🔥 Trending CVEs - Last 90 Days

4,387 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
10,870
Total CVEs Published
972
Critical Severity
3,415
High Severity
⚠️
Critical Alert
972 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-68846 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Asynchronous Javascript WordPress plugin. When users v...

📅 23 days ago • Feb 20, 2026
CVE-2025-68848 7.1

This vulnerability allows attackers to inject malicious scripts into the amr cron manager WordPress plugin, which are then reflected back to users' br...

📅 23 days ago • Feb 20, 2026
CVE-2025-68842 7.1

This CVE describes a reflected cross-site scripting (XSS) vulnerability in the Widget Logic Visual WordPress plugin. Attackers can inject malicious sc...

📅 23 days ago • Feb 20, 2026
CVE-2025-68495 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Crocoblock JetEngine WordPress plugin. It allows attackers to inject malicious scr...

📅 23 days ago • Feb 20, 2026
CVE-2025-67990 7.1

This Cross-Site Scripting (XSS) vulnerability in the RealMag777 GMap Targeting WordPress plugin allows attackers to inject malicious scripts into web ...

📅 23 days ago • Feb 20, 2026
CVE-2025-67978 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Educare WordPress plugin. When users visit a specially...

📅 23 days ago • Feb 20, 2026
CVE-2025-67971 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the FluentCart WordPress plugin. Attackers can inject malicious scripts via crafted UR...

📅 23 days ago • Feb 20, 2026
CVE-2025-53237 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the WP Wizard Cloak WordPress plugin that allows attackers to inject malicious scripts...

📅 23 days ago • Feb 20, 2026
CVE-2025-53231 7.1

This stored cross-site scripting (XSS) vulnerability in the WordPress Easy Taxonomy Images plugin allows attackers to inject malicious scripts into we...

📅 23 days ago • Feb 20, 2026
CVE-2026-26960 7.1

CVE-2026-26960 is a path traversal vulnerability in node-tar that allows attackers to create hardlinks pointing outside the extraction directory when ...

📅 24 days ago • Feb 20, 2026
CVE-2026-23547 7.1

This CVE describes a Missing Authorization vulnerability in CMSMasters Content Composer WordPress plugin that allows attackers to bypass access contro...

📅 24 days ago • Feb 19, 2026
CVE-2026-22048 7.1

StorageGRID versions with Single Sign-on enabled and configured to use Microsoft Entra ID are vulnerable to Server-Side Request Forgery (SSRF). This a...

📅 26 days ago • Feb 18, 2026
CVE-2025-70846 7.1

Aidigu v1.9.1 contains a stored cross-site scripting vulnerability in the password input field on the /tools/Password/add page. This allows attackers ...

📅 26 days ago • Feb 17, 2026
CVE-2025-36247 7.1

IBM Db2 databases running vulnerable versions are susceptible to XML external entity injection (XXE) attacks when processing XML data. This allows rem...

📅 26 days ago • Feb 17, 2026
CVE-2026-20641 7.1

This CVE describes a privacy vulnerability in Apple operating systems where an app could potentially identify what other apps a user has installed, ex...

📅 32 days ago • Feb 11, 2026
CVE-2026-20628 7.1

This CVE describes a sandbox escape vulnerability in multiple Apple operating systems where an app can bypass its security restrictions. It affects us...

📅 32 days ago • Feb 11, 2026
CVE-2026-20606 7.1

This vulnerability allows applications to bypass certain privacy preferences on Apple operating systems, potentially accessing sensitive user data wit...

📅 32 days ago • Feb 11, 2026
CVE-2026-20611 7.1

This CVE describes an out-of-bounds memory access vulnerability in Apple's media file processing across multiple operating systems. Attackers can craf...

📅 32 days ago • Feb 11, 2026
CVE-2026-25999 7.1

CVE-2026-25999 is an improper access control vulnerability in Klaw (Apache Kafka management portal) that allows unauthorized users to reset or delete ...

📅 32 days ago • Feb 11, 2026
CVE-2025-62676 7.1

A local privilege escalation vulnerability in Fortinet FortiClient for Windows allows low-privileged attackers to write arbitrary files with elevated ...

📅 33 days ago • Feb 10, 2026
CVE-2025-11142 7.1

CVE-2025-11142 is an OS command injection vulnerability in Axis camera VAPIX API's mediaclip.cgi endpoint that allows authenticated attackers with ope...

📅 34 days ago • Feb 10, 2026
CVE-2026-25640 7.1

A path traversal vulnerability in Pydantic AI's web UI allows attackers to serve malicious JavaScript by crafting URLs with unvalidated version parame...

📅 37 days ago • Feb 6, 2026
CVE-2026-2103 7.1

CVE-2026-2103 is a hard-coded cryptographic key vulnerability in Infor SyteLine ERP that allows attackers to decrypt stored credentials including pass...

📅 37 days ago • Feb 6, 2026
CVE-2026-25536 7.1

The CVE-2026-25536 vulnerability in the MCP TypeScript SDK allows cross-client response data leakage when a single server/transport instance is reused...

📅 39 days ago • Feb 4, 2026
CVE-2026-25503 7.1

A type confusion vulnerability in iccDEV allows malformed ICC color profiles to trigger undefined behavior when loading invalid icImageEncodingType va...

📅 40 days ago • Feb 3, 2026
CVE-2020-37112 7.1

CVE-2020-37112 is an SQL injection vulnerability in GUnet OpenEclass 1.7.3 that allows authenticated attackers to manipulate database queries through ...

📅 40 days ago • Feb 3, 2026
CVE-2026-1058 7.1

The Form Maker WordPress plugin has a stored XSS vulnerability in versions up to 1.15.35. Unauthenticated attackers can inject malicious JavaScript in...

📅 41 days ago • Feb 3, 2026
CVE-2025-47366 7.1

A cryptographic vulnerability in Qualcomm's Trusted Zone when triggered by the High-Level Operating System (HLOS) providing incorrect input. This allo...

📅 41 days ago • Feb 2, 2026
CVE-2025-15396 7.1

The Library Viewer WordPress plugin before version 3.2.0 contains a reflected cross-site scripting (XSS) vulnerability where unsanitized parameters ar...

📅 42 days ago • Feb 2, 2026
CVE-2020-37053 7.1

Navigate CMS 2.8.7 contains an authenticated SQL injection vulnerability in the 'sidx' parameter of comments functionality. Attackers with valid crede...

📅 44 days ago • Jan 30, 2026
CVE-2026-25126 7.1

PolarLearn's vote API route accepts arbitrary string values for the 'direction' parameter due to missing runtime validation. Attackers can send unexpe...

📅 45 days ago • Jan 29, 2026
CVE-2026-24902 7.1

This CVE describes a server-side request forgery (SSRF) vulnerability in TrustTunnel VPN software that allows attackers to bypass private network rest...

📅 45 days ago • Jan 29, 2026
CVE-2026-24835 7.1

A critical authentication bypass vulnerability in Podman Desktop allows any installed extension to completely circumvent permission checks and gain un...

📅 46 days ago • Jan 28, 2026
CVE-2025-68479 7.1

This CVE describes an authorization bypass vulnerability in Discourse discussion platform where subscription endpoints lack proper ownership verificat...

📅 46 days ago • Jan 28, 2026
CVE-2026-24779 7.1

A Server-Side Request Forgery (SSRF) vulnerability in vLLM's MediaConnector class allows attackers to bypass host restrictions and make the server sen...

📅 47 days ago • Jan 27, 2026
CVE-2026-0810 7.1

A vulnerability in gix-date's TimeBuf component allows generation of invalid non-UTF8 strings, violating internal safety guarantees and causing undefi...

📅 48 days ago • Jan 26, 2026
CVE-2025-14316 7.1

The AhaChat Messenger Marketing WordPress plugin through version 1.1 contains a reflected cross-site scripting (XSS) vulnerability. Attackers can inje...

📅 49 days ago • Jan 26, 2026
CVE-2026-24410 7.1

CVE-2026-24410 is a vulnerability in iccDEV's ICC color management profile libraries where improper input validation in CIccProfileXml::ParseBasic() l...

📅 51 days ago • Jan 24, 2026
CVE-2026-24411 7.1

CVE-2026-24411 is an undefined behavior vulnerability in iccDEV's CIccTagXmlSegmentedCurve::ToXml() function that allows attackers to perform denial o...

📅 51 days ago • Jan 24, 2026
CVE-2026-24409 7.1

This vulnerability in iccDEV allows attackers to exploit undefined behavior and null pointer dereferences when processing user-controlled ICC color pr...

📅 51 days ago • Jan 24, 2026
CVE-2026-24407 7.1

CVE-2026-24407 is an undefined behavior vulnerability in iccDEV's icSigCalcOp() function that allows attackers to manipulate ICC color profile data. S...

📅 51 days ago • Jan 24, 2026
CVE-2026-24403 7.1

An integer overflow vulnerability in iccDEV's CIccProfile::CheckHeader() function allows attackers to trigger memory corruption or denial of service b...

📅 51 days ago • Jan 24, 2026
CVE-2026-24404 7.1

A null pointer dereference vulnerability in iccDEV's CIccXmlArrayType() function allows attackers to cause denial of service, manipulate data, bypass ...

📅 51 days ago • Jan 24, 2026
CVE-2025-67230 7.1

This vulnerability in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to bypass validation and invoke external protocol handle...

📅 51 days ago • Jan 23, 2026
CVE-2026-22984 7.1

This CVE describes an out-of-bounds read vulnerability in the Linux kernel's libceph component within the handle_auth_done() function. Attackers could...

📅 51 days ago • Jan 23, 2026
CVE-2026-0771 7.1

This vulnerability allows remote attackers to execute arbitrary Python code on Langflow installations through Python function components. Attackers ca...

📅 52 days ago • Jan 23, 2026
CVE-2026-23976 7.1

This stored XSS vulnerability in the Modula Image Gallery WordPress plugin allows attackers to inject malicious scripts into web pages that persist in...

📅 52 days ago • Jan 22, 2026
CVE-2026-22355 7.1

This vulnerability in the Simple XML Sitemap WordPress plugin allows attackers to perform Cross-Site Request Forgery (CSRF) attacks that lead to Store...

📅 52 days ago • Jan 22, 2026
CVE-2026-0535 7.1

A stored cross-site scripting vulnerability in Autodesk Fusion allows attackers to inject malicious HTML into component descriptions. When users click...

📅 52 days ago • Jan 22, 2026
CVE-2026-0534 7.1

This stored cross-site scripting vulnerability in Autodesk Fusion allows attackers to inject malicious HTML into part attributes. When users click the...

📅 52 days ago • Jan 22, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free