🔥 Trending CVEs - Last 90 Days

4,484 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
11,079
Total CVEs Published
990
Critical Severity
3,494
High Severity
⚠️
Critical Alert
990 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-14550 7.5

This vulnerability in Django's ASGIRequest component allows remote attackers to cause denial-of-service by sending crafted requests with multiple dupl...

📅 37 days ago • Feb 3, 2026
CVE-2025-67853 7.5

This vulnerability in Moodle allows remote attackers to bypass rate limiting on confirmation email services, enabling brute-force attacks against user...

📅 37 days ago • Feb 3, 2026
CVE-2025-8590 7.5

This vulnerability allows unauthorized actors to access directory listings in AKCE Software Technology's SKSPro software, potentially exposing sensiti...

📅 38 days ago • Feb 3, 2026
CVE-2025-12774 7.5

A vulnerability in Brocade SANnav migration scripts before version 3.0 allows sensitive database information to be captured in support save files. Att...

📅 38 days ago • Feb 3, 2026
CVE-2025-15556 7.5

This vulnerability allows attackers to intercept Notepad++ update traffic and replace legitimate updates with malicious installers. When users update ...

📅 38 days ago • Feb 3, 2026
CVE-2026-25222 7.5

This timing attack vulnerability in PolarLearn allows unauthenticated attackers to enumerate valid user email addresses by measuring login response ti...

📅 38 days ago • Feb 2, 2026
CVE-2022-50977 7.5

CVE-2022-50977 allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via HTTP requests. Th...

📅 38 days ago • Feb 2, 2026
CVE-2022-50978 7.5

This vulnerability allows unauthenticated remote attackers to disrupt operations by switching between multiple configuration presets via Modbus TCP. I...

📅 38 days ago • Feb 2, 2026
CVE-2026-0599 7.5

This vulnerability in huggingface/text-generation-inference allows unauthenticated attackers to trigger resource exhaustion by exploiting unbounded ex...

📅 38 days ago • Feb 2, 2026
CVE-2024-54263 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the Talemy Spirit Framework WordPress plugin. Attackers can exploit improper filename c...

📅 39 days ago • Feb 2, 2026
CVE-2026-20401 7.5

This vulnerability allows remote denial of service attacks against mobile devices with affected MediaTek modems. An attacker can crash the system by c...

📅 39 days ago • Feb 2, 2026
CVE-2026-22888 7.5

An improper input verification vulnerability in Cybozu Garoon allows attackers to modify portal settings without proper authorization. This could bloc...

📅 39 days ago • Feb 2, 2026
CVE-2020-37041 7.5

CVE-2020-37041 is a directory traversal vulnerability in OpenCTI 3.3.1 that allows unauthenticated attackers to read arbitrary files from the server f...

📅 41 days ago • Jan 30, 2026
CVE-2026-25128 7.5

A vulnerability in fast-xml-parser versions 4.3.6 through 5.3.3 allows attackers to cause denial of service by sending XML with out-of-range numeric e...

📅 41 days ago • Jan 30, 2026
CVE-2024-4027 7.5

This vulnerability in Undertow allows remote attackers to cause denial-of-service by sending HTTP requests with large parameter names, triggering OutO...

📅 41 days ago • Jan 30, 2026
CVE-2026-24714 7.5

CVE-2026-24714 allows attackers to activate telnet service on end-of-service NETGEAR devices by sending a specially crafted 'magic packet' to the Teln...

📅 42 days ago • Jan 30, 2026
CVE-2026-25061 7.5

This vulnerability in tcpflow's wifipcap component allows a 1-byte out-of-bounds write when parsing specially crafted 802.11 management frames with la...

📅 42 days ago • Jan 29, 2026
CVE-2025-63656 7.5

An out-of-bounds read vulnerability in Monkey web server's HTTP parser allows attackers to cause denial of service by sending crafted HTTP requests. T...

📅 42 days ago • Jan 29, 2026
CVE-2025-63657 7.5

An out-of-bounds read vulnerability in Monkey web server's mk_mimetype_find function allows attackers to cause denial of service by sending specially ...

📅 42 days ago • Jan 29, 2026
CVE-2025-63658 7.5

A stack overflow vulnerability in Monkey web server's mk_http_index_lookup function allows attackers to cause denial of service by sending specially c...

📅 42 days ago • Jan 29, 2026
CVE-2025-63649 7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) by sending a specially crafted POST request to the Monkey web server. The out-o...

📅 42 days ago • Jan 29, 2026
CVE-2025-63650 7.5

An out-of-bounds read vulnerability in Monkey web server's memory handling allows attackers to cause denial of service by sending crafted HTTP request...

📅 42 days ago • Jan 29, 2026
CVE-2025-63651 7.5

A use-after-free vulnerability in Monkey web server's string handling function allows attackers to crash the server by sending specially crafted HTTP ...

📅 42 days ago • Jan 29, 2026
CVE-2025-63652 7.5

A use-after-free vulnerability in Monkey web server's HTTP request handling allows attackers to crash the server by sending a specially crafted HTTP r...

📅 42 days ago • Jan 29, 2026
CVE-2025-63653 7.5

An out-of-bounds read vulnerability in Monkey web server's mk_vhost_fdt_close function allows attackers to cause denial of service by sending crafted ...

📅 42 days ago • Jan 29, 2026
CVE-2025-63655 7.5

This vulnerability allows attackers to crash Monkey web servers by sending specially crafted HTTP requests that trigger a NULL pointer dereference. An...

📅 42 days ago • Jan 29, 2026
CVE-2025-7714 7.5

This SQL injection vulnerability in Global Interactive Design Media Software Inc.'s CMS allows attackers to execute arbitrary SQL commands through uns...

📅 42 days ago • Jan 29, 2026
CVE-2026-1616 7.5

This vulnerability in Open Security Issue Management (OSIM) allows attackers to perform path traversal attacks by manipulating query parameters in ngi...

📅 42 days ago • Jan 29, 2026
CVE-2026-23743 7.5

This vulnerability in Discourse allows attackers to obtain sensitive information about private resources through URL redirects. When users without pro...

📅 43 days ago • Jan 28, 2026
CVE-2025-71007 7.5

An input validation vulnerability in OneFlow's oneflow.index_add component allows attackers to trigger a Denial of Service (DoS) by sending specially ...

📅 43 days ago • Jan 28, 2026
CVE-2025-71003 7.5

An input validation vulnerability in OneFlow's flow.arange() function allows attackers to trigger a Denial of Service (DoS) by sending specially craft...

📅 43 days ago • Jan 28, 2026
CVE-2025-61726 7.5

This vulnerability in Go's net/url package allows attackers to cause denial of service through memory exhaustion by sending HTTP requests with an exce...

📅 43 days ago • Jan 28, 2026
CVE-2025-14840 7.5

This vulnerability in Drupal HTTP Client Manager allows attackers to bypass access controls through forceful browsing, potentially accessing restricte...

📅 43 days ago • Jan 28, 2026
CVE-2026-0750 7.5

This vulnerability allows attackers to bypass authentication in Drupal Commerce Paybox payment processing module by exploiting improper cryptographic ...

📅 43 days ago • Jan 28, 2026
CVE-2025-70999 7.5

A GPU device-ID validation flaw in OneFlow's CUDA component allows attackers to trigger a Denial of Service (DoS) by providing a crafted device ID. Th...

📅 43 days ago • Jan 28, 2026
CVE-2025-71000 7.5

A vulnerability in OneFlow v0.9.0's flow.cuda.BoolTensor component allows attackers to cause Denial of Service (DoS) by sending specially crafted inpu...

📅 43 days ago • Jan 28, 2026
CVE-2025-65891 7.5

A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Service (DoS) by calling flow.cuda.get_device_properties() w...

📅 43 days ago • Jan 28, 2026
CVE-2026-1280 7.5

This vulnerability in the Frontend File Manager WordPress plugin allows unauthenticated attackers to share any uploaded file via email by exploiting a...

📅 43 days ago • Jan 28, 2026
CVE-2026-0702 7.5

The VidShop plugin for WordPress is vulnerable to SQL injection via the 'fields' parameter, allowing unauthenticated attackers to execute arbitrary SQ...

📅 44 days ago • Jan 28, 2026
CVE-2025-40537 7.5

SolarWinds Web Help Desk contains hardcoded credentials that could allow attackers to access administrative functions under certain conditions. This a...

📅 44 days ago • Jan 28, 2026
CVE-2026-24783 7.5

This vulnerability in the soroban-fixed-point-math library causes incorrect rounding in division operations when both the intermediate product and div...

📅 44 days ago • Jan 27, 2026
CVE-2026-0919 7.5

An unauthenticated attacker can send HTTP requests with excessively long URL paths to Tapo C220 v1 and C520WS v2 cameras, causing the HTTP parser to c...

📅 44 days ago • Jan 27, 2026
CVE-2026-0918 7.5

This vulnerability allows unauthenticated attackers to crash the HTTP service on Tapo C220 v1 and C520WS v2 cameras by sending POST requests with exce...

📅 44 days ago • Jan 27, 2026
CVE-2026-24831 7.5

This CVE describes an infinite loop vulnerability in ixray-1.6-stcop software where a loop condition cannot be satisfied, causing indefinite execution...

📅 44 days ago • Jan 27, 2026
CVE-2025-69420 7.5

A type confusion vulnerability in OpenSSL's TimeStamp Response verification allows attackers to cause denial of service by providing malformed timesta...

📅 44 days ago • Jan 27, 2026
CVE-2025-69421 7.5

A NULL pointer dereference vulnerability in OpenSSL's PKCS12_item_decrypt_d2i_ex() function allows attackers to cause denial of service by providing m...

📅 44 days ago • Jan 27, 2026
CVE-2020-36949 7.5

CVE-2020-36949 is a denial of service vulnerability in TapinRadio 2.13.7 where attackers can crash the application by pasting large buffers (20,000+ c...

📅 44 days ago • Jan 27, 2026
CVE-2026-24827 7.5

An out-of-bounds write vulnerability in Commander-Genius game engine allows attackers to write data beyond allocated memory boundaries. This affects a...

📅 45 days ago • Jan 27, 2026
CVE-2026-24828 7.5

This is a memory leak vulnerability (CWE-401) in Is-Daouda is-Engine software where memory is not properly released after use. This allows attackers t...

📅 45 days ago • Jan 27, 2026
CVE-2026-21720 7.5

This vulnerability in Grafana allows attackers to cause denial of service by exhausting system memory through uncontrolled goroutine creation. Attacke...

📅 45 days ago • Jan 27, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free