🔥 Trending CVEs - Last 90 Days

4,370 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
10,770
Total CVEs Published
971
Critical Severity
3,399
High Severity
⚠️
Critical Alert
971 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2025-15069 7.1

An improper authentication vulnerability in Gmission Web Fax allows attackers to bypass authentication mechanisms and escalate privileges. This affect...

📅 77 days ago • Dec 29, 2025
CVE-2025-68697 7.1

In self-hosted n8n instances prior to version 2.0.0, authenticated users with workflow editing access can exploit the Code node's legacy JavaScript ex...

📅 79 days ago • Dec 26, 2025
CVE-2025-66445 7.1

An authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer allows attackers to access restricte...

📅 82 days ago • Dec 24, 2025
CVE-2025-66736 7.1

CVE-2025-66736 is an authorization bypass vulnerability in youlai-boot V2.21.1 where the importUsers function lacks proper permission checks. This all...

📅 83 days ago • Dec 22, 2025
CVE-2025-1927 7.1

This CSRF vulnerability in Restajet Online Food Delivery System allows attackers to trick authenticated users into performing unintended actions on th...

📅 87 days ago • Dec 19, 2025
CVE-2025-62000 7.1

BullWall Ransomware Containment has a vulnerability where an authenticated attacker can encrypt files while preserving the first four bytes, bypassing...

📅 87 days ago • Dec 18, 2025
CVE-2025-67745 7.1

MyHoard versions 1.0.1 through 1.2.x log backup information including encryption keys in certain cases, potentially exposing sensitive database backup...

📅 87 days ago • Dec 18, 2025
CVE-2025-66118 7.1

This reflected cross-site scripting (XSS) vulnerability in the BoldGrid Sprout Clients WordPress plugin allows attackers to inject malicious scripts i...

📅 88 days ago • Dec 18, 2025
CVE-2025-66119 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Bob Hostel WordPress plugin. When users visit a specia...

📅 88 days ago • Dec 18, 2025
CVE-2025-6324 7.1

This DOM-based Cross-Site Scripting (XSS) vulnerability in the Easy Invoice WordPress plugin allows attackers to inject malicious scripts into web pag...

📅 88 days ago • Dec 18, 2025
CVE-2025-66102 7.1

This Cross-Site Scripting (XSS) vulnerability in the FolioVision FV Antispam WordPress plugin allows attackers to inject malicious scripts into web pa...

📅 88 days ago • Dec 18, 2025
CVE-2025-64372 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Traveler WordPress theme that allows attackers to inject malicious scripts into we...

📅 88 days ago • Dec 18, 2025
CVE-2025-64376 7.1

This Cross-Site Scripting (XSS) vulnerability in the ListingPro WordPress theme allows attackers to inject malicious scripts into web pages viewed by ...

📅 88 days ago • Dec 18, 2025
CVE-2025-64260 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the ANAC XML Bandi di Gara WordPress plugin. When users vi...

📅 88 days ago • Dec 18, 2025
CVE-2025-64207 7.1

This DOM-based cross-site scripting (XSS) vulnerability in the Jannah WordPress theme allows attackers to inject malicious scripts into web pages view...

📅 88 days ago • Dec 18, 2025
CVE-2025-64217 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the Photography WordPress theme. When users visit a specia...

📅 88 days ago • Dec 18, 2025
CVE-2025-64221 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the dt-reservation-plugin WordPress plugin. When users vis...

📅 88 days ago • Dec 18, 2025
CVE-2025-64189 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the XStore Core WordPress plugin. Attackers can inject malicious scripts via crafted U...

📅 88 days ago • Dec 18, 2025
CVE-2025-64191 7.1

This vulnerability allows attackers to inject malicious scripts into web pages generated by the XStore WordPress theme, which are then executed in vic...

📅 88 days ago • Dec 18, 2025
CVE-2025-64203 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Mailster WordPress plugin that allows attackers to inject malicious scripts into w...

📅 88 days ago • Dec 18, 2025
CVE-2025-60182 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Schiocco Support Board WordPress plugin. Attackers can inject malicious scripts in...

📅 88 days ago • Dec 18, 2025
CVE-2025-60079 7.1

This CVE describes a Missing Authorization vulnerability in the bPlugins Parallax Section WordPress block plugin that allows attackers to access funct...

📅 88 days ago • Dec 18, 2025
CVE-2025-54751 7.1

This CVE describes a Missing Authorization vulnerability in the WPXPO PostX (ultimate-post) WordPress plugin that allows attackers to bypass access co...

📅 88 days ago • Dec 18, 2025
CVE-2025-57897 7.1

This is a reflected cross-site scripting (XSS) vulnerability in the Logtik WordPress theme that allows attackers to inject malicious scripts into web ...

📅 88 days ago • Dec 18, 2025
CVE-2025-65203 7.1

KeePassXC-Browser versions through 1.9.9.2 automatically fill or prompt to fill stored credentials into documents rendered under browser-enforced CSP ...

📅 88 days ago • Dec 17, 2025
CVE-2025-14101 7.1

This vulnerability allows attackers to bypass authorization controls in PaperWork by manipulating user-controlled keys or identifiers. It affects all ...

📅 89 days ago • Dec 17, 2025
CVE-2025-14701 7.1

A stored cross-site scripting (XSS) vulnerability in Crafty Controller's Server MOTD component allows remote unauthenticated attackers to inject malic...

📅 89 days ago • Dec 17, 2025
CVE-2026-25178 7.0

This vulnerability is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to escalate pri...

📅 5 days ago • Mar 10, 2026
CVE-2026-25170 7.0

This CVE describes a use-after-free vulnerability in Windows Hyper-V that allows an authenticated attacker to escalate privileges on the local system....

📅 5 days ago • Mar 10, 2026
CVE-2026-24295 7.0

A race condition vulnerability in Windows Device Association Service allows authenticated attackers to escalate privileges locally. This affects Windo...

📅 5 days ago • Mar 10, 2026
CVE-2026-24285 7.0

CVE-2026-24285 is a use-after-free vulnerability in Windows Win32K that allows an authenticated attacker to escalate privileges on a local system. Thi...

📅 5 days ago • Mar 10, 2026
CVE-2026-23668 7.0

A race condition vulnerability in Microsoft Graphics Component allows authenticated attackers to escalate privileges on local systems. This affects Wi...

📅 5 days ago • Mar 10, 2026
CVE-2026-23671 7.0

A race condition vulnerability in Windows Bluetooth RFCOM Protocol Driver allows an authenticated attacker to execute code with elevated privileges on...

📅 5 days ago • Mar 10, 2026
CVE-2026-3787 7.0

This vulnerability in UltraVNC 1.6.4.0 on Windows involves an uncontrolled search path weakness in cryptbase.dll that could allow local attackers to e...

📅 7 days ago • Mar 8, 2026
CVE-2026-2492 7.0

This vulnerability allows local attackers to escalate privileges on TensorFlow installations by exploiting an insecure plugin loading mechanism. Attac...

📅 23 days ago • Feb 20, 2026
CVE-2026-25087 7.0

A Use After Free vulnerability in Apache Arrow C++ allows memory corruption when reading Arrow IPC files with pre-buffering enabled. This affects C++ ...

📅 26 days ago • Feb 17, 2026
CVE-2026-2538 7.0

This CVE describes a DLL hijacking vulnerability in Flos Freeware Notepad2 versions 4.2.22 through 4.2.25. Attackers can exploit uncontrolled search p...

📅 28 days ago • Feb 16, 2026
CVE-2026-2516 7.0

This vulnerability in Unidocs ezPDF DRM Reader and ezPDF Reader allows local attackers to exploit an uncontrolled search path issue in SHFOLDER.dll, p...

📅 29 days ago • Feb 15, 2026
CVE-2026-20617 7.0

A race condition vulnerability in Apple operating systems allows malicious applications to potentially gain root privileges. This affects users runnin...

📅 32 days ago • Feb 11, 2026
CVE-2026-26157 7.0

A path traversal vulnerability in BusyBox's archive extraction utilities allows attackers to create malicious archives that, when extracted under spec...

📅 32 days ago • Feb 11, 2026
CVE-2026-21508 7.0

CVE-2026-21508 is an improper authentication vulnerability in Windows Storage that allows authenticated attackers to elevate privileges locally. This ...

📅 33 days ago • Feb 10, 2026
CVE-2026-21253 7.0

This vulnerability involves a use-after-free flaw in the Windows Mailslot File System that allows an authenticated attacker to execute arbitrary code ...

📅 33 days ago • Feb 10, 2026
CVE-2026-21241 7.0

This vulnerability is a use-after-free flaw in Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to execute arbitrar...

📅 33 days ago • Feb 10, 2026
CVE-2026-21237 7.0

A race condition vulnerability in Windows Subsystem for Linux allows authenticated local attackers to escalate privileges by exploiting improper synch...

📅 33 days ago • Feb 10, 2026
CVE-2025-15569 7.0

This vulnerability in Artifex MuPDF on Windows allows local attackers to exploit an uncontrolled search path issue in the get_system_dpi function. Att...

📅 34 days ago • Feb 10, 2026
CVE-2026-24051 7.0

OpenTelemetry-Go SDK versions v1.20.0 through v1.39.0 on macOS/Darwin systems are vulnerable to path hijacking attacks. An attacker with local access ...

📅 41 days ago • Feb 2, 2026
CVE-2025-10279 7.0

This CVE describes a local privilege escalation vulnerability in mlflow versions before 3.4.0 where temporary directories for Python virtual environme...

📅 42 days ago • Feb 2, 2026
CVE-2025-68119 7.0

This vulnerability allows attackers to execute arbitrary code or write arbitrary files when downloading and building Go modules with malicious version...

📅 46 days ago • Jan 28, 2026
CVE-2026-21417 7.0

Dell CloudBoost Virtual Appliance versions before 19.14.0.0 store passwords in plaintext, allowing attackers with remote access and high privileges to...

📅 48 days ago • Jan 27, 2026
CVE-2026-0775 7.0

This CVE describes a local privilege escalation vulnerability in npm CLI where incorrect permission assignment allows loading modules from unsecured l...

📅 52 days ago • Jan 23, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free