🔥 Trending CVEs - Last 90 Days
4,390 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 exposes the ModelBuilder HMAC signing key in cleartext via the DescribeTrainingJob API. Thi...
📅 41 days ago • Feb 2, 2026This CVE describes an authenticated command injection vulnerability in TP-Link Archer BE230 routers. Attackers with admin access can execute arbitrary...
📅 41 days ago • Feb 2, 2026This CVE describes a command injection vulnerability in the Archer BE230 router's VPN Connection Service that requires admin authentication. Successfu...
📅 41 days ago • Feb 2, 2026A command injection vulnerability in TP-Link Archer BE230 routers allows authenticated attackers to execute arbitrary OS commands via the configuratio...
📅 41 days ago • Feb 2, 2026This CVE describes a command injection vulnerability in TP-Link Archer BE230 routers that allows authenticated attackers to execute arbitrary commands...
📅 41 days ago • Feb 2, 2026This CVE describes a command injection vulnerability in TP-Link Archer BE230 routers that allows authenticated attackers to execute arbitrary commands...
📅 41 days ago • Feb 2, 2026This stored XSS vulnerability in the Sell BTC WordPress plugin allows unauthenticated attackers to inject malicious scripts into order records. When a...
📅 43 days ago • Jan 31, 2026This CVE describes a local privilege escalation vulnerability in IBM Db2 where an instance owner can execute malicious code to gain root privileges. T...
📅 44 days ago • Jan 30, 2026This vulnerability allows attackers with valid credentials to execute arbitrary commands on affected Hikvision Wireless Access Points by sending speci...
📅 44 days ago • Jan 30, 2026This vulnerability allows authenticated users of certain HIKSEMI NAS products to execute arbitrary commands on the device by sending specially crafted...
📅 44 days ago • Jan 30, 2026This vulnerability allows low-privilege API keys in Immich to escalate their own permissions by calling the update endpoint, granting themselves full ...
📅 45 days ago • Jan 29, 2026This vulnerability in the AI Engine WordPress plugin allows authenticated attackers with Editor-level access or higher to upload arbitrary files, incl...
📅 46 days ago • Jan 28, 2026The TableMaster for Elementor WordPress plugin has a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers with Author-...
📅 46 days ago • Jan 28, 2026This CVE describes an OS command injection vulnerability in D-Link DIR-615 routers via the MAC Filter Configuration component. Attackers can execute a...
📅 47 days ago • Jan 28, 2026This CVE describes a remote OS command injection vulnerability in D-Link DIR-615 routers via the /set_temp_nodes.php file in the URL Filter component....
📅 47 days ago • Jan 28, 2026This CVE describes an authentication bypass vulnerability in Kargo's API endpoints. Unauthenticated attackers can access configuration data (exposing ...
📅 47 days ago • Jan 27, 2026This SQL injection vulnerability allows authenticated admin users to execute arbitrary SQL commands through the Structure component. It affects system...
📅 48 days ago • Jan 26, 2026PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the address parameter of change_params.php. Attackers can inject malicious...
📅 51 days ago • Jan 23, 2026PEEL Shopping 9.3.0 contains a stored cross-site scripting vulnerability in the 'Comments / Special Instructions' field of the purchase page. Attacker...
📅 51 days ago • Jan 23, 2026This Server-Side Request Forgery (SSRF) vulnerability in the WP Messiah Frontis Blocks WordPress plugin allows attackers to make unauthorized requests...
📅 52 days ago • Jan 22, 2026Quick.Cart e-commerce software contains a Local File Inclusion and Path Traversal vulnerability in its theme selection mechanism. This allows authenti...
📅 52 days ago • Jan 22, 2026This CVE describes an OS command injection vulnerability in Ruijie AP180 series access points running vulnerable firmware versions. Attackers can exec...
📅 53 days ago • Jan 22, 2026This stored cross-site scripting vulnerability in VestaCP allows attackers to inject malicious scripts into the IP interface configuration. When admin...
📅 53 days ago • Jan 21, 2026OpenLiteSpeed 1.7.9 contains a stored cross-site scripting vulnerability in the dashboard's Notes parameter that allows attackers to inject malicious ...
📅 53 days ago • Jan 21, 2026Moodle 3.10.3 contains a persistent cross-site scripting vulnerability in calendar event subtitles that allows attackers to inject malicious JavaScrip...
📅 53 days ago • Jan 21, 2026This stored cross-site scripting vulnerability in Genexis Platinum-4410 routers allows attackers to inject malicious scripts into the 'start_addr' par...
📅 53 days ago • Jan 21, 2026CVE-2021-47778 is a PHP code injection vulnerability in GetSimple CMS My SMTP Contact Plugin 1.1.2 that allows authenticated administrators to execute...
📅 53 days ago • Jan 21, 2026This vulnerability allows unauthenticated attackers to inject malicious scripts into WordPress sites using the NotificationX plugin. When users visit ...
📅 54 days ago • Jan 20, 2026An authenticated SQL injection vulnerability in WeGIA's Atendido_ocorrenciaControle endpoint allows attackers to extract sensitive data from the datab...
📅 58 days ago • Jan 16, 2026StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability where attackers can upload malicious markdown files containing JavaScript paylo...
📅 58 days ago • Jan 16, 2026Markdownify 1.2.0 contains a persistent cross-site scripting (XSS) vulnerability that allows attackers to upload malicious markdown files containing e...
📅 58 days ago • Jan 16, 2026Markright 1.0 contains a persistent cross-site scripting (XSS) vulnerability where attackers can embed malicious JavaScript in markdown files. When us...
📅 58 days ago • Jan 16, 2026CVE-2021-47839 is a persistent cross-site scripting (XSS) vulnerability in Marky 0.0.1 that allows attackers to inject malicious JavaScript into markd...
📅 58 days ago • Jan 16, 2026Moeditor 0.2.0 contains a persistent cross-site scripting (XSS) vulnerability where attackers can embed malicious JavaScript in markdown files. When v...
📅 58 days ago • Jan 16, 2026Freeter 1.2.1 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious scripts in custom widget titles and fi...
📅 58 days ago • Jan 16, 2026This CVE describes a cross-site scripting (XSS) vulnerability in LemonLDAP::NG's portal login page. Attackers can inject malicious scripts via the tab...
📅 58 days ago • Jan 16, 2026This vulnerability in Supermicro BMC firmware allows attackers to bypass validation checks and install malicious firmware images on affected servers. ...
📅 58 days ago • Jan 16, 2026This CVE describes a code injection vulnerability in Shopware's map() function where PHP Closures can bypass allow-list validation. It affects Shopwar...
📅 60 days ago • Jan 14, 2026This vulnerability allows authenticated remote attackers to perform SQL injection attacks on EdgeConnect SD-WAN Orchestrator's web management interfac...
📅 60 days ago • Jan 14, 2026This SQL injection vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to execute arbitrary SQL...
📅 60 days ago • Jan 14, 2026This SQL injection vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to execute arbitrary SQL...
📅 60 days ago • Jan 14, 2026The Name Directory WordPress plugin up to version 1.30.3 has a stored cross-site scripting vulnerability that allows unauthenticated attackers to inje...
📅 60 days ago • Jan 14, 2026The AJS Footnotes WordPress plugin has a stored XSS vulnerability that allows unauthenticated attackers to inject malicious scripts into website pages...
📅 60 days ago • Jan 14, 2026This stored XSS vulnerability in the GeekyBot WordPress plugin allows unauthenticated attackers to inject malicious scripts via chat messages. When ad...
📅 60 days ago • Jan 14, 2026The GetContentFromURL WordPress plugin is vulnerable to Server-Side Request Forgery (SSRF) in all versions up to 1.0. This allows authenticated attack...
📅 60 days ago • Jan 14, 2026CVE-2022-50939 is a critical file upload vulnerability in e107 CMS version 3.2.1 that allows authenticated administrators to overwrite arbitrary serve...
📅 61 days ago • Jan 13, 2026CVE-2022-50916 is a file upload vulnerability in e107 CMS version 3.2.1 that allows authenticated administrators to overwrite server files through Med...
📅 61 days ago • Jan 13, 2026Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow attackers with valid credentials to execute arbitrary...
📅 61 days ago • Jan 13, 2026Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow authenticated attackers to execute arbitrary commands...
📅 61 days ago • Jan 13, 2026An authenticated attacker with valid credentials can exploit improper input handling in the web management interface of Aruba mobility conductors runn...
📅 61 days ago • Jan 13, 2026Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats