🔥 Trending CVEs - Last 90 Days

4,484 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,079
Total CVEs Published
990
Critical Severity
3,494
High Severity
⚠️
Critical Alert
990 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-25885 7.5

CVE-2026-25885 is an authentication bypass vulnerability in PolarLearn's WebSocket group chat functionality. Unauthenticated attackers can subscribe t...

📅 31 days ago • Feb 9, 2026
CVE-2026-25808 7.5

This vulnerability in Hollo microblogging software exposes private direct messages and followers-only posts through the ActivityPub outbox endpoint wi...

📅 31 days ago • Feb 9, 2026
CVE-2026-25813 7.5

PlaciPy placement management system logs sensitive data to console output without redaction in version 1.0.0. This allows attackers with access to con...

📅 31 days ago • Feb 9, 2026
CVE-2026-25639 7.5

This vulnerability in Axios allows attackers to cause denial of service by providing malicious configuration objects containing __proto__ as an own pr...

📅 31 days ago • Feb 9, 2026
CVE-2026-25791 7.5

This vulnerability in Sliver C2 framework allows unauthenticated attackers to create unlimited DNS sessions without OTP validation, leading to memory ...

📅 31 days ago • Feb 9, 2026
CVE-2026-25231 7.5

FileRise versions before 3.3.0 have an unauthenticated file read vulnerability where anyone can access files in the /uploads directory without authent...

📅 31 days ago • Feb 9, 2026
CVE-2026-2236 7.5

CVE-2026-2236 is a SQL injection vulnerability in HGiga's C&Cm@il software that allows unauthenticated remote attackers to execute arbitrary SQL comma...

📅 32 days ago • Feb 9, 2026
CVE-2026-22905 7.5

This vulnerability allows unauthenticated remote attackers to bypass authentication by exploiting insufficient URI validation. Attackers can use path ...

📅 32 days ago • Feb 9, 2026
CVE-2025-66597 7.5

Yokogawa FAST/TOOLS industrial control system software uses weak cryptographic algorithms, potentially allowing attackers to decrypt web server commun...

📅 32 days ago • Feb 9, 2026
CVE-2025-66598 7.5

This vulnerability in Yokogawa's FAST/TOOLS software allows attackers to potentially decrypt communications by exploiting support for outdated SSL/TLS...

📅 32 days ago • Feb 9, 2026
CVE-2025-66608 7.5

A path traversal vulnerability in Yokogawa's FAST/TOOLS software allows attackers to bypass URL validation and access arbitrary files on the web serve...

📅 32 days ago • Feb 9, 2026
CVE-2026-25644 7.5

DataHub's LDAP ingestion source is vulnerable to TLS downgrade attacks, allowing man-in-the-middle attackers to intercept and potentially modify LDAP ...

📅 34 days ago • Feb 6, 2026
CVE-2026-25762 7.5

AdonisJS multipart file upload handler has a memory exhaustion vulnerability that allows attackers to cause denial of service by uploading specially c...

📅 34 days ago • Feb 6, 2026
CVE-2026-25758 7.5

A critical IDOR vulnerability in Spree Commerce allows guest users to manipulate address ID parameters during checkout, bypassing ownership validation...

📅 34 days ago • Feb 6, 2026
CVE-2026-25732 7.5

This vulnerability in NiceGUI allows attackers to perform path traversal attacks by uploading files with malicious filenames containing '../' sequence...

📅 34 days ago • Feb 6, 2026
CVE-2026-25650 7.5

The MCP Salesforce Connector prior to version 0.1.10 allows arbitrary attribute access that can lead to disclosure of Salesforce authentication tokens...

📅 34 days ago • Feb 6, 2026
CVE-2026-25724 7.5

CVE-2026-25724 is a symbolic link bypass vulnerability in Claude Code that allows reading files explicitly denied in settings.json. Attackers could ac...

📅 34 days ago • Feb 6, 2026
CVE-2026-25556 7.5

MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in the barcode decoding functionality. When processing specially crafted inpu...

📅 34 days ago • Feb 6, 2026
CVE-2026-21626 7.5

This vulnerability allows unauthorized access to forum post custom fields through JSON output, bypassing access control settings. It affects EasyDiscu...

📅 35 days ago • Feb 6, 2026
CVE-2020-37150 7.5

This vulnerability allows unauthenticated attackers to access the /wizard_reboot.asp page on Edimax EW-7438RPn-v3 Mini range extenders, which disclose...

📅 35 days ago • Feb 5, 2026
CVE-2026-25541 7.5

This vulnerability in the Bytes library allows integer overflow in the BytesMut::reserve function, which can cause memory corruption and out-of-bounds...

📅 36 days ago • Feb 4, 2026
CVE-2026-25575 7.5

CVE-2026-25575 is a path traversal vulnerability in NavigaTUM's propose_edits endpoint that allows unauthenticated attackers to overwrite files in wri...

📅 36 days ago • Feb 4, 2026
CVE-2026-25537 7.5

This vulnerability in the jsonwebtoken Rust library allows attackers to bypass time-based security restrictions like 'Not Before' (nbf) and 'Expiratio...

📅 36 days ago • Feb 4, 2026
CVE-2026-25499 7.5

This vulnerability in the Terraform/OpenTofu Proxmox provider allows attackers to escape restricted directories via path traversal (../) in SSH config...

📅 36 days ago • Feb 4, 2026
CVE-2026-23897 7.5

Apollo Server's startStandaloneServer function is vulnerable to denial-of-service attacks when attackers send GraphQL requests with specially crafted ...

📅 36 days ago • Feb 4, 2026
CVE-2025-71031 7.5

CVE-2025-71031 is a denial-of-service vulnerability in Water-Melon Melon's HTTP component that lacks request header length limits. Attackers can crash...

📅 36 days ago • Feb 4, 2026
CVE-2026-25140 7.5

This vulnerability in apko allows attackers who control or compromise APK repositories to cause resource exhaustion on build hosts. By serving a small...

📅 36 days ago • Feb 4, 2026
CVE-2026-25121 7.5

A path traversal vulnerability in apko's dirFS filesystem abstraction allows attackers to create directories or symlinks outside the intended installa...

📅 36 days ago • Feb 4, 2026
CVE-2026-20119 7.5

An unauthenticated remote attacker can cause Cisco TelePresence and RoomOS devices to reload by sending crafted text, resulting in denial of service. ...

📅 36 days ago • Feb 4, 2026
CVE-2026-24735 7.5

An unauthenticated API endpoint in Apache Answer exposes full revision history for deleted content, allowing unauthorized users to retrieve sensitive ...

📅 36 days ago • Feb 4, 2026
CVE-2025-15268 7.5

The Infility Global WordPress plugin contains an unauthenticated SQL injection vulnerability in its 'infility_get_data' API endpoint. Attackers can ex...

📅 36 days ago • Feb 4, 2026
CVE-2025-15285 7.5

The SEO Flow by LupsOnline WordPress plugin has an authorization bypass vulnerability that allows unauthenticated attackers to create, modify, and del...

📅 36 days ago • Feb 4, 2026
CVE-2026-25223 7.5

Fastify versions before 5.7.2 have a validation bypass vulnerability where attackers can circumvent request body validation by appending a tab charact...

📅 37 days ago • Feb 3, 2026
CVE-2020-37097 7.5

CVE-2020-37097 allows unauthenticated attackers to access the wlencrypt_wiz.asp file on Edimax EW-7438RPn range extenders, exposing WiFi network confi...

📅 37 days ago • Feb 3, 2026
CVE-2026-25614 7.5

CVE-2026-25614 is a PHP object injection vulnerability in Blesta billing software that allows attackers to execute arbitrary code by deserializing unt...

📅 37 days ago • Feb 3, 2026
CVE-2025-64438 7.5

CVE-2025-64438 is a remotely triggerable denial-of-service vulnerability in Fast DDS that allows unauthenticated attackers to cause out-of-memory cond...

📅 37 days ago • Feb 3, 2026
CVE-2025-62601 7.5

A heap buffer overflow vulnerability in Fast DDS allows remote attackers to terminate the Fast-DDS process by sending specially crafted SPDP packets w...

📅 37 days ago • Feb 3, 2026
CVE-2025-62602 7.5

This vulnerability in Fast DDS allows remote attackers to cause denial-of-service by sending specially crafted SPDP packets with manipulated DATA Subm...

📅 37 days ago • Feb 3, 2026
CVE-2025-62603 7.5

Fast DDS versions prior to 3.4.1, 3.3.1, and 2.6.11 contain a vulnerability where malicious ParticipantGenericMessage packets can trigger excessive me...

📅 37 days ago • Feb 3, 2026
CVE-2026-25239 7.5

This SQL injection vulnerability in PEAR's apidoc queue insertion allows attackers to manipulate database queries by controlling filename values. It a...

📅 37 days ago • Feb 3, 2026
CVE-2026-25235 7.5

This vulnerability in PEAR (PHP Extension and Application Repository) allows attackers to guess verification tokens due to predictable hashes, potenti...

📅 37 days ago • Feb 3, 2026
CVE-2025-62600 7.5

This vulnerability in Fast DDS allows remote attackers to cause a denial-of-service (DoS) by sending specially crafted SPDP packets with modified DATA...

📅 37 days ago • Feb 3, 2026
CVE-2026-24773 7.5

CVE-2026-24773 is an Insecure Direct Object Reference (IDOR) vulnerability in Open eClass (formerly GUnet eClass) that allows unauthenticated attacker...

📅 37 days ago • Feb 3, 2026
CVE-2025-70758 7.5

This CVE describes an authentication bypass vulnerability in chetans9 core-php-admin-panel where the authentication validation script sends a redirect...

📅 37 days ago • Feb 3, 2026
CVE-2025-62599 7.5

This vulnerability in Fast DDS allows remote attackers to cause a denial of service by triggering an out-of-memory condition. When security mode is en...

📅 37 days ago • Feb 3, 2026
CVE-2025-59439 7.5

A vulnerability in Samsung Exynos processors and modems allows denial of service attacks through improper handling of NAS Registration messages. Attac...

📅 37 days ago • Feb 3, 2026
CVE-2026-24762 7.5

RustFS versions alpha.13 through alpha.81 log sensitive AWS credentials (access keys, secret keys, session tokens) in plaintext at INFO level. This al...

📅 37 days ago • Feb 3, 2026
CVE-2026-21862 7.5

This vulnerability allows attackers to bypass IP-based access controls in RustFS by spoofing their IP address using HTTP headers. Any client that can ...

📅 37 days ago • Feb 3, 2026
CVE-2026-25027 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Unicamp WordPress theme. Attackers can include arbitrary local files through improp...

📅 37 days ago • Feb 3, 2026
CVE-2026-1285 7.5

This vulnerability in Django allows remote attackers to cause denial-of-service by sending crafted inputs with many unmatched HTML end tags to specifi...

📅 37 days ago • Feb 3, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free