🔥 Trending CVEs - Last 90 Days

4,400 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
10,903
Total CVEs Published
975
Critical Severity
3,425
High Severity
⚠️
Critical Alert
975 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-14989 7.3

This SQL injection vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 allows attackers to execute arbitrary SQL commands t...

📅 85 days ago • Dec 21, 2025
CVE-2025-14968 7.3

CVE-2025-14968 is an SQL injection vulnerability in Simple Stock System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ema...

📅 86 days ago • Dec 19, 2025
CVE-2025-14959 7.3

CVE-2025-14959 is an SQL injection vulnerability in Simple Stock System 1.0 that allows remote attackers to execute arbitrary SQL commands through the...

📅 86 days ago • Dec 19, 2025
CVE-2025-14951 7.3

This vulnerability allows remote attackers to execute SQL injection attacks against the Scholars Tracking System 1.0 by manipulating the post_content ...

📅 86 days ago • Dec 19, 2025
CVE-2025-14952 7.3

Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_category.php file via the txtCategoryName parameter....

📅 86 days ago • Dec 19, 2025
CVE-2025-14950 7.3

CVE-2025-14950 is an SQL injection vulnerability in code-projects Scholars Tracking System 1.0 that allows attackers to execute arbitrary SQL commands...

📅 86 days ago • Dec 19, 2025
CVE-2025-14940 7.3

This SQL injection vulnerability in Scholars Tracking System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in /admin/del...

📅 86 days ago • Dec 19, 2025
CVE-2025-64724 7.3

Arduino IDE for macOS versions before 2.3.7 installs with world-writable file permissions on sensitive application components. This allows any local u...

📅 87 days ago • Dec 18, 2025
CVE-2025-14877 7.3

This SQL injection vulnerability in Campcodes Supplier Management System 1.0 allows attackers to execute arbitrary SQL commands through the cmbAreaCod...

📅 87 days ago • Dec 18, 2025
CVE-2025-68429 7.3

A vulnerability in Storybook versions 7.0.0 through 7.6.20, 8.0.0 through 8.6.14, 9.0.0 through 9.1.16, and 10.0.0 through 10.1.9 could expose sensiti...

📅 88 days ago • Dec 17, 2025
CVE-2025-14833 7.3

This CVE describes a SQL injection vulnerability in code-projects Online Appointment Booking System 1.0. Attackers can remotely exploit the /admin/del...

📅 88 days ago • Dec 17, 2025
CVE-2025-14832 7.3

CVE-2025-14832 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...

📅 88 days ago • Dec 17, 2025
CVE-2025-67285 7.3

This SQL injection vulnerability in the COVID Tracking System Using QR-Code v1.0 allows attackers to execute arbitrary SQL commands through the 'id' p...

📅 88 days ago • Dec 17, 2025
CVE-2026-3873 7.2

CVE-2026-3873 is a hard-coded credentials vulnerability in Avantra that allows attackers to bypass authentication and access functionality not properl...

📅 2 days ago • Mar 13, 2026
CVE-2026-32414 7.2

This CVE describes a remote code execution vulnerability in the Advanced Woo Labels WordPress plugin. Attackers can inject malicious code that gets ex...

📅 2 days ago • Mar 13, 2026
CVE-2026-20163 7.2

This vulnerability allows authenticated Splunk users with the 'edit_cmd' capability to execute arbitrary shell commands via the unarchive_cmd paramete...

📅 4 days ago • Mar 11, 2026
CVE-2026-3178 7.2

The Name Directory WordPress plugin has a stored cross-site scripting vulnerability in the 'name_directory_name' parameter that allows unauthenticated...

📅 4 days ago • Mar 11, 2026
CVE-2026-3231 7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts via WooCommerce checkout fields. When administrators view order detail...

📅 4 days ago • Mar 11, 2026
CVE-2026-1454 7.2

This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress lead form submissions. When administrators view these s...

📅 4 days ago • Mar 11, 2026
CVE-2026-20892 7.2

A code injection vulnerability in MR-GM5L-S1 and MR-GM5A-L1 devices allows authenticated administrators to execute arbitrary commands on affected syst...

📅 4 days ago • Mar 11, 2026
CVE-2026-23815 7.2

This vulnerability allows authenticated remote attackers with high privileges to perform command injection through a custom binary in AOS-CX Switches'...

📅 4 days ago • Mar 11, 2026
CVE-2026-31834 7.2

This CVE describes a privilege escalation vulnerability in Umbraco CMS where authenticated backoffice users with user management permissions can assig...

📅 5 days ago • Mar 10, 2026
CVE-2026-30958 7.2

CVE-2026-30958 is an unauthenticated path traversal vulnerability in OneUptime's workflow documentation endpoint that allows attackers to read arbitra...

📅 5 days ago • Mar 10, 2026
CVE-2026-25836 7.2

This CVE describes an OS command injection vulnerability in Fortinet FortiSandbox Cloud 5.0.4 that allows privileged attackers with super-admin profil...

📅 5 days ago • Mar 10, 2026
CVE-2026-22572 7.2

This CVE describes an authentication bypass vulnerability in Fortinet FortiAnalyzer and FortiManager products (both on-premises and cloud versions). A...

📅 5 days ago • Mar 10, 2026
CVE-2026-1261 7.2

The MetForm Pro WordPress plugin has a stored XSS vulnerability in its Quiz feature that allows unauthenticated attackers to inject malicious scripts....

📅 5 days ago • Mar 10, 2026
CVE-2025-68648 7.2

A format string vulnerability in Fortinet FortiAnalyzer and FortiManager products allows attackers to escalate privileges via specially crafted reques...

📅 5 days ago • Mar 10, 2026
CVE-2025-66178 7.2

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb web application firewalls. Authenticated attackers can execute arbitrary...

📅 5 days ago • Mar 10, 2026
CVE-2026-1074 7.2

The WP App Bar WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into plugin settings....

📅 8 days ago • Mar 7, 2026
CVE-2025-14675 7.2

The Meta Box WordPress plugin has an arbitrary file deletion vulnerability that allows authenticated attackers with Contributor-level access or higher...

📅 8 days ago • Mar 7, 2026
CVE-2026-3352 7.2

The Easy PHP Settings WordPress plugin allows authenticated attackers with Administrator privileges to inject arbitrary PHP code into wp-config.php vi...

📅 8 days ago • Mar 7, 2026
CVE-2026-25887 7.2

Chartbrew versions before 4.8.1 contain a remote code execution vulnerability in MongoDB dataset queries. Attackers can execute arbitrary code on the ...

📅 9 days ago • Mar 6, 2026
CVE-2026-3613 7.2

A remote stack-based buffer overflow vulnerability in Wavlink WL-NU516U1 router's login.cgi component allows attackers to execute arbitrary code by ma...

📅 9 days ago • Mar 6, 2026
CVE-2026-3612 7.2

This CVE describes a command injection vulnerability in Wavlink WL-NU516U1 routers that allows remote attackers to execute arbitrary commands on affec...

📅 9 days ago • Mar 6, 2026
CVE-2026-2365 7.2

The Fluent Forms Pro WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into draft form...

📅 10 days ago • Mar 5, 2026
CVE-2026-20062 7.2

This vulnerability allows authenticated local administrators in one context of Cisco ASA multi-context mode to copy files to/from other contexts via S...

📅 11 days ago • Mar 4, 2026
CVE-2026-1273 7.2

This Server-Side Request Forgery (SSRF) vulnerability in the PostX WordPress plugin allows authenticated attackers with Administrator privileges to ma...

📅 11 days ago • Mar 4, 2026
CVE-2026-1945 7.2

The WPBookit WordPress plugin has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts into w...

📅 11 days ago • Mar 4, 2026
CVE-2025-67840 7.2

Multiple authenticated OS command injection vulnerabilities in Cohesity TranZman 4.0 allow authenticated admin users to execute arbitrary commands wit...

📅 12 days ago • Mar 3, 2026
CVE-2025-63909 7.2

This vulnerability allows attackers to escalate privileges to root and read/write arbitrary files on Cohesity TranZman Migration Appliance systems due...

📅 12 days ago • Mar 3, 2026
CVE-2025-63911 7.2

CVE-2025-63911 is an authenticated command injection vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614. This allows authe...

📅 12 days ago • Mar 3, 2026
CVE-2026-2269 7.2

This vulnerability allows authenticated WordPress administrators to perform server-side request forgery (SSRF) attacks via the Uncanny Automator plugi...

📅 12 days ago • Mar 3, 2026
CVE-2026-27819 7.2

This vulnerability in Vikunja allows attackers to overwrite arbitrary files on the host system by uploading a malicious ZIP archive during configurati...

📅 18 days ago • Feb 25, 2026
CVE-2026-27624 7.2

This vulnerability allows attackers to bypass Coturn's IP address restrictions by using IPv4-mapped IPv6 addresses. Attackers can send CreatePermissio...

📅 18 days ago • Feb 25, 2026
CVE-2026-1459 7.2

This CVE describes a post-authentication command injection vulnerability in Zyxel VMG3625-T50B devices. An authenticated attacker with administrator p...

📅 19 days ago • Feb 24, 2026
CVE-2026-2980 7.2

A buffer overflow vulnerability in the UTT HiPER 810G router's administrative interface allows remote attackers to execute arbitrary code by manipulat...

📅 20 days ago • Feb 23, 2026
CVE-2026-2935 7.2

This CVE describes a remote buffer overflow vulnerability in UTT HiPER 810G routers. Attackers can exploit the strcpy function in the ConfigExceptMSN ...

📅 21 days ago • Feb 22, 2026
CVE-2026-26045 7.2

This vulnerability in Moodle's backup restore functionality allows authenticated privileged users to upload specially crafted backup files that bypass...

📅 22 days ago • Feb 21, 2026
CVE-2026-2846 7.2

This CVE describes a remote command injection vulnerability in the UTT HiPER 520 router's web management interface. Attackers can execute arbitrary op...

📅 23 days ago • Feb 20, 2026
CVE-2019-25419 7.2

Comodo Dome Firewall 2.7.0 contains a stored cross-site scripting vulnerability in the schedule endpoint. Attackers can inject malicious JavaScript vi...

📅 24 days ago • Feb 19, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free