

This vulnerability in nr modem allows remote attackers to cause a system crash through improper input validation, leading to denial of service without...

📅 3 days ago • Mar 9, 2026
CVE-2026-29784 7.5

Ghost CMS versions 5.101.6 through 6.19.2 have incomplete CSRF protections in the session verification endpoint, allowing attackers to use one-time co...

📅 5 days ago • Mar 7, 2026
CVE-2026-30827 7.5

A vulnerability in express-rate-limit middleware versions 8.0.0 through 8.3.0 causes all IPv4 clients to share the same rate-limit bucket when using I...

📅 5 days ago • Mar 7, 2026
CVE-2026-2020 7.5

The JS Archive List WordPress plugin is vulnerable to PHP object injection through the 'included' shortcode attribute. Authenticated attackers with Co...

📅 6 days ago • Mar 7, 2026
CVE-2025-14353 7.5

This SQL injection vulnerability in the WordPress ZIP Code Based Content Protection plugin allows unauthenticated attackers to inject malicious SQL qu...

📅 6 days ago • Mar 7, 2026
CVE-2026-29087 7.5

This vulnerability allows attackers to bypass route-based middleware protections in @hono/node-server applications by using URL-encoded slashes (%2F) ...

📅 6 days ago • Mar 6, 2026
CVE-2026-24696 7.5

This vulnerability allows attackers to bypass rate limiting on WebSocket authentication requests, enabling denial-of-service attacks that disrupt legi...

📅 6 days ago • Mar 6, 2026
CVE-2026-26018 7.5

A denial of service vulnerability in CoreDNS's loop detection plugin allows attackers to crash DNS servers by sending specially crafted DNS queries. T...

📅 6 days ago • Mar 6, 2026
CVE-2026-2753 7.5

An absolute path traversal vulnerability in Navtor NavBox allows unauthenticated remote attackers to read arbitrary files from the filesystem. This af...

📅 6 days ago • Mar 6, 2026
CVE-2018-25193 7.5

Mongoose Web Server 6.9 contains a denial of service vulnerability where remote attackers can crash the service by establishing multiple socket connec...

📅 6 days ago • Mar 6, 2026
CVE-2018-25178 7.5

Easyndexer 1.0 contains an unauthenticated arbitrary file download vulnerability that allows attackers to retrieve sensitive system files by manipulat...

📅 6 days ago • Mar 6, 2026
CVE-2018-25169 7.5

AMPPS 2.7 contains a denial of service vulnerability where remote attackers can crash the service by sending malformed data to the default HTTP port. ...

📅 6 days ago • Mar 6, 2026
CVE-2026-29074 7.5

SVGO versions 2.1.0-2.8.0, 3.0.0-3.3.2, and before 4.0.1 are vulnerable to XML entity expansion attacks. Attackers can craft small malicious SVG files...

📅 6 days ago • Mar 6, 2026
CVE-2026-28429 7.5

This CVE describes a path traversal vulnerability in Talishar, a fan-made Flesh and Blood project, where the ParseGamestate.php component can be acces...

📅 6 days ago • Mar 6, 2026
CVE-2026-27778 7.5

This CVE describes a WebSocket API vulnerability where missing rate limiting on authentication requests allows attackers to conduct denial-of-service ...

📅 7 days ago • Mar 6, 2026
CVE-2026-28479 7.5

OpenClaw versions before 2026.2.15 use deprecated SHA-1 hashing for sandbox identifier cache keys, making them vulnerable to collision attacks. Attack...

📅 7 days ago • Mar 5, 2026
CVE-2026-28469 7.5

OpenClaw versions before 2026.2.14 have a webhook routing vulnerability in the Google Chat monitor component that allows attackers to misroute webhook...

📅 7 days ago • Mar 5, 2026
CVE-2026-28462 7.5

OpenClaw versions before 2026.2.13 contain a path traversal vulnerability in browser control API endpoints that handle trace and download files. Attac...

📅 7 days ago • Mar 5, 2026
CVE-2026-28454 7.5

OpenClaw versions before 2026.2.2 fail to validate Telegram webhook secrets, allowing unauthenticated attackers to send forged Telegram updates. This ...

📅 7 days ago • Mar 5, 2026
CVE-2026-28789 7.5

CVE-2026-28789 is an unauthenticated denial-of-service vulnerability in OliveTin's OAuth2 login flow. Attackers can crash the service by sending concu...

📅 7 days ago • Mar 5, 2026
CVE-2026-28342 7.5

CVE-2026-28342 is an unauthenticated denial-of-service vulnerability in OliveTin's PasswordHash API endpoint. Attackers can send concurrent password h...

📅 7 days ago • Mar 5, 2026
CVE-2026-29054 7.5

This vulnerability allows remote unauthenticated attackers to bypass Traefik's protection mechanisms and remove critical X-Forwarded headers that iden...

📅 7 days ago • Mar 5, 2026
CVE-2026-26999 7.5

This vulnerability allows remote unauthenticated attackers to cause denial of service in Traefik by exploiting a TLS handshake flaw. Attackers can sen...

📅 7 days ago • Mar 5, 2026
CVE-2026-1605 7.5

This vulnerability in Eclipse Jetty's GzipHandler causes a memory leak when processing compressed HTTP requests without compressed responses. Attacker...

📅 7 days ago • Mar 5, 2026
CVE-2026-29045 7.5

This vulnerability in Hono web framework allows attackers to bypass route-based middleware protections (like authentication) for static files by using...

📅 8 days ago • Mar 4, 2026
CVE-2026-28435 7.5

This vulnerability in cpp-httplib allows attackers to bypass configured payload size limits by sending compressed HTTP requests. When using streaming ...

📅 8 days ago • Mar 4, 2026
CVE-2026-26514 7.5

An argument injection vulnerability in bird-lg-go's traceroute module allows remote attackers to inject arbitrary command-line flags via the q paramet...

📅 8 days ago • Mar 4, 2026
CVE-2023-7337 7.5

This SQL injection vulnerability in the JS Help Desk WordPress plugin allows unauthenticated attackers to inject malicious SQL queries via a cookie pa...

📅 8 days ago • Mar 4, 2026
CVE-2026-27932 7.5

This vulnerability allows unauthenticated attackers to cause CPU exhaustion denial-of-service by sending specially crafted JWE tokens with extremely h...

📅 9 days ago • Mar 3, 2026
CVE-2024-55019 7.5

This vulnerability allows unauthenticated attackers to download arbitrary files from Weintek cMT-3072XH2 HMI devices via the download_wb.cgi component...

📅 9 days ago • Mar 3, 2026
CVE-2026-3338 7.5

This vulnerability allows unauthenticated attackers to bypass signature verification in PKCS7 objects with Authenticated Attributes in AWS-LC. It affe...

📅 10 days ago • Mar 2, 2026
CVE-2026-3336 7.5

A certificate validation bypass vulnerability in AWS-LC's PKCS7_verify() function allows unauthenticated attackers to bypass certificate chain verific...

📅 10 days ago • Mar 2, 2026
CVE-2026-27959 7.5

This vulnerability in Koa.js allows attackers to inject malicious hostnames via specially crafted HTTP Host headers containing '@' symbols. Applicatio...

📅 15 days ago • Feb 26, 2026
CVE-2026-27903 7.5

This vulnerability in minimatch allows attackers to cause denial of service by crafting glob patterns with multiple non-adjacent ** segments, causing ...

📅 15 days ago • Feb 26, 2026
CVE-2026-1557 7.5

The WP Responsive Images WordPress plugin contains a path traversal vulnerability in the 'src' parameter that allows unauthenticated attackers to read...

📅 15 days ago • Feb 26, 2026
CVE-2026-27888 7.5

This vulnerability in pypdf allows attackers to craft malicious PDF files that cause denial of service by exhausting system RAM when the XFA property ...

📅 15 days ago • Feb 26, 2026
CVE-2026-27831 7.5

CVE-2026-27831 is a heap-based out-of-bounds read vulnerability in rldns DNS server version 2.3 that can cause denial of service. The vulnerability al...

📅 15 days ago • Feb 26, 2026
CVE-2026-27635 7.5

This vulnerability allows authenticated users to achieve remote code execution by uploading a ZIP file containing a file with shell metacharacters in ...

📅 15 days ago • Feb 26, 2026
CVE-2026-27630 7.5

TinyWeb versions before 2.02 are vulnerable to Slowloris denial-of-service attacks where attackers can exhaust server resources by opening many connec...

📅 15 days ago • Feb 26, 2026
CVE-2026-26986 7.5

This is a use-after-free vulnerability in FreeRDP's X11 client implementation where a freed pointer is dereferenced during cleanup. An attacker could ...

📅 15 days ago • Feb 25, 2026
CVE-2026-25942 7.5

This vulnerability in FreeRDP allows a malicious RDP server to trigger an out-of-bounds read by sending an execResult value of 7 or greater. This coul...

📅 15 days ago • Feb 25, 2026
CVE-2026-1662 7.5

An unauthenticated attacker can cause Denial of Service on GitLab instances by sending specially crafted requests to the Jira events endpoint. This af...

📅 15 days ago • Feb 25, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free