🔥 Trending CVEs - Last 90 Days

4,372 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
10,779
Total CVEs Published
971
Critical Severity
3,401
High Severity
⚠️
Critical Alert
971 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-68866 7.1

This stored XSS vulnerability in the Dinatur WordPress plugin allows attackers to inject malicious scripts into web pages that are then executed when ...

📅 52 days ago • Jan 22, 2026
CVE-2025-68871 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Dooodl WordPress plugin that allows attackers to inject malicious scripts into web...

📅 52 days ago • Jan 22, 2026
CVE-2025-68883 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the bidorbuy Store Integrator WordPress plugin. When users...

📅 52 days ago • Jan 22, 2026
CVE-2025-68884 7.1

This vulnerability allows attackers to inject malicious scripts into the WP Simple Redirect WordPress plugin, which are then reflected back to users' ...

📅 52 days ago • Jan 22, 2026
CVE-2025-68835 7.1

This CVE describes a reflected cross-site scripting (XSS) vulnerability in the Ravpage WordPress plugin. Attackers can inject malicious scripts via cr...

📅 52 days ago • Jan 22, 2026
CVE-2025-68838 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the MemberPress Discord Addon WordPress plugin. When users...

📅 52 days ago • Jan 22, 2026
CVE-2025-68839 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Easy Theme Options WordPress plugin. When users visit ...

📅 52 days ago • Jan 22, 2026
CVE-2025-68849 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Quote Master WordPress plugin. When users visit specia...

📅 52 days ago • Jan 22, 2026
CVE-2025-68858 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the wpCAS WordPress plugin, which are then executed in vic...

📅 52 days ago • Jan 22, 2026
CVE-2025-68859 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Syntax Highlighter Compress WordPress plugin. When use...

📅 52 days ago • Jan 22, 2026
CVE-2025-68518 7.1

This reflected cross-site scripting (XSS) vulnerability in the Hoteller WordPress theme allows attackers to inject malicious scripts into web pages by...

📅 52 days ago • Jan 22, 2026
CVE-2025-68520 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the DotLife WordPress theme that allows attackers to inject malicious scripts into web...

📅 52 days ago • Jan 22, 2026
CVE-2025-68538 7.1

This DOM-based XSS vulnerability in the Craft Coffee Shop WordPress theme allows attackers to inject malicious scripts into web pages viewed by users....

📅 52 days ago • Jan 22, 2026
CVE-2025-68041 7.1

This stored cross-site scripting (XSS) vulnerability in the Codisto Omnichannel for WooCommerce plugin allows attackers to inject malicious scripts in...

📅 52 days ago • Jan 22, 2026
CVE-2025-68008 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the WP Mail plugin, which are then executed in victims' br...

📅 52 days ago • Jan 22, 2026
CVE-2025-68010 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Netgsm WordPress plugin. When users visit specially cr...

📅 52 days ago • Jan 22, 2026
CVE-2025-68011 7.1

This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users through improper input sanitization in the GLS Sh...

📅 52 days ago • Jan 22, 2026
CVE-2025-68012 7.1

This stored cross-site scripting (XSS) vulnerability in the CodeColorer WordPress plugin allows attackers to inject malicious scripts into web pages t...

📅 52 days ago • Jan 22, 2026
CVE-2025-68004 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the My Post Order WordPress plugin. When users visit a spe...

📅 52 days ago • Jan 22, 2026
CVE-2025-67959 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the WorkScout WordPress theme. Attackers can inject malicious scripts via crafted URLs...

📅 52 days ago • Jan 22, 2026
CVE-2025-67960 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the WorkScout-Core WordPress plugin that allows attackers to inject malicious scripts ...

📅 52 days ago • Jan 22, 2026
CVE-2025-67964 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the favethemes Homey Core WordPress plugin. Attackers can inject malicious scripts via...

📅 52 days ago • Jan 22, 2026
CVE-2025-67947 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the AdForest Elementor WordPress plugin. When users visit ...

📅 52 days ago • Jan 22, 2026
CVE-2025-67949 7.1

This Cross-Site Scripting (XSS) vulnerability in the Hostiko WordPress theme allows attackers to inject malicious scripts into web pages viewed by oth...

📅 52 days ago • Jan 22, 2026
CVE-2025-67952 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Grand Tour WordPress theme. When users visit a special...

📅 52 days ago • Jan 22, 2026
CVE-2025-67943 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the My auctions allegro WordPress plugin. When users visit...

📅 52 days ago • Jan 22, 2026
CVE-2025-67620 7.1

This reflected cross-site scripting (XSS) vulnerability in the CleverSoft Anon WordPress theme allows attackers to inject malicious scripts into web p...

📅 52 days ago • Jan 22, 2026
CVE-2025-67923 7.1

This Cross-Site Scripting (XSS) vulnerability in the Crocoblock JetEngine WordPress plugin allows attackers to inject malicious scripts into web pages...

📅 52 days ago • Jan 22, 2026
CVE-2025-67614 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the TheNa WordPress theme that allows attackers to inject malicious scripts into web p...

📅 52 days ago • Jan 22, 2026
CVE-2026-24049 7.1

CVE-2026-24049 is a path traversal vulnerability in Python's wheel tool (versions 0.40.0-0.46.1) that allows attackers to modify file permissions of c...

📅 53 days ago • Jan 22, 2026
CVE-2026-24046 7.1

This CVE describes a symlink-based path traversal vulnerability in Backstage's Scaffolder component. Attackers with template creation/execution privil...

📅 53 days ago • Jan 21, 2026
CVE-2026-23986 7.1

CVE-2026-23986 is a path traversal vulnerability in Copier project template tool that allows malicious templates to write files outside the intended d...

📅 53 days ago • Jan 21, 2026
CVE-2021-47872 7.1

SEO Panel versions before 4.9.0 contain a blind SQL injection vulnerability in the archive.php page. Authenticated attackers can inject malicious SQL ...

📅 53 days ago • Jan 21, 2026
CVE-2026-22444 7.1

This vulnerability in Apache Solr allows attackers to bypass path restrictions and read unauthorized files from the filesystem when creating new cores...

📅 53 days ago • Jan 21, 2026
CVE-2026-21986 7.1

An unauthenticated local attacker can cause a denial-of-service (DoS) crash in Oracle VM VirtualBox on Windows hosts. This vulnerability affects Virtu...

📅 54 days ago • Jan 20, 2026
CVE-2026-21976 7.1

This vulnerability in Oracle Business Intelligence Enterprise Edition allows authenticated attackers with local access to the infrastructure to manipu...

📅 54 days ago • Jan 20, 2026
CVE-2025-55131 7.1

A Node.js vulnerability in the vm module's buffer allocation can expose uninitialized memory when timeouts interrupt allocations. This may leak sensit...

📅 54 days ago • Jan 20, 2026
CVE-2026-23843 7.1

This CVE describes an Insecure Direct Object Reference (IDOR) vulnerability in the teklifolustur_app PHP application. Authenticated users can manipula...

📅 55 days ago • Jan 19, 2026
CVE-2026-21223 7.1

This vulnerability allows a standard local user without administrative privileges to execute privileged update commands via Microsoft Edge's Elevation...

📅 58 days ago • Jan 16, 2026
CVE-2025-24528 7.1

This vulnerability in MIT Kerberos 5 allows authenticated attackers to trigger an integer overflow in the kadmind daemon's log handling code, leading ...

📅 58 days ago • Jan 16, 2026
CVE-2025-64769 7.1

The Process Optimization application suite uses unencrypted communication channels by default, allowing attackers to intercept, modify, or steal sensi...

📅 59 days ago • Jan 16, 2026
CVE-2026-21908 7.1

A use-after-free vulnerability in Juniper's 802.1X authentication daemon (dot1xd) allows authenticated, network-adjacent attackers to crash the daemon...

📅 59 days ago • Jan 15, 2026
CVE-2026-22249 7.1

Docmost versions 0.21.0 through 0.23.x contain a ZipSlip vulnerability in the zip import feature that allows attackers to write arbitrary files to any...

📅 59 days ago • Jan 15, 2026
CVE-2025-36911 7.1

This vulnerability in key-based pairing allows attackers within proximity to intercept and access users' conversations and location data without requi...

📅 59 days ago • Jan 15, 2026
CVE-2021-47766 7.1

Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php. This allows attackers with valid ...

📅 59 days ago • Jan 15, 2026
CVE-2025-14615 7.1

This CSRF vulnerability in the DASHBOARD BUILDER WordPress plugin allows unauthenticated attackers to trick administrators into modifying SQL queries ...

📅 61 days ago • Jan 14, 2026
CVE-2025-13772 7.1

This vulnerability allows authenticated GitLab users to access and use AI model settings from namespaces they shouldn't have access to by manipulating...

📅 66 days ago • Jan 9, 2026
CVE-2025-68889 7.1

This vulnerability allows attackers to inject malicious scripts into Pinpoll WordPress plugin pages, which execute in victims' browsers when they visi...

📅 67 days ago • Jan 8, 2026
CVE-2025-68891 7.1

This vulnerability allows attackers to inject malicious scripts into WordPress sites using the WP App Bar plugin. When users click specially crafted l...

📅 67 days ago • Jan 8, 2026
CVE-2025-68873 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the PRIMER by chloédigital WordPress plugin. When users v...

📅 67 days ago • Jan 8, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free