🔥 Trending CVEs - Last 90 Days
4,459 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
A path traversal vulnerability in Qfiling allows remote attackers to read arbitrary files on the system by manipulating file paths. This affects all Q...
📅 71 days ago • Jan 2, 2026Cowrie honeypot versions before 2.9.0 contain a server-side request forgery vulnerability in the emulated wget and curl commands. Unauthenticated atta...
📅 73 days ago • Dec 31, 2025This vulnerability in KZTech JT3500V 4G LTE CPE devices allows attackers to reuse expired session credentials due to improper session expiration. Atta...
📅 73 days ago • Dec 31, 2025This vulnerability allows limited administrative users on ZBL EPON ONU Broadband Router V100R001 to escalate privileges by accessing configuration end...
📅 73 days ago • Dec 31, 2025CVE-2021-47744 is a hard-coded credentials vulnerability in Cypress Solutions CTM-200/CTM-ONE devices running version 1.3.6. Attackers can use the sta...
📅 73 days ago • Dec 31, 2025This vulnerability allows non-privileged users on NuCom 11N Wireless Router to retrieve administrative credentials by accessing the configuration back...
📅 73 days ago • Dec 31, 2025The Knowband Mobile App Builder WordPress plugin before version 3.0.0 has an authorization vulnerability in its REST API that allows unauthenticated a...
📅 74 days ago • Dec 31, 2025This vulnerability in the cbor2 library allows attackers to read sensitive data from previously decoded CBOR messages when a CBORDecoder instance is r...
📅 74 days ago • Dec 31, 2025This vulnerability allows attackers to include local files on the server through improper input validation in the MAS Videos WordPress plugin. Attacke...
📅 74 days ago • Dec 30, 2025CVE-2023-54163 is a SQL injection vulnerability in NLB mKlik Macedonia mobile banking app version 3.3.12. Attackers can inject malicious SQL code thro...
📅 74 days ago • Dec 30, 2025CVE-2022-50799 is a denial of service vulnerability in Fetch FTP Client 5.8.2 where attackers can send specially crafted FTP server responses exceedin...
📅 74 days ago • Dec 30, 2025H3C SSL VPN has a user enumeration vulnerability that allows attackers to determine valid usernames by analyzing login response differences. Attackers...
📅 74 days ago • Dec 30, 2025This vulnerability allows remote attackers to read arbitrary files on SOUND4 IMPACT/FIRST/PULSE/Eco devices without authentication by manipulating the...
📅 74 days ago • Dec 30, 2025CVE-2022-50788 is an information disclosure vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems that allows unauthenticated attackers to access sen...
📅 74 days ago • Dec 30, 2025This vulnerability allows unauthenticated remote attackers to access live radio stream information from SOUND4 IMPACT/FIRST/PULSE/Eco systems. Attacke...
📅 74 days ago • Dec 30, 2025SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below have insufficient session expiration, allowing attackers to reuse old session credentials. This e...
📅 74 days ago • Dec 30, 2025This vulnerability allows unauthenticated attackers to abuse network diagnostic scripts (ping.php, traceroute.php, dns.php) in SOUND4 products to laun...
📅 74 days ago • Dec 30, 2025CVE-2025-66723 is an insecure permissions vulnerability in inMusic Brands Engine DJ software where the Remote Library's exposed HTTP service allows at...
📅 74 days ago • Dec 30, 2025This vulnerability in Ruby's URI module allows credential exposure when using the '+' operator to combine URIs. Sensitive information like passwords f...
📅 74 days ago • Dec 30, 2025A vulnerability in WasmEdge WebAssembly runtime allows integer overflow in memory boundary checking, leading to segmentation faults. This affects all ...
📅 74 days ago • Dec 30, 2025A command injection vulnerability in Serverless Framework's experimental MCP server feature allows attackers to execute arbitrary system commands via ...
📅 74 days ago • Dec 30, 2025A divide-by-zero vulnerability in GNU Recutils v1.9 encryption/decryption routines allows attackers to cause a Denial of Service (DoS) by providing an...
📅 74 days ago • Dec 30, 2025A NULL pointer dereference vulnerability in GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) by injecting a crafted payload into...
📅 74 days ago • Dec 30, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...
📅 74 days ago • Dec 30, 2025The E-Invoice App Malaysia WordPress plugin exposes sensitive system information to unauthorized users. This vulnerability allows attackers to retriev...
📅 74 days ago • Dec 30, 2025This vulnerability in the Contact Form 7 Extension For Mailchimp WordPress plugin exposes sensitive data embedded in form submissions. Attackers can r...
📅 74 days ago • Dec 30, 2025CVE-2025-15358 is a denial of service vulnerability in Delta Electronics DVP-12SE11T programmable logic controllers. Attackers can send specially craf...
📅 75 days ago • Dec 30, 2025This vulnerability allows attackers to bypass the Same-Origin Policy in Whale browser's sidebar environment, potentially enabling cross-origin data th...
📅 75 days ago • Dec 30, 2025This CVE describes a missing authorization vulnerability in CubeWP WordPress plugin that allows attackers to access functionality not properly restric...
📅 75 days ago • Dec 30, 2025CVE-2024-25183 is a directory traversal vulnerability in givanz VvvebJs 1.7.2 that allows attackers to read arbitrary files on the server via the scan...
📅 75 days ago • Dec 29, 2025NagiosXI 2026R1.0.1 build 1762361101 contains a directory traversal vulnerability in /admin/coreconfigsnapshots.php that allows attackers to access fi...
📅 75 days ago • Dec 29, 2025A buffer overflow vulnerability in the dcputchar function of libming 0.4.8 allows attackers to execute arbitrary code or cause denial of service. This...
📅 75 days ago • Dec 29, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
📅 75 days ago • Dec 29, 2025A buffer overflow vulnerability in the gnu_special function of BinUtils' cplus-dem.c file allows attackers to crash applications by processing special...
📅 75 days ago • Dec 29, 2025A vulnerability in BinUtils' cp-demangle.c function allows attackers to cause denial of service through crafted PE files. This affects systems using B...
📅 75 days ago • Dec 29, 2025A vulnerability in BinUtils' cp-demangle.c allows attackers to cause denial of service through crafted PE files. This affects systems using BinUtils f...
📅 75 days ago • Dec 29, 2025A stack-based buffer overflow vulnerability exists in the cp-demangle.c file of BinUtils 2.26, specifically in the d_print_comp_inner function. Attack...
📅 75 days ago • Dec 29, 2025A vulnerability in BinUtils' cp-demangle.c allows attackers to cause denial of service through crafted PE files. This affects systems using BinUtils f...
📅 75 days ago • Dec 29, 2025A buffer overflow vulnerability in the strcat function within libming 0.4.8 allows attackers to execute arbitrary code or cause denial of service. Thi...
📅 75 days ago • Dec 29, 2025An unauthenticated remote attacker can trigger generation and download of configuration backup ZIP files in vulnerable phpMyFAQ installations. This ex...
📅 75 days ago • Dec 29, 2025This CVE describes a PHP Local File Inclusion vulnerability in the CedCommerce Integration for Good Market WordPress plugin. Attackers can include arb...
📅 75 days ago • Dec 29, 2025CVE-2025-15227 is an arbitrary file read vulnerability in BPMFlowWebkit developed by WELLTEND TECHNOLOGY. Unauthenticated remote attackers can exploit...
📅 76 days ago • Dec 29, 2025WMPro software developed by Sunnet contains an arbitrary file read vulnerability due to relative path traversal. Unauthenticated remote attackers can ...
📅 76 days ago • Dec 29, 2025This CVE describes an information disclosure vulnerability in PHP's getimagesize() function where uninitialized heap memory can leak into image metada...
📅 77 days ago • Dec 27, 2025This vulnerability in PHP's PDO PostgreSQL driver causes a null pointer dereference when using prepared statements with invalid character sequences, l...
📅 77 days ago • Dec 27, 2025CVE-2025-59946 is a heap use-after-free vulnerability in NanoMQ MQTT broker caused by a data race condition in subscription information handling. This...
📅 78 days ago • Dec 27, 2025This vulnerability allows unauthenticated attackers to access administrative endpoints in DEV Systemtechnik GmbH's DEV 7113 RF over Fiber Distribution...
📅 78 days ago • Dec 26, 2025This vulnerability allows attackers to change the Administrator password and escalate privileges on Comtech EF Data CDM-625/CDM-625A satellite modems ...
📅 78 days ago • Dec 26, 2025Cola Dnslog v1.3.2 has a directory traversal vulnerability in TXT record processing that allows attackers to read arbitrary files on the server. This ...
📅 78 days ago • Dec 26, 2025A vulnerability in libxmljs 1.0.11 allows attackers to cause a segmentation fault and denial-of-service by parsing a specially crafted XML document th...
📅 78 days ago • Dec 26, 2025Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats