🔥 Trending CVEs - Last 90 Days

4,667 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.

Last 7 Days Last 30 Days Last 90 Days
12,059
Total CVEs Published
1,037
Critical Severity
3,630
High Severity
⚠️
Critical Alert
1,037 critical vulnerabilities published in the last 90 days. Immediate action recommended.
Get Alerts

Critical & High-Risk CVEs

CVE-2026-0848 10.0

CVE-2026-0848 allows arbitrary code execution in NLTK versions <=3.9.2 due to improper input validation in the StanfordSegmenter module. Attackers can...

⚡ Yesterday • Mar 5, 2026
CVE-2026-29000 10.0

This critical authentication bypass vulnerability in pac4j-jwt allows attackers with the server's RSA public key to forge JWT authentication tokens an...

📅 2 days ago • Mar 4, 2026
CVE-2026-20131 10.0

This critical vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to execute arbitrary Java code with roo...

📅 2 days ago • Mar 4, 2026
CVE-2026-20079 10.0

An authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary s...

📅 2 days ago • Mar 4, 2026
CVE-2026-28289 10.0

This CVE describes a patch bypass vulnerability in FreeScout help desk software that allows authenticated users with file upload permissions to achiev...

📅 3 days ago • Mar 3, 2026
CVE-2026-24898 10.0

OpenEMR versions before 8.0.0 contain an unauthenticated token disclosure vulnerability in the MedEx callback endpoint. Any unauthenticated visitor ca...

📅 3 days ago • Mar 3, 2026
CVE-2026-20127 10.0

This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to gain admi...

📅 9 days ago • Feb 25, 2026
CVE-2026-27597 10.0

CVE-2026-27597 is a critical sandbox escape vulnerability in Enclave, a secure JavaScript sandbox for AI agent code execution. Attackers can bypass se...

📅 10 days ago • Feb 25, 2026
CVE-2026-2776 10.0

This CVE describes a sandbox escape vulnerability in Firefox's Telemetry component due to incorrect boundary conditions. Attackers could potentially b...

📅 10 days ago • Feb 24, 2026
CVE-2026-2778 10.0

This CVE describes a sandbox escape vulnerability in Firefox's DOM Core & HTML component due to incorrect boundary conditions. It allows malicious web...

📅 10 days ago • Feb 24, 2026
CVE-2026-2768 10.0

This CVE describes a sandbox escape vulnerability in Firefox's IndexedDB storage component. Attackers could potentially break out of browser security ...

📅 10 days ago • Feb 24, 2026
CVE-2026-2760 10.0

This CVE describes a sandbox escape vulnerability in Firefox's WebRender graphics component due to incorrect boundary conditions. It allows attackers ...

📅 10 days ago • Feb 24, 2026
CVE-2026-23693 10.0

The ElementsKit Lite WordPress plugin versions before 3.7.9 expose an unauthenticated REST endpoint that accepts Mailchimp API credentials. Unauthenti...

📅 11 days ago • Feb 23, 2026
CVE-2026-27211 10.0

Cloud Hypervisor versions 34.0 through 50.0 are vulnerable to host file exfiltration when using virtio-block devices with raw images. A malicious gues...

📅 13 days ago • Feb 21, 2026
CVE-2021-35402 10.0

This vulnerability allows remote attackers to execute arbitrary operating system commands on PROLiNK PRC2402M routers by injecting shell metacharacter...

📅 14 days ago • Feb 20, 2026
CVE-2025-30412 10.0

CVE-2025-30412 allows attackers to bypass authentication mechanisms in Acronis Cyber Protect, potentially leading to unauthorized access, sensitive da...

📅 15 days ago • Feb 20, 2026
CVE-2025-14009 10.0

This critical vulnerability in NLTK's downloader component allows remote code execution when users download malicious zip packages. Attackers can craf...

📅 16 days ago • Feb 18, 2026
CVE-2026-22769 10.0

Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 HF1 contain hardcoded credentials that allow unauthenticated remote attackers to gain r...

📅 17 days ago • Feb 17, 2026
CVE-2025-69770 10.0

This zip slip vulnerability in MojoPortal CMS allows attackers to upload malicious zip files that extract to arbitrary locations on the server, potent...

📅 21 days ago • Feb 13, 2026
CVE-2026-26216 10.0

Crawl4AI versions before 0.8.0 contain an unauthenticated remote code execution vulnerability in the Docker API deployment. Attackers can send malicio...

📅 22 days ago • Feb 12, 2026
CVE-2025-64075 10.0

A path traversal vulnerability in the ZBT WE2001 router's check_token function allows remote attackers to bypass authentication by manipulating sessio...

📅 23 days ago • Feb 11, 2026
CVE-2026-25632 10.0

CVE-2026-25632 is a critical remote code execution vulnerability in EPyT-Flow's REST API. Attackers can send malicious JSON payloads that trigger dyna...

📅 28 days ago • Feb 6, 2026
CVE-2026-25641 10.0

CVE-2026-25641 is a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandbox restrictions by ...

📅 28 days ago • Feb 6, 2026
CVE-2026-25520 10.0

SandboxJS versions before 0.8.29 have a critical sandbox escape vulnerability that allows attackers to obtain the host's Function constructor and exec...

📅 28 days ago • Feb 6, 2026
CVE-2026-25586 10.0

This CVE describes a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandboxing by shadowing...

📅 28 days ago • Feb 6, 2026
CVE-2026-25587 10.0

CVE-2026-25587 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can overwrite Map.prototype.has to br...

📅 28 days ago • Feb 6, 2026
CVE-2026-25725 10.0

This vulnerability allows malicious code running inside Claude Code's sandbox to create a missing settings.json file and inject persistent hooks that ...

📅 28 days ago • Feb 6, 2026
CVE-2025-68121 10.0

This vulnerability in Go's crypto/tls package allows TLS session resumption to succeed when it should fail due to certificate authority configuration ...

📅 29 days ago • Feb 5, 2026
CVE-2025-59818 10.0

This vulnerability allows authenticated attackers to execute arbitrary system commands by manipulating uploaded file names. It affects Zenitel communi...

📅 30 days ago • Feb 4, 2026
CVE-2026-1633 10.0

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter's web management interface lacks authentication, allowing any unauthenticated user to acce...

📅 31 days ago • Feb 4, 2026
CVE-2025-10878 10.0

An unauthenticated SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 allows attackers to bypass authentication completely. Successful expl...

📅 31 days ago • Feb 3, 2026
CVE-2025-70841 10.0

CVE-2025-70841 allows unauthenticated attackers to access the .env configuration file in Dokans Multi-Tenancy eCommerce Platform, exposing sensitive c...

📅 31 days ago • Feb 3, 2026
CVE-2026-25142 10.0

CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...

📅 32 days ago • Feb 2, 2026
CVE-2026-1699 10.0

This CVE describes a critical GitHub Actions vulnerability in Eclipse Theia's website repository where the pull_request_target trigger allowed untrust...

📅 35 days ago • Jan 30, 2026
CVE-2026-24054 10.0

A vulnerability in Kata Containers allows malformed container images with no layers to cause the host's block device to be mounted as read-only, poten...

📅 36 days ago • Jan 29, 2026
CVE-2026-24897 10.0

CVE-2026-24897 is a critical path traversal vulnerability in Erugo file-sharing platform that allows authenticated low-privileged users to upload arbi...

📅 37 days ago • Jan 28, 2026
CVE-2025-57792 10.0

CVE-2025-57792 is a critical SQL injection vulnerability in Explorance Blue software that allows unauthenticated attackers to execute arbitrary SQL co...

📅 37 days ago • Jan 28, 2026
CVE-2026-23830 10.0

SandboxJS versions before 0.8.26 have a critical sandbox escape vulnerability that allows attackers to execute arbitrary code outside the sandbox cont...

📅 38 days ago • Jan 28, 2026
CVE-2025-4320 10.0

This vulnerability allows attackers to bypass authentication and exploit weak password recovery mechanisms in Birebirsoft Sufirmam software. Attackers...

📅 42 days ago • Jan 23, 2026
CVE-2025-69828 10.0

A critical file upload vulnerability in TMS Global Software TMS Management Console allows remote attackers to upload malicious files through the Logo ...

📅 43 days ago • Jan 22, 2026
CVE-2026-21636 10.0

A critical vulnerability in Node.js v25's experimental permission model allows attacker-controlled inputs to bypass network restrictions and connect t...

📅 45 days ago • Jan 20, 2026
CVE-2026-23800 10.0

This vulnerability allows attackers to escalate privileges in Modular DS modular-connector WordPress plugin. Attackers can gain higher-level permissio...

📅 49 days ago • Jan 16, 2026
CVE-2026-23550 10.0

This critical vulnerability in Modular DS allows attackers to escalate privileges due to incorrect privilege assignment. It affects all versions up to...

📅 51 days ago • Jan 14, 2026
CVE-2026-22686 10.0

CVE-2026-22686 is a critical sandbox escape vulnerability in enclave-vm that allows untrusted JavaScript code to execute arbitrary code in the host No...

📅 52 days ago • Jan 14, 2026
CVE-2025-68271 10.0

OpenC3 COSMOS versions 5.0.0 through 6.10.1 contain a critical remote code execution vulnerability in the JSON-RPC API. Unauthenticated attackers can ...

📅 52 days ago • Jan 13, 2026
CVE-2026-0881 10.0

This CVE describes a sandbox escape vulnerability in the Messaging System component of Firefox and Thunderbird. Attackers can potentially execute arbi...

📅 52 days ago • Jan 13, 2026
CVE-2025-40805 10.0

This critical vulnerability allows unauthenticated remote attackers to bypass authentication on specific API endpoints and impersonate legitimate user...

📅 52 days ago • Jan 13, 2026
CVE-2025-63314 10.0

CVE-2025-63314 is a critical authentication bypass vulnerability in DDSN Interactive Acora CMS v10.7.1 where static password reset tokens allow attack...

📅 53 days ago • Jan 12, 2026
CVE-2025-52694 10.0

This critical SQL injection vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on internet-exposed services. Successful ...

📅 54 days ago • Jan 12, 2026
CVE-2025-64090 10.0

This vulnerability allows authenticated attackers to execute arbitrary commands on affected devices by manipulating the hostname parameter. It affects...

📅 56 days ago • Jan 9, 2026

Why Track Trending CVEs?

Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.

Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.

🚀 Automated Trending CVE Monitoring

  • Scan your servers to detect packages affected by trending CVEs
  • Receive instant email alerts when critical vulnerabilities are discovered
  • Dashboard shows CVE age, severity, CVSS scores, and affected systems
  • Filter by time period (7/30/90 days) to focus on recent threats
Start Monitoring Trending CVEs Free