🔥 Trending CVEs - Last 90 Days

4,453 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
10,998
Total CVEs Published
984
Critical Severity
3,469
High Severity
⚠️
Critical Alert
984 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-68274 7.5

A nil pointer dereference vulnerability in SIPGO library's NewResponseFromRequest function allows remote attackers to crash SIP applications by sendin...

📅 88 days ago • Dec 16, 2025
CVE-2025-68155 7.5

This vulnerability in @vitejs/plugin-rsc allows unauthenticated attackers to read arbitrary files accessible to the Node.js process during development...

📅 88 days ago • Dec 16, 2025
CVE-2025-68156 7.5

This vulnerability in Expr for Go allows denial-of-service attacks through stack overflow panics. Attackers can crash applications by providing deeply...

📅 88 days ago • Dec 16, 2025
CVE-2025-10450 7.5

CVE-2025-10450 is an exposure of private personal information vulnerability in RTI Connext Professional Core Libraries that allows unauthorized actors...

📅 88 days ago • Dec 16, 2025
CVE-2025-13474 7.5

This vulnerability allows attackers to bypass authorization mechanisms in Menulux Software Inc.'s Mobile App by manipulating user-controlled keys to e...

📅 89 days ago • Dec 16, 2025
CVE-2025-68067 7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP's include/require statements. It aff...

📅 89 days ago • Dec 16, 2025
CVE-2025-68068 7.5

This vulnerability allows attackers to include local files on the server through the Stockholm WordPress theme's PHP code. Attackers can potentially r...

📅 89 days ago • Dec 16, 2025
CVE-2025-68061 7.5

This vulnerability allows attackers to include local PHP files through improper filename control in the EduMall WordPress theme. Attackers can potenti...

📅 89 days ago • Dec 16, 2025
CVE-2025-68062 7.5

This CVE describes a PHP Local File Inclusion vulnerability in the MinimogWP WordPress theme. Attackers can include arbitrary local files, potentially...

📅 89 days ago • Dec 16, 2025
CVE-2025-68065 7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

📅 89 days ago • Dec 16, 2025
CVE-2025-68066 7.5

This vulnerability allows attackers to include local files on the server through improper filename control in PHP include/require statements. It affec...

📅 89 days ago • Dec 16, 2025
CVE-2025-61976 7.5

CVE-2025-61976 is an improper condition check vulnerability in CHOCO TEI WATCHER mini (IB-MCT001) that allows remote attackers to send specially craft...

📅 89 days ago • Dec 16, 2025
CVE-2025-62847 7.5

This CVE describes an argument injection vulnerability in QNAP operating systems where attackers can manipulate command arguments to alter execution l...

📅 89 days ago • Dec 16, 2025
CVE-2023-53886 7.5

Xlight FTP Server 3.9.3.6 contains a stack buffer overflow vulnerability in the 'Execute Program' configuration that allows attackers to crash the app...

📅 89 days ago • Dec 15, 2025
CVE-2025-65176 7.5

Dynatrace OneAgent versions before 1.325.47 automatically retry failed network share access attempts using all available user tokens, enabling NTLM re...

📅 89 days ago • Dec 15, 2025
CVE-2025-71263 7.4

A buffer overflow vulnerability exists in the su command of UNIX Fourth Research Edition (v4) due to a fixed-size 100-byte password buffer. Local user...

⚡ Yesterday • Mar 13, 2026
CVE-2026-32132 7.4

ZITADEL identity management platform versions before 3.4.8 and 4.12.2 contain a passkey registration vulnerability where improper expiration checks al...

📅 3 days ago • Mar 11, 2026
CVE-2026-20074 7.4

This vulnerability in Cisco IOS XR's IS-IS multi-instance routing allows an unauthenticated attacker on the same network segment to send specially cra...

📅 3 days ago • Mar 11, 2026
CVE-2025-66413 7.4

This vulnerability in Git for Windows allows attackers to steal users' NTLM password hashes by tricking them into cloning from a malicious Git server....

📅 4 days ago • Mar 10, 2026
CVE-2026-2713 7.4

This vulnerability in IBM Trusteer Rapport installer 3.5.2309.290 allows a local attacker to execute arbitrary code via DLL hijacking. Attackers can p...

📅 4 days ago • Mar 10, 2026
CVE-2026-25573 7.4

This CVE describes a command injection vulnerability in Siemens SICAM SIAPP SDK where user-controlled input is improperly sanitized before being used ...

📅 4 days ago • Mar 10, 2026
CVE-2026-25569 7.4

An out-of-bounds write vulnerability in SICAM SIAPP SDK allows attackers to write data beyond allocated buffers. This could lead to denial of service ...

📅 4 days ago • Mar 10, 2026
CVE-2026-25167 7.4

CVE-2026-25167 is a use-after-free vulnerability in Microsoft Brokering File System that allows local attackers to execute arbitrary code with elevate...

📅 4 days ago • Mar 10, 2026
CVE-2026-27981 7.4

This vulnerability allows attackers to bypass authentication rate limiting in HomeBox by forging IP headers, enabling brute-force attacks on login cre...

📅 11 days ago • Mar 3, 2026
CVE-2026-27800 7.4

Zed code editor versions before 0.224.4 contain a Zip Slip vulnerability in the extension archive extraction functionality. This allows malicious exte...

📅 17 days ago • Feb 26, 2026
CVE-2026-20010 7.4

An unauthenticated attacker on the same network segment can send a specially crafted LLDP packet to vulnerable Cisco NX-OS devices, causing the LLDP p...

📅 17 days ago • Feb 25, 2026
CVE-2026-25967 7.4

This vulnerability is a stack-based buffer overflow in ImageMagick's FTXT image reader, allowing crafted FTXT files to cause out-of-bounds writes on t...

📅 19 days ago • Feb 24, 2026
CVE-2025-63945 7.4

A local privilege escalation vulnerability in Tencent iOA for Windows allows authenticated local users to execute programs with elevated privileges by...

📅 19 days ago • Feb 23, 2026
CVE-2025-70045 7.4

This vulnerability allows man-in-the-middle attacks by disabling TLS/SSL certificate validation in jxcore jxm master. When 'jx_obj.IsSecure' is true, ...

📅 19 days ago • Feb 23, 2026
CVE-2025-68051 7.4

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the Shiprocket WordPress plugin that allows attackers to bypass authori...

📅 22 days ago • Feb 20, 2026
CVE-2025-33088 7.4

This vulnerability allows local users with knowledge of IBM Concert's system architecture to escalate privileges by exploiting incorrect file permissi...

📅 25 days ago • Feb 17, 2026
CVE-2025-70093 7.4

This vulnerability in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code on the server by sending a specially crafted AJAX response. This...

📅 29 days ago • Feb 13, 2026
CVE-2026-26214 7.4

This vulnerability in the Galaxy FDS Android SDK disables TLS hostname verification, allowing man-in-the-middle attackers to intercept and modify comm...

📅 30 days ago • Feb 12, 2026
CVE-2026-25478 7.4

Litestar ASGI framework versions before 2.20.0 have a CORS origin validation bypass vulnerability. Attackers can craft malicious origin headers that m...

📅 33 days ago • Feb 9, 2026
CVE-2025-68621 7.4

A critical timing attack vulnerability in Trilium Notes allows unauthenticated remote attackers to recover authentication hashes through statistical t...

📅 36 days ago • Feb 6, 2026
CVE-2026-1707 7.4

pgAdmin 9.11 in server mode has a restore restriction bypass vulnerability that allows authenticated attackers to execute arbitrary commands on the ho...

📅 37 days ago • Feb 5, 2026
CVE-2026-24052 7.4

CVE-2026-24052 is a URL validation bypass vulnerability in Claude Code's trusted domain verification. Attackers could register malicious subdomains th...

📅 39 days ago • Feb 3, 2026
CVE-2025-69419 7.4

This OpenSSL vulnerability allows memory corruption via a malicious PKCS#12 file containing non-ASCII BMP characters in the friendly name field. When ...

📅 46 days ago • Jan 27, 2026
CVE-2026-21521 7.4

This vulnerability in Copilot allows attackers to exploit improper input sanitization to extract sensitive information over network connections. It af...

📅 51 days ago • Jan 22, 2026
CVE-2026-21524 7.4

This vulnerability in Azure Data Explorer allows unauthorized attackers to access sensitive information over the network. It affects organizations usi...

📅 51 days ago • Jan 22, 2026
CVE-2025-69822 7.4

This vulnerability in Atomberg Erica Smart Fan firmware allows attackers to send crafted deauthentication frames to extract sensitive information and ...

📅 51 days ago • Jan 22, 2026
CVE-2025-69821 7.4

A vulnerability in Beat XP VEGA Smartwatch firmware allows attackers to cause denial of service via Bluetooth Low Energy (BLE) connections. This affec...

📅 51 days ago • Jan 22, 2026
CVE-2026-0723 7.4

This vulnerability allows an attacker with knowledge of a victim's credential ID to bypass two-factor authentication in GitLab by submitting forged de...

📅 52 days ago • Jan 22, 2026
CVE-2025-65098 7.4

This vulnerability in Typebot allows attackers to steal stored credentials (OpenAI keys, Google Sheets tokens, SMTP passwords) from any user who previ...

📅 52 days ago • Jan 22, 2026
CVE-2025-68141 7.4

A null pointer dereference vulnerability in EVerest EV charging software allows remote attackers to cause denial of service by sending specially craft...

📅 52 days ago • Jan 21, 2026
CVE-2025-68136 7.4

This vulnerability in EVerest EV charging software allows attackers to cause denial of service through null pointer dereference when handling SDP requ...

📅 52 days ago • Jan 21, 2026
CVE-2025-68134 7.4

This vulnerability in EVerest EV charging software allows attackers to cause denial of service by triggering assertion failures that crash individual ...

📅 52 days ago • Jan 21, 2026
CVE-2025-68133 7.4

This vulnerability in EVerest EV charging software allows attackers to cause denial of service by exhausting system memory through unlimited TCP conne...

📅 53 days ago • Jan 21, 2026
CVE-2025-11043 7.4

An improper certificate validation vulnerability in OPC-UA and ANSL over TLS clients in Automation Studio allows attackers to intercept and manipulate...

📅 54 days ago • Jan 19, 2026
CVE-2026-22816 7.4

This vulnerability in Gradle's dependency resolution allows an attacker to serve malicious artifacts if they can register a domain name matching an un...

📅 57 days ago • Jan 16, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free