🔥 Trending CVEs - Last 90 Days

4,448 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
10,988
Total CVEs Published
982
Critical Severity
3,466
High Severity
⚠️
Critical Alert
982 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-20853 7.4

This vulnerability is a race condition in Windows WalletService that allows local attackers to gain elevated privileges by exploiting improper synchro...

📅 60 days ago • Jan 13, 2026
CVE-2026-20844 7.4

This vulnerability involves a use-after-free flaw in the Windows Clipboard Server that allows an unauthorized local attacker to execute arbitrary code...

📅 60 days ago • Jan 13, 2026
CVE-2025-69211 7.4

NestJS applications using Fastify platform with route-specific middleware are vulnerable to URL encoding bypass. This allows attackers to access prote...

📅 76 days ago • Dec 29, 2025
CVE-2025-68922 7.4

CVE-2025-68922 is a remote code execution vulnerability in OpenOps that allows attackers to execute arbitrary commands via the Terraform block. This a...

📅 80 days ago • Dec 25, 2025
CVE-2025-68644 7.4

Yealink RPS (Remote Provisioning Service) before June 27, 2025 allows unauthorized access to sensitive information including AutoP URL addresses due t...

📅 84 days ago • Dec 21, 2025
CVE-2025-48429 7.4

An out-of-bounds read vulnerability in Grassroot DICOM's RLECodec::DecodeByStreams function allows attackers to leak heap memory data by providing a s...

📅 88 days ago • Dec 16, 2025
CVE-2025-52582 7.4

An out-of-bounds read vulnerability in Grassroot DICOM's Overlay::GrabOverlayFromPixelData function allows attackers to leak sensitive information by ...

📅 88 days ago • Dec 16, 2025
CVE-2025-53618 7.4

An out-of-bounds read vulnerability in Grassroot DICOM's JPEGBITSCodec::InternalCode function allows attackers to leak sensitive information by provid...

📅 88 days ago • Dec 16, 2025
CVE-2025-53619 7.4

An out-of-bounds read vulnerability in Grassroot DICOM's JPEGBITSCodec::InternalCode function allows attackers to leak sensitive information by provid...

📅 88 days ago • Dec 16, 2025
CVE-2026-25076 7.3

An authenticated attacker with access to the GraphQL Reports API in Anchore Enterprise can execute arbitrary SQL commands through an SQL injection vul...

⚡ Yesterday • Mar 13, 2026
CVE-2026-4014 7.3

CVE-2026-4014 is an SQL injection vulnerability in itsourcecode Cafe Reservation System 1.0 that allows attackers to manipulate database queries throu...

📅 3 days ago • Mar 12, 2026
CVE-2026-3980 7.3

This SQL injection vulnerability in Online Doctor Appointment System 1.0 allows attackers to manipulate database queries through the patient_id parame...

📅 3 days ago • Mar 12, 2026
CVE-2026-3969 7.3

This CVE describes a SQL injection vulnerability in FeMiner wms up to version 1.0, specifically in the Basic Organizational Structure Module. Attacker...

📅 3 days ago • Mar 12, 2026
CVE-2026-3943 7.3

This vulnerability allows remote attackers to execute arbitrary commands on H3C ACG1000-AK230 devices by manipulating the suffix parameter in the /web...

📅 4 days ago • Mar 11, 2026
CVE-2026-2364 7.3

A local attacker with low privileges can exploit a TOCTOU (Time-of-Check Time-of-Use) vulnerability in the CODESYS installer to gain elevated system r...

📅 4 days ago • Mar 10, 2026
CVE-2026-29023 7.3

Keygraph Shannon contains a hard-coded API key in its router configuration that allows network attackers to authenticate using a publicly known static...

📅 5 days ago • Mar 9, 2026
CVE-2026-3818 7.3

This CVE describes a SQL injection vulnerability in Tiandy Easy7 CMS Windows version 7.17.0. Attackers can remotely exploit the /Easy7/apps/WebService...

📅 6 days ago • Mar 9, 2026
CVE-2026-3794 7.3

This vulnerability allows attackers to bypass authentication in DoraCMS 3.0.x by exploiting the Email API endpoint /api/v1/mail/send. Attackers can re...

📅 6 days ago • Mar 9, 2026
CVE-2026-3764 7.3

This vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to bypass authorization controls and perform unauthorized ...

📅 6 days ago • Mar 8, 2026
CVE-2026-3762 7.3

This vulnerability in SourceCodester Client Database Management System allows unauthorized deletion of manager accounts via improper authorization in ...

📅 6 days ago • Mar 8, 2026
CVE-2026-3757 7.3

CVE-2026-3757 is a SQL injection vulnerability in projectworlds Online Art Gallery Shop 1.0 that allows remote attackers to execute arbitrary SQL comm...

📅 6 days ago • Mar 8, 2026
CVE-2026-3759 7.3

This SQL injection vulnerability in projectworlds Online Art Gallery Shop 1.0 allows remote attackers to execute arbitrary SQL commands via the reach_...

📅 6 days ago • Mar 8, 2026
CVE-2026-3746 7.3

CVE-2026-3746 is an SQL injection vulnerability in SourceCodester Simple Responsive Tourism Website 1.0 that allows attackers to execute arbitrary SQL...

📅 7 days ago • Mar 8, 2026
CVE-2026-3744 7.3

This SQL injection vulnerability in Student Web Portal 1.0 allows attackers to manipulate database queries through the password registration field. Re...

📅 7 days ago • Mar 8, 2026
CVE-2026-3740 7.3

This CVE describes a SQL injection vulnerability in itsourcecode University Management System 1.0, specifically in the /admin_search_student.php file....

📅 7 days ago • Mar 8, 2026
CVE-2026-3736 7.3

This CVE describes a SQL injection vulnerability in code-projects Simple Flight Ticket Booking System 1.0. Attackers can manipulate the 'from' paramet...

📅 7 days ago • Mar 8, 2026
CVE-2026-3734 7.3

This vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to bypass authorization controls by manipulating the manag...

📅 7 days ago • Mar 8, 2026
CVE-2026-3723 7.3

This SQL injection vulnerability in Simple Flight Ticket Booking System 1.0 allows attackers to manipulate database queries through the flightno param...

📅 7 days ago • Mar 8, 2026
CVE-2026-3709 7.3

CVE-2026-3709 is a SQL injection vulnerability in Simple Flight Ticket Booking System 1.0 that allows attackers to manipulate database queries through...

📅 7 days ago • Mar 8, 2026
CVE-2026-3708 7.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the Username parameter in the login.php file of Simple Flight Ticket ...

📅 7 days ago • Mar 8, 2026
CVE-2026-3693 7.3

This vulnerability in Shy2593666979 AgentChat allows attackers to manipulate user_id parameters in user information functions, enabling unauthorized a...

📅 7 days ago • Mar 8, 2026
CVE-2026-3696 7.3

This CVE describes a remote command injection vulnerability in Totolink N300RH routers. Attackers can execute arbitrary operating system commands by m...

📅 7 days ago • Mar 8, 2026
CVE-2026-29082 7.3

This vulnerability allows attackers to inject malicious HTML/JavaScript into Kestra's execution-file preview feature, leading to cross-site scripting ...

📅 8 days ago • Mar 6, 2026
CVE-2026-27764 7.3

This WebSocket vulnerability allows session hijacking in charging station management systems by enabling multiple connections with the same predictabl...

📅 9 days ago • Mar 6, 2026
CVE-2026-20748 7.3

This WebSocket vulnerability allows session hijacking by connecting with predictable charging station identifiers, enabling attackers to impersonate l...

📅 9 days ago • Mar 6, 2026
CVE-2026-28721 7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 17 for Windows due to improper handling of symbolic links. Atta...

📅 9 days ago • Mar 6, 2026
CVE-2026-28722 7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect 17 for Windows due to improper handling of symbolic links. An a...

📅 9 days ago • Mar 6, 2026
CVE-2025-11792 7.3

This CVE describes a local privilege escalation vulnerability in Acronis Cyber Protect Cloud Agent for Windows. Attackers can exploit DLL hijacking to...

📅 9 days ago • Mar 6, 2026
CVE-2026-26276 7.3

This CVE describes a DOM-based cross-site scripting (XSS) vulnerability in Gogs self-hosted Git service. Attackers can inject malicious JavaScript int...

📅 9 days ago • Mar 5, 2026
CVE-2026-28542 7.3

A permission bypass vulnerability in Huawei's system service framework allows attackers to circumvent intended access controls. This affects availabil...

📅 10 days ago • Mar 5, 2026
CVE-2026-3413 7.3

This SQL injection vulnerability in itsourcecode University Management System 1.0 allows attackers to manipulate database queries through the ID param...

📅 13 days ago • Mar 2, 2026
CVE-2026-3411 7.3

This SQL injection vulnerability in itsourcecode University Management System 1.0 allows attackers to manipulate database queries through the /admin_s...

📅 13 days ago • Mar 2, 2026
CVE-2026-3409 7.3

This CVE-2026-3409 vulnerability allows remote attackers to execute arbitrary code through a code injection flaw in the Flow Import Endpoint of eospho...

📅 13 days ago • Mar 2, 2026
CVE-2026-3406 7.3

This SQL injection vulnerability in Online Art Gallery Shop 1.0 allows attackers to manipulate database queries through the registration form's fname ...

📅 13 days ago • Mar 2, 2026
CVE-2026-3395 7.3

This vulnerability allows remote attackers to execute arbitrary code on MaxSite CMS installations through a code injection flaw in the MarkItUp Previe...

📅 14 days ago • Mar 1, 2026
CVE-2026-25733 7.3

Rucio versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting vulnerability in the WebUI's Custom Rules function. This allows ...

📅 17 days ago • Feb 25, 2026
CVE-2026-3164 7.3

This SQL injection vulnerability in itsourcecode News Portal Project 1.0 allows attackers to manipulate database queries through the pagetitle paramet...

📅 18 days ago • Feb 25, 2026
CVE-2026-3151 7.3

CVE-2026-3151 is an SQL injection vulnerability in itsourcecode College Management System 1.0 that allows attackers to manipulate database queries thr...

📅 18 days ago • Feb 25, 2026
CVE-2026-3153 7.3

This SQL injection vulnerability in itsourcecode Document Management System 1.0 allows attackers to execute arbitrary SQL commands via the Username pa...

📅 18 days ago • Feb 25, 2026
CVE-2026-3135 7.3

This SQL injection vulnerability in itsourcecode News Portal Project 1.0 allows attackers to manipulate database queries through the Category paramete...

📅 18 days ago • Feb 25, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free