🔥 Trending CVEs - Last 90 Days
4,459 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
This vulnerability in Kentico Xperience allows attackers to view detailed error messages containing sensitive stack trace information through Portal E...
📅 86 days ago • Dec 18, 2025A cryptography vulnerability in Kentico Xperience allows attackers to manipulate URL hash values, potentially enabling unauthorized actions or data ac...
📅 86 days ago • Dec 18, 2025A denial-of-service vulnerability in omec-project UPF's pfcpiface component allows attackers to crash the UPF process by sending malformed PFCP Sessio...
📅 86 days ago • Dec 18, 2025A denial-of-service vulnerability in the omec-project UPF's pfcpiface component allows attackers to crash the UPF process by sending specially crafted...
📅 86 days ago • Dec 18, 2025A denial-of-service vulnerability in the omec-project UPF's pfcpiface component allows attackers to crash the UPF by sending specially crafted PFCP Se...
📅 86 days ago • Dec 18, 2025CVE-2025-63387 is an insecure permissions vulnerability in Dify v1.9.1 that allows unauthenticated attackers to access the /console/api/system-feature...
📅 86 days ago • Dec 18, 2025A reachable assertion vulnerability in Open5GS UPF component causes denial of service when processing malformed PFCP Session Establishment Requests wi...
📅 86 days ago • Dec 18, 2025A vulnerability in free5GC's LocalNode.Sess function allows attackers to send crafted PFCP Session Modification Requests with malicious Local SEID hea...
📅 86 days ago • Dec 18, 2025CVE-2025-65562 is an unauthenticated denial-of-service vulnerability in free5GC UPF where specially crafted PFCP Session Deletion Requests with large ...
📅 86 days ago • Dec 18, 2025A denial-of-service vulnerability in omec-project UPF allows attackers to crash the UPF process by sending malformed PFCP Association Setup Request me...
📅 86 days ago • Dec 18, 2025A denial-of-service vulnerability in omec-upf's PFCP interface allows attackers to crash the UPF process by sending malformed PFCP Association Setup R...
📅 86 days ago • Dec 18, 2025An improper authentication vulnerability in TP-Link WA850RE Wi-Fi range extenders allows unauthenticated attackers to download the device configuratio...
📅 86 days ago • Dec 18, 2025CVE-2025-14896 is a server-side request forgery (SSRF) vulnerability in Vega's convert() function when safeMode is enabled and the spec parameter is a...
📅 86 days ago • Dec 18, 2025An authentication bypass vulnerability in Open-WebUI's /api/config endpoint allows unauthenticated remote attackers to access sensitive system configu...
📅 86 days ago • Dec 18, 2025CVE-2025-7358 is a hard-coded credentials vulnerability in Utarit Informatics Services Inc. SoliClub software that allows attackers to bypass authenti...
📅 86 days ago • Dec 18, 2025An integer overflow vulnerability in FFmpeg's libswscale component allows attackers to cause heap corruption when processing specially crafted YUV vid...
📅 86 days ago • Dec 18, 2025CVE-2025-1029 is a hard-coded credentials vulnerability in Utarit Information Services SoliClub software that allows attackers to extract sensitive au...
📅 86 days ago • Dec 18, 2025This vulnerability in Utarit Informatics Services Inc. SoliClub allows unauthorized actors to query the system and access private personal information...
📅 86 days ago • Dec 18, 2025This vulnerability allows attackers to bypass authorization controls in Utarit Informatics Services Inc. SoliClub by manipulating user-controlled keys...
📅 86 days ago • Dec 18, 2025The Hummingbird Performance WordPress plugin exposes sensitive information including Cloudflare API credentials to unauthenticated attackers via the '...
📅 87 days ago • Dec 18, 2025A denial-of-service vulnerability in Nodemailer allows attackers to crash email-sending applications by sending specially crafted email addresses that...
📅 87 days ago • Dec 18, 2025This vulnerability in Ultimate Member Widgets for Elementor WordPress plugin allows attackers to retrieve embedded sensitive data from the plugin's wi...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the Ays Pro Easy Form WordPress plugin that allows attackers to bypass access controls. It...
📅 87 days ago • Dec 18, 2025This CVE describes a missing authorization vulnerability in the LearnPress WordPress plugin that allows attackers to bypass access controls and perfor...
📅 87 days ago • Dec 18, 2025This CVE describes a missing authorization vulnerability in the wpForo Forum WordPress plugin that allows attackers to bypass access controls. It affe...
📅 87 days ago • Dec 18, 2025This CVE describes a missing authorization vulnerability in PropertyHive WordPress plugin that allows attackers to bypass access controls. It affects ...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the ListingPro WordPress theme that allows attackers to bypass access controls. It affects...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the Arraytics Timetics WordPress plugin that allows attackers to bypass access controls. I...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the GetResponse Email Marketing WordPress plugin that allows attackers to exploit incorrec...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the FantasticPlugins WooCommerce Recover Abandoned Cart plugin that allows attackers to de...
📅 87 days ago • Dec 18, 2025This path traversal vulnerability in the WP Chill Filr WordPress plugin allows attackers to delete arbitrary files on the server. It affects all WordP...
📅 87 days ago • Dec 18, 2025The Follow My Blog Post WordPress plugin (versions up to 2.3.9) exposes sensitive system information to unauthorized users. This vulnerability allows ...
📅 87 days ago • Dec 18, 2025This CVE describes a missing authorization vulnerability in the Masterstudy WordPress theme that allows attackers to access functionality not properly...
📅 87 days ago • Dec 18, 2025This vulnerability in MasterStudy LMS Pro WordPress plugin allows attackers to retrieve embedded sensitive data from the system. It affects all WordPr...
📅 87 days ago • Dec 18, 2025This CVE describes a missing authorization vulnerability in the MasterStudy LMS Pro WordPress plugin that allows attackers to access functionality not...
📅 87 days ago • Dec 18, 2025This vulnerability in the Passster WordPress plugin allows attackers to retrieve embedded sensitive data that should be protected. It affects all Word...
📅 87 days ago • Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
📅 87 days ago • Dec 18, 2025This vulnerability allows attackers to execute arbitrary code through PHP object injection by exploiting unsafe deserialization in the PDF for Gravity...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the WP Voting Contest WordPress plugin that allows attackers to exploit incorrectly config...
📅 87 days ago • Dec 18, 2025This CVE describes a PHP Local File Inclusion vulnerability in the Ray Enterprise Translation WordPress plugin. Attackers can exploit improper filenam...
📅 87 days ago • Dec 18, 2025This CVE describes a missing authorization vulnerability in the YayPricing WordPress plugin that allows attackers to access functionality not properly...
📅 87 days ago • Dec 18, 2025This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the ThemeAtelier IDonatePro WordPress plugin that allows attackers to access functionality...
📅 87 days ago • Dec 18, 2025This CVE describes a Missing Authorization vulnerability in the Javo Core WordPress plugin that allows attackers to delete arbitrary content without p...
📅 87 days ago • Dec 18, 2025CVE-2023-53930 is an insecure direct object reference vulnerability in ProjectSend r1605 that allows unauthenticated attackers to download private fil...
📅 87 days ago • Dec 17, 2025An unprivileged user can cause a Blue Screen of Death (BSOD) on Windows computers running vulnerable DriveLock versions by sending a specific IOCTL wi...
📅 87 days ago • Dec 17, 2025This vulnerability in Homarr allows privilege escalation and unauthorized access to other users' groups through crafted LDAP search queries due to ins...
📅 87 days ago • Dec 17, 2025A NULL pointer dereference vulnerability in RIOT OS's IPv6 fragmentation reassembly allows remote attackers to crash the operating system by sending s...
📅 87 days ago • Dec 17, 2025AVideo versions before 20.1 expose sensitive user information through an unauthenticated public API endpoint. This allows attackers to enumerate users...
📅 87 days ago • Dec 17, 2025AVideo versions before 20.1 expose absolute server filesystem paths through public API endpoints. This information disclosure vulnerability reveals in...
📅 87 days ago • Dec 17, 2025Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats