🔥 Trending CVEs - Last 90 Days

4,484 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,079
Total CVEs Published
990
Critical Severity
3,494
High Severity
⚠️
Critical Alert
990 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-14511 7.5

An unauthenticated attacker can cause denial of service in GitLab by sending specially crafted files to the container registry event endpoint. This af...

📅 15 days ago • Feb 25, 2026
CVE-2026-25476 7.5

OpenEMR versions before 8.0.0 have a session expiration bypass vulnerability. Attackers can send a specific parameter (skip_timeout_reset=1) to preven...

📅 15 days ago • Feb 25, 2026
CVE-2026-27850 7.5

A firewall misconfiguration allows external attackers to connect to internal services through WAN port 5222, bypassing intended network segmentation. ...

📅 15 days ago • Feb 25, 2026
CVE-2026-27730 7.5

CVE-2026-27730 is a Server-Side Request Forgery (SSRF) vulnerability in esm.sh's fetch route that allows attackers to bypass hostname-based validation...

📅 15 days ago • Feb 25, 2026
CVE-2026-2416 7.5

The Geo Mashup WordPress plugin contains an SQL injection vulnerability in the 'sort' parameter that allows unauthenticated attackers to execute arbit...

📅 15 days ago • Feb 25, 2026
CVE-2026-1916 7.5

The WPGSI: Spreadsheet Integration plugin for WordPress has critical REST API endpoints that lack proper authentication and authorization checks. Unau...

📅 15 days ago • Feb 25, 2026
CVE-2026-27640 7.5

tfplan2md versions before 1.26.1 fail to properly mask sensitive values in Terraform plan reports, exposing secrets like API keys, passwords, and conf...

📅 16 days ago • Feb 25, 2026
CVE-2026-27595 7.5

This vulnerability in Parse Dashboard's AI Agent API endpoint allows unauthenticated remote attackers to perform arbitrary read and write operations o...

📅 16 days ago • Feb 25, 2026
CVE-2026-27195 7.5

A bug in Wasmtime's async component model implementation causes a panic when call_async futures are dropped before completion and then called again on...

📅 16 days ago • Feb 24, 2026
CVE-2026-27572 7.5

This vulnerability in Wasmtime's WASI HTTP implementation causes denial of service when excessive HTTP headers are processed. The runtime panics inste...

📅 16 days ago • Feb 24, 2026
CVE-2026-25891 7.5

A path traversal vulnerability in Fiber's static middleware on Windows allows remote attackers to bypass sanitization and read arbitrary files from th...

📅 16 days ago • Feb 24, 2026
CVE-2026-25899 7.5

CVE-2026-25899 is a memory exhaustion vulnerability in GoFiber v3 web framework where a specially crafted 10-character cookie value triggers unvalidat...

📅 16 days ago • Feb 24, 2026
CVE-2024-48928 7.5

Piwigo versions 14.x have a weak secret key generation vulnerability during installation. Attackers can brute-force the secret key in about one hour, ...

📅 16 days ago • Feb 24, 2026
CVE-2026-27521 7.5

This vulnerability in Binardat 10G08-0800GSM network switches allows attackers to perform brute-force attacks against login credentials due to missing...

📅 16 days ago • Feb 24, 2026
CVE-2026-27516 7.5

Binardat 10G08-0800GSM network switches expose administrative passwords in plaintext within the web interface and HTTP responses, allowing attackers t...

📅 16 days ago • Feb 24, 2026
CVE-2026-27519 7.5

This vulnerability in Binardat 10G08-0800GSM network switches allows attackers to decrypt protected data due to the use of RC4 encryption with a hard-...

📅 16 days ago • Feb 24, 2026
CVE-2026-27584 7.5

CVE-2026-27584 is an authentication bypass vulnerability in ActualBudget server that allows unauthenticated attackers to access sensitive bank account...

📅 16 days ago • Feb 24, 2026
CVE-2026-2794 7.5

This vulnerability allows attackers to read uninitialized memory in Firefox and Firefox Focus for Android, potentially exposing sensitive information....

📅 16 days ago • Feb 24, 2026
CVE-2026-1773 7.5

This vulnerability affects IEC 60870-5-104 implementations when bi-directional functionality is configured. Attackers can send specially crafted inval...

📅 16 days ago • Feb 24, 2026
CVE-2026-25985 7.5

ImageMagick versions prior to 7.1.2-15 and 6.9.13-40 contain a memory allocation vulnerability in SVG processing. A malicious SVG file with a crafted ...

📅 17 days ago • Feb 24, 2026
CVE-2026-26025 7.5

A denial-of-service vulnerability in free5GC SMF allows attackers to crash the Session Management Function by sending malformed PFCP SessionReportRequ...

📅 17 days ago • Feb 24, 2026
CVE-2026-24481 7.5

ImageMagick versions before 7.1.2-15 and 6.9.13-40 have a heap information disclosure vulnerability in their PSD format handler. When processing speci...

📅 17 days ago • Feb 24, 2026
CVE-2026-24485 7.5

This vulnerability in ImageMagick allows attackers to cause denial of service by exploiting an infinite loop in PCD file processing. When ImageMagick ...

📅 17 days ago • Feb 24, 2026
CVE-2025-69247 7.5

A heap-based buffer overflow vulnerability in free5GC go-upf versions before 1.2.8 allows remote attackers to cause denial of service by sending speci...

📅 17 days ago • Feb 23, 2026
CVE-2026-21863 7.5

This vulnerability in Valkey allows attackers with access to the clusterbus port to send specially crafted packets that cause out-of-bounds reads, pot...

📅 17 days ago • Feb 23, 2026
CVE-2019-25461 7.5

CVE-2019-25461 is an unauthenticated SQL injection vulnerability in Web Ofisi Platinum E-Ticaret v5 e-commerce software. Attackers can inject maliciou...

📅 18 days ago • Feb 22, 2026
CVE-2019-25457 7.5

Web Ofisi Firma v13 contains an unauthenticated SQL injection vulnerability in the 'oz' parameter. Attackers can inject malicious SQL payloads via GET...

📅 18 days ago • Feb 22, 2026
CVE-2019-25455 7.5

Web Ofisi E-Ticaret v3 contains an unauthenticated SQL injection vulnerability in the 'a' parameter that allows attackers to execute arbitrary SQL que...

📅 18 days ago • Feb 22, 2026
CVE-2019-25450 7.5

Dolibarr ERP/CRM 10.0.1 contains SQL injection vulnerabilities in card.php endpoints that allow authenticated attackers to inject malicious SQL throug...

📅 18 days ago • Feb 22, 2026
CVE-2026-27202 7.5

GetSimple CMS has a path traversal vulnerability in its Uploaded Files feature that allows attackers to read arbitrary files on the server. This affec...

📅 20 days ago • Feb 21, 2026
CVE-2019-25438 7.5

This vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on LabCollector 5.423 by injecting malicious code through login ...

📅 20 days ago • Feb 20, 2026
CVE-2019-25432 7.5

CVE-2019-25432 is an SQL injection vulnerability in Part-DB's authentication system that allows unauthenticated attackers to bypass login by injecting...

📅 20 days ago • Feb 20, 2026
CVE-2026-24892 7.5

openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization vulnerability in changelog processing. While no current explo...

📅 20 days ago • Feb 20, 2026
CVE-2026-24891 7.5

CVE-2026-24891 is an unsafe deserialization vulnerability in openITCOCKPIT monitoring tool that allows PHP Object Injection when untrusted systems can...

📅 20 days ago • Feb 20, 2026
CVE-2026-24455 7.5

This vulnerability exposes user credentials through unencrypted HTTP Basic Authentication in an embedded web interface. Attackers on the same network ...

📅 20 days ago • Feb 20, 2026
CVE-2025-69401 7.5

This vulnerability allows attackers to bypass authentication and spoof identities in the WooODT Lite WordPress plugin. It affects all WooCommerce site...

📅 20 days ago • Feb 20, 2026
CVE-2025-69387 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Simple Retail Menus WordPress plugin. Attackers can include arbitrary local files f...

📅 20 days ago • Feb 20, 2026
CVE-2025-69393 7.5

This CVE describes a missing authorization vulnerability in the Jthemes Exzo WordPress theme that allows attackers to bypass access controls. It affec...

📅 20 days ago • Feb 20, 2026
CVE-2025-69383 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the WP Shop WordPress plugin. Attackers can include arbitrary local files through impro...

📅 20 days ago • Feb 20, 2026
CVE-2025-69373 7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

📅 20 days ago • Feb 20, 2026
CVE-2025-69303 7.5

This CVE describes a missing authorization vulnerability in the ModelTheme Framework WordPress plugin that allows attackers to bypass access controls....

📅 20 days ago • Feb 20, 2026
CVE-2025-69298 7.5

This CVE describes a missing authorization vulnerability in the GhostPool Gauge WordPress theme that allows attackers to bypass access controls. The v...

📅 20 days ago • Feb 20, 2026
CVE-2025-68048 7.5

This CVE describes a Missing Authorization vulnerability in the NextMove Lite WordPress plugin that allows attackers to bypass access controls. The vu...

📅 20 days ago • Feb 20, 2026
CVE-2025-67994 7.5

This CVE describes a Missing Authorization vulnerability in the YayCommerce YayCurrency WordPress plugin that allows attackers to delete arbitrary con...

📅 20 days ago • Feb 20, 2026
CVE-2026-26321 7.5

OpenClaw's Feishu extension had a path traversal vulnerability that allowed reading arbitrary local files by supplying attacker-controlled paths. This...

📅 21 days ago • Feb 19, 2026
CVE-2026-26324 7.5

OpenClaw's SSRF protection could be bypassed using IPv4-mapped IPv6 addresses, allowing attackers to access restricted internal resources like localho...

📅 21 days ago • Feb 19, 2026
CVE-2026-26319 7.5

OpenClaw versions 2026.2.13 and below with the @openclaw/voice-call plugin allow unauthenticated attackers to forge Telnyx webhook events when telnyx....

📅 21 days ago • Feb 19, 2026
CVE-2026-26316 7.5

This vulnerability allows attackers to bypass authentication in OpenClaw's BlueBubbles iMessage plugin by sending webhook requests from localhost addr...

📅 21 days ago • Feb 19, 2026
CVE-2026-26275 7.5

A logic flaw in httpsig-hyper versions before 0.0.23 causes digest verification to always succeed regardless of actual digest values, allowing message...

📅 21 days ago • Feb 19, 2026
CVE-2026-26315 7.5

A cryptographic flaw in go-ethereum's ECIES implementation allows attackers to extract bits of the p2p node key. This affects all Geth nodes running v...

📅 21 days ago • Feb 19, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free