🔥 Trending CVEs - Last 30 Days

1,262 critical and high-severity vulnerabilities discovered in the last 30 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
2,778
Total CVEs Published
304
Critical Severity
958
High Severity
⚠️
Critical Alert
304 critical vulnerabilities published in the last 30 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-24956 9.3

This SQL injection vulnerability in Download Manager Addons for Elementor allows attackers to execute arbitrary SQL commands against the WordPress dat...

📅 15 days ago • Feb 20, 2026
CVE-2025-69337 9.3

This SQL injection vulnerability in the Wolmart Core WordPress plugin allows attackers to execute arbitrary SQL commands on affected databases. It aff...

📅 15 days ago • Feb 20, 2026
CVE-2025-69366 9.3

This SQL injection vulnerability in the TeconceTheme Emerce Core WordPress plugin allows attackers to execute arbitrary SQL commands on the database. ...

📅 15 days ago • Feb 20, 2026
CVE-2025-69309 9.3

This SQL injection vulnerability in the Saasplate Core WordPress plugin allows attackers to execute arbitrary SQL commands against the database. It af...

📅 15 days ago • Feb 20, 2026
CVE-2025-69305 9.3

This SQL injection vulnerability in the Crete Core WordPress plugin allows attackers to execute arbitrary SQL commands against the database. It affect...

📅 15 days ago • Feb 20, 2026
CVE-2025-69307 9.3

This CVE describes a blind SQL injection vulnerability in the TeconceTheme Medinik Core WordPress plugin. Attackers can inject malicious SQL queries t...

📅 15 days ago • Feb 20, 2026
CVE-2026-24834 9.3

This vulnerability in Kata Containers allows a container user to modify the Guest micro VM's file system, leading to arbitrary code execution as root ...

📅 15 days ago • Feb 19, 2026
CVE-2025-32058 9.3

This vulnerability allows an attacker with code execution on the infotainment system's main processor to execute arbitrary code on the RH850 CAN commu...

📅 20 days ago • Feb 15, 2026
CVE-2026-0106 9.3

This vulnerability allows local attackers to map arbitrary memory addresses due to missing bounds checking in the vpu_mmap function. This can lead to ...

📅 29 days ago • Feb 5, 2026
CVE-2026-27208 9.2

This vulnerability allows attackers to execute arbitrary operating system commands with root privileges within the container running bleon-ethical/api...

📅 11 days ago • Feb 24, 2026
CVE-2026-29188 9.1

This broken access control vulnerability in File Browser allows authenticated users with only Create permission to delete files and directories they s...

⚡ Yesterday • Mar 5, 2026
CVE-2026-24457 9.1

CVE-2026-24457 is a path traversal vulnerability in OpenMQ's configuration parsing that allows remote attackers to read arbitrary files from the MQ Br...

⚡ Yesterday • Mar 5, 2026
CVE-2026-26279 9.1

A typo in Froxlor's input validation code (== instead of =) disables email format checking for admin email settings. This allows authenticated admins ...

📅 3 days ago • Mar 3, 2026
CVE-2026-27812 9.1

CVE-2026-27812 is a password reset poisoning vulnerability in Sub2API versions before 0.1.85 that allows attackers to manipulate password reset links ...

📅 9 days ago • Feb 26, 2026
CVE-2026-27575 9.1

This vulnerability in Vikunja task management software allows attackers to compromise accounts through weak password policies and maintain persistent ...

📅 9 days ago • Feb 25, 2026
CVE-2025-1242 9.1

This vulnerability allows attackers to extract administrative credentials from Gardyn IoT Hub through API responses, mobile app reverse engineering, o...

📅 10 days ago • Feb 25, 2026
CVE-2026-27699 9.1

The basic-ftp Node.js library contains a path traversal vulnerability in the downloadToDir() method. A malicious FTP server can send filenames contain...

📅 10 days ago • Feb 25, 2026
CVE-2026-0704 9.1

This vulnerability in Octopus Deploy allows attackers to delete files or file contents on the host system through an unauthenticated API endpoint lack...

📅 10 days ago • Feb 25, 2026
CVE-2026-27588 9.1

Caddy servers with host lists exceeding 100 entries have a case-sensitivity vulnerability in the HTTP host matcher. Attackers can bypass host-based ro...

📅 10 days ago • Feb 24, 2026
CVE-2026-27586 9.1

CVE-2026-27586 is a critical authentication bypass vulnerability in Caddy server where mTLS client certificate authentication silently fails open when...

📅 10 days ago • Feb 24, 2026
CVE-2026-2806 9.1

This vulnerability involves uninitialized memory in Firefox's Graphics: Text component, which could allow attackers to read sensitive data from memory...

📅 11 days ago • Feb 24, 2026
CVE-2025-40540 9.1

A type confusion vulnerability in SolarWinds Serv-U allows attackers with administrative privileges to execute arbitrary native code with elevated pri...

📅 11 days ago • Feb 24, 2026
CVE-2025-40538 9.1

A broken access control vulnerability in SolarWinds Serv-U allows domain or group administrators to create system admin users and execute arbitrary co...

📅 11 days ago • Feb 24, 2026
CVE-2024-58041 9.1

Smolder versions through 1.51 for Perl use the non-cryptographically secure rand() function for cryptographic operations, making generated values pred...

📅 11 days ago • Feb 24, 2026
CVE-2026-3061 9.1

This vulnerability allows a remote attacker to read memory outside the intended buffer in Chrome's media component by tricking a user into visiting a ...

📅 11 days ago • Feb 23, 2026
CVE-2025-70043 9.1

This vulnerability in Ayms node-To master branch disables TLS/SSL certificate validation, allowing man-in-the-middle attackers to intercept and manipu...

📅 12 days ago • Feb 23, 2026
CVE-2026-23552 9.1

The CVE-2026-23552 vulnerability allows attackers to bypass tenant isolation in Apache Camel Keycloak component by using JWT tokens from unauthorized ...

📅 12 days ago • Feb 23, 2026
CVE-2026-2588 9.1

This CVE describes an integer overflow vulnerability in Crypt::NaCl::Sodium Perl module versions through 2.001 on 32-bit systems. The flaw occurs when...

📅 12 days ago • Feb 23, 2026
CVE-2026-27197 9.1

This critical vulnerability in Sentry's SAML SSO implementation allows attackers to take over any user account by exploiting misconfigured multi-organ...

📅 14 days ago • Feb 21, 2026
CVE-2019-25444 9.1

This SQL injection vulnerability in Fiverr Clone Script 1.2.2 allows unauthenticated attackers to inject malicious SQL code through the page parameter...

📅 14 days ago • Feb 20, 2026
CVE-2026-26988 9.1

This SQL injection vulnerability in LibreNMS allows attackers to execute arbitrary SQL commands through the ajax_table.php endpoint when searching IPv...

📅 15 days ago • Feb 20, 2026
CVE-2025-55853 9.1

SoftVision webPDF versions before 10.0.2 contain a Server-Side Request Forgery (SSRF) vulnerability in the PDF converter function. Attackers can uploa...

📅 16 days ago • Feb 19, 2026
CVE-2026-25548 9.1

InvoicePlane 1.7.0 contains a critical Remote Code Execution vulnerability that allows authenticated administrators to execute arbitrary system comman...

📅 16 days ago • Feb 18, 2026
CVE-2025-70146 9.1

This vulnerability allows remote attackers to perform administrative operations without authentication in ProjectWorlds Online Time Table Generator 1....

📅 16 days ago • Feb 18, 2026
CVE-2026-25227 9.1

This vulnerability in authentik allows authenticated users with specific delegated permissions to execute arbitrary code on the authentik server conta...

📅 22 days ago • Feb 12, 2026
CVE-2026-25939 9.1

An authorization bypass vulnerability in FUXA web-based SCADA/HMI software allows unauthenticated remote attackers to create and modify arbitrary sche...

📅 25 days ago • Feb 9, 2026
CVE-2026-25811 9.1

PlaciPy placement management system version 1.0.0 allows cross-tenant data access by deriving tenant identifiers from user-provided email domains with...

📅 25 days ago • Feb 9, 2026
CVE-2026-25810 9.1

PlaciPy placement management system version 1.0.0 has an authorization vulnerability where authenticated users can access other users' student submiss...

📅 25 days ago • Feb 9, 2026
CVE-2026-25876 9.1

PlaciPy placement management system version 1.0.0 has a missing object-level authorization vulnerability that allows authenticated users to access ass...

📅 25 days ago • Feb 9, 2026
CVE-2026-25057 9.1

This vulnerability allows instructors to achieve arbitrary file write on the server by uploading specially crafted zip files. Attackers could write ma...

📅 25 days ago • Feb 9, 2026
CVE-2026-25848 9.1

This authentication bypass vulnerability in JetBrains Hub allows attackers to perform administrative actions without proper credentials. All organizat...

📅 26 days ago • Feb 9, 2026
CVE-2026-2234 9.1

CVE-2026-2234 is a missing authentication vulnerability in HGiga's C&Cm@il software that allows unauthenticated remote attackers to read and modify an...

📅 26 days ago • Feb 9, 2026
CVE-2026-25804 9.1

This vulnerability in Antrea's network policy priority assignment system causes incorrect traffic enforcement due to a uint16 arithmetic overflow when...

📅 28 days ago • Feb 6, 2026
CVE-2026-25643 9.1

CVE-2026-25643 is a critical Remote Command Execution vulnerability in Frigate NVR software that allows attackers to execute arbitrary system commands...

📅 28 days ago • Feb 6, 2026
CVE-2026-25722 9.1

CVE-2026-25722 is a directory traversal vulnerability in Claude Code that allows attackers to bypass write protection in sensitive directories like .c...

📅 28 days ago • Feb 6, 2026
CVE-2019-25298 9.1

CVE-2019-25298 is an SQL injection vulnerability in html5_snmp 1.11 that allows attackers to manipulate database queries through Router_ID and Router_...

📅 29 days ago • Feb 6, 2026
CVE-2025-59542 9.0

A stored cross-site scripting (XSS) vulnerability in Chamilo LMS allows low-privileged users (like trainers) to inject malicious JavaScript into cours...

⚡ Yesterday • Mar 6, 2026
CVE-2025-55208 9.0

This vulnerability allows low-privilege users in Chamilo LMS to upload malicious files containing stored XSS payloads through the Social Networks feat...

⚡ Yesterday • Mar 5, 2026
CVE-2026-27493 9.0

This CVE describes a second-order expression injection vulnerability in n8n's Form nodes that could allow unauthenticated attackers to inject and eval...

📅 9 days ago • Feb 25, 2026
CVE-2026-27822 9.0

A stored cross-site scripting (XSS) vulnerability in RustFS Console allows attackers to inject malicious JavaScript that executes when administrators ...

📅 10 days ago • Feb 25, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free