🔥 Trending CVEs - Last 90 Days
4,484 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
iDailyDiary 4.30 contains a denial of service vulnerability where attackers can crash the application by pasting an extremely long string (2,000,000 c...
📅 55 days ago • Jan 16, 2026CVE-2021-47827 is a denial of service vulnerability in WebSSH for iOS that allows attackers to crash the application by pasting malformed input into t...
📅 55 days ago • Jan 16, 2026DupTerminator 1.4.5639.37199 contains a denial of service vulnerability where attackers can crash the application by inputting a long string (8000 rep...
📅 55 days ago • Jan 16, 2026CVE-2021-47821 is a denial of service vulnerability in RarmaRadio 2.72.8 where attackers can crash the application by overflowing network configuratio...
📅 55 days ago • Jan 16, 2026RustFS versions 1.0.0-alpha.1 through 1.0.0-alpha.79 log the shared HMAC secret when invalid RPC signatures are received. This exposes the secret to a...
📅 55 days ago • Jan 16, 2026A stack overflow vulnerability in Tenda AX-1806 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted requests to the...
📅 55 days ago • Jan 16, 2026Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the security parameter handling. Attackers can exploit this ...
📅 55 days ago • Jan 16, 2026The Librarian's web_fetch tool contains an information leakage vulnerability that allows attackers to retrieve arbitrary external content and proxy re...
📅 56 days ago • Jan 16, 2026The Librarian contains a server-side request forgery (SSRF) vulnerability that allows attackers to use the web_fetch tool to scan internal network por...
📅 56 days ago • Jan 16, 2026TheLibrarians web_fetch tool can be exploited to retrieve the Adminer interface content, enabling unauthorized access to the internal TheLibrarian bac...
📅 56 days ago • Jan 16, 2026This vulnerability in Apache Airflow exposes sensitive values like passwords and API keys in cleartext in the Rendered Templates UI when template fiel...
📅 56 days ago • Jan 16, 2026Apache Airflow versions before 3.1.6 expose proxy credentials in logs when connections contain proxy URLs with embedded authentication. This allows at...
📅 56 days ago • Jan 16, 2026The Gotac Statistics Database System contains an arbitrary file read vulnerability that allows unauthenticated remote attackers to download any system...
📅 56 days ago • Jan 16, 2026The Gotac Statistics Database System has a Missing Authentication vulnerability (CWE-306) that allows unauthenticated remote attackers to directly que...
📅 56 days ago • Jan 16, 2026The Police Statistics Database System developed by Gotac contains an unauthenticated arbitrary file read vulnerability via absolute path traversal. Th...
📅 56 days ago • Jan 16, 2026This vulnerability in Redragon Gaming Mouse drivers allows attackers to cause a kernel-level denial of service by sending specially crafted IOCTL requ...
📅 56 days ago • Jan 16, 2026Deno's node:crypto module before version 2.6.0 fails to properly finalize cipher operations, allowing attackers to perform infinite encryption attempt...
📅 56 days ago • Jan 15, 2026This vulnerability in GNU C Library (glibc) allows stack memory contents to be leaked to DNS resolvers when getnetbyaddr functions query for a zero-va...
📅 56 days ago • Jan 15, 2026A double free vulnerability in Juniper's flow processing daemon (flowd) allows unauthenticated attackers to cause denial-of-service by sending a speci...
📅 56 days ago • Jan 15, 2026An unauthenticated attacker can send specially crafted DNS requests to Juniper SRX Series devices running vulnerable Junos OS versions, causing the fl...
📅 56 days ago • Jan 15, 2026An unauthenticated attacker can cause a complete denial-of-service on vulnerable Juniper EX4000 switches by sending high volumes of traffic to the dev...
📅 56 days ago • Jan 15, 2026An improper locking vulnerability in Juniper SRX Series GTP plugin allows unauthenticated attackers to cause denial-of-service by sending malformed GT...
📅 56 days ago • Jan 15, 2026An unauthenticated attacker can cause a denial-of-service on Juniper SRX Series firewalls by sending specially crafted SSL packets to devices with UTM...
📅 56 days ago • Jan 15, 2026An unauthenticated attacker can crash the packet forwarding engine on vulnerable Juniper SRX Series devices by sending a specific ICMP packet through ...
📅 56 days ago • Jan 15, 2026An unauthenticated attacker can send specially crafted SIP messages over TCP to trigger an infinite loop in Juniper's SIP ALG, crashing critical proce...
📅 56 days ago • Jan 15, 2026A buffer over-read vulnerability in Juniper's routing protocol daemon (rpd) allows unauthenticated attackers to cause denial-of-service by sending spe...
📅 56 days ago • Jan 15, 2026This vulnerability in NanoMQ allows attackers to cause a denial of service by sending crafted requests that cause the recv-q queue to fill up, leading...
📅 56 days ago • Jan 15, 2026CVE-2026-22803 is a denial-of-service vulnerability in SvelteKit's experimental form remote function that allows attackers to cause memory exhaustion ...
📅 56 days ago • Jan 15, 2026An unauthenticated attacker can send specially crafted requests to Palo Alto Networks PAN-OS firewalls, causing them to crash and enter maintenance mo...
📅 56 days ago • Jan 15, 2026CVE-2026-22774 is a denial-of-service vulnerability in the Svelte devalue JavaScript library where specially crafted inputs cause excessive CPU and me...
📅 56 days ago • Jan 15, 2026CVE-2026-22775 is a denial-of-service vulnerability in the Svelte devalue JavaScript library where specially crafted inputs cause excessive CPU and me...
📅 56 days ago • Jan 15, 2026A remote, unauthenticated attacker can exploit a null pointer dereference vulnerability in the TP-Link TL-WR841N v14 web portal's referer header check...
📅 56 days ago • Jan 15, 2026A stack overflow vulnerability in GPAC's dump_ttxt_sample function allows attackers to cause Denial of Service by sending specially crafted packets. T...
📅 56 days ago • Jan 15, 2026CVE-2026-22265 is a command injection vulnerability in Roxy-WI web interface versions prior to 8.2.8.2 that allows authenticated users to execute arbi...
📅 56 days ago • Jan 15, 2026An out-of-bounds read vulnerability in GPAC's GSF demuxer filter allows attackers to cause denial of service by processing a malicious .gsf file. This...
📅 56 days ago • Jan 15, 2026CVE-2025-70656 is a stack overflow vulnerability in Tenda AX-1806 routers that allows attackers to cause Denial of Service (DoS) by sending specially ...
📅 56 days ago • Jan 15, 2026A buffer overflow vulnerability in GPAC's vobsub_get_subpic_duration() function allows attackers to cause denial of service by sending specially craft...
📅 56 days ago • Jan 15, 2026CVE-2025-66417 is an unauthenticated SQL injection vulnerability in GLPI's inventory endpoint. Attackers can execute arbitrary SQL commands without cr...
📅 56 days ago • Jan 15, 2026This vulnerability allows unauthorized users to access documents attached to any item in GLPI (tickets, assets, etc.). If the public FAQ feature is en...
📅 56 days ago • Jan 15, 2026This directory traversal vulnerability in Omnispace Agora Project allows unauthenticated attackers to read arbitrary files with extensions from the se...
📅 56 days ago • Jan 15, 2026CVE-2021-47784 is a denial of service vulnerability in Cyberfox Web Browser where attackers can crash the application by pasting an excessively large ...
📅 56 days ago • Jan 15, 2026CVE-2021-47755 is a path traversal vulnerability in Oliver Library Server v5 that allows unauthenticated attackers to download arbitrary files from th...
📅 56 days ago • Jan 15, 2026CVE-2021-47752 is a denial of service vulnerability in AWebServer GhostBuilding 18 that allows remote attackers to crash or render the server unrespon...
📅 56 days ago • Jan 15, 2026Tenda AX-1806 routers version 1.0.0.1 contain a stack overflow vulnerability in the cloneType parameter that allows attackers to cause Denial of Servi...
📅 56 days ago • Jan 15, 2026This vulnerability in Tenda AX-1806 routers allows attackers to cause a Denial of Service (DoS) by sending specially crafted requests that trigger a s...
📅 56 days ago • Jan 15, 2026This vulnerability allows remote attackers to cause Denial of Service (DoS) by sending a specially crafted .keras archive with an extremely large data...
📅 57 days ago • Jan 15, 2026This vulnerability allows unauthorized access to system functions that control installed applications. Attackers can start, stop, or delete applicatio...
📅 57 days ago • Jan 15, 2026This vulnerability allows attackers to gain unauthorized access to affected devices by using weak, publicly known default passwords on hidden user acc...
📅 57 days ago • Jan 15, 2026This vulnerability allows unauthenticated attackers to perform blind SQL injection attacks on WordPress sites using the Simply Schedule Appointments B...
📅 57 days ago • Jan 14, 2026Tenda AX-1806 routers running firmware v1.0.0.1 contain a stack overflow vulnerability in the serviceName parameter that allows remote attackers to cr...
📅 57 days ago • Jan 14, 2026Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats