🔥 Trending CVEs - Last 90 Days
4,667 critical and high-severity vulnerabilities discovered in the last 90 days. Stay ahead of emerging threats with real-time CVE tracking and instant security alerts.
Critical & High-Risk CVEs
CVE-2026-0848 allows arbitrary code execution in NLTK versions <=3.9.2 due to improper input validation in the StanfordSegmenter module. Attackers can...
⚡ Yesterday • Mar 5, 2026This critical authentication bypass vulnerability in pac4j-jwt allows attackers with the server's RSA public key to forge JWT authentication tokens an...
📅 2 days ago • Mar 4, 2026This critical vulnerability in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to execute arbitrary Java code with roo...
📅 2 days ago • Mar 4, 2026An authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) allows unauthenticated remote attackers to execute arbitrary s...
📅 2 days ago • Mar 4, 2026This CVE describes a patch bypass vulnerability in FreeScout help desk software that allows authenticated users with file upload permissions to achiev...
📅 3 days ago • Mar 3, 2026OpenEMR versions before 8.0.0 contain an unauthenticated token disclosure vulnerability in the MedEx callback endpoint. Any unauthenticated visitor ca...
📅 3 days ago • Mar 3, 2026This critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller and Manager allows unauthenticated remote attackers to gain admi...
📅 9 days ago • Feb 25, 2026CVE-2026-27597 is a critical sandbox escape vulnerability in Enclave, a secure JavaScript sandbox for AI agent code execution. Attackers can bypass se...
📅 10 days ago • Feb 25, 2026This CVE describes a sandbox escape vulnerability in Firefox's Telemetry component due to incorrect boundary conditions. Attackers could potentially b...
📅 10 days ago • Feb 24, 2026This CVE describes a sandbox escape vulnerability in Firefox's DOM Core & HTML component due to incorrect boundary conditions. It allows malicious web...
📅 10 days ago • Feb 24, 2026This CVE describes a sandbox escape vulnerability in Firefox's IndexedDB storage component. Attackers could potentially break out of browser security ...
📅 10 days ago • Feb 24, 2026This CVE describes a sandbox escape vulnerability in Firefox's WebRender graphics component due to incorrect boundary conditions. It allows attackers ...
📅 10 days ago • Feb 24, 2026The ElementsKit Lite WordPress plugin versions before 3.7.9 expose an unauthenticated REST endpoint that accepts Mailchimp API credentials. Unauthenti...
📅 11 days ago • Feb 23, 2026Cloud Hypervisor versions 34.0 through 50.0 are vulnerable to host file exfiltration when using virtio-block devices with raw images. A malicious gues...
📅 13 days ago • Feb 21, 2026This vulnerability allows remote attackers to execute arbitrary operating system commands on PROLiNK PRC2402M routers by injecting shell metacharacter...
📅 14 days ago • Feb 20, 2026CVE-2025-30412 allows attackers to bypass authentication mechanisms in Acronis Cyber Protect, potentially leading to unauthorized access, sensitive da...
📅 15 days ago • Feb 20, 2026This critical vulnerability in NLTK's downloader component allows remote code execution when users download malicious zip packages. Attackers can craf...
📅 16 days ago • Feb 18, 2026Dell RecoverPoint for Virtual Machines versions before 6.0.3.1 HF1 contain hardcoded credentials that allow unauthenticated remote attackers to gain r...
📅 17 days ago • Feb 17, 2026This zip slip vulnerability in MojoPortal CMS allows attackers to upload malicious zip files that extract to arbitrary locations on the server, potent...
📅 21 days ago • Feb 13, 2026Crawl4AI versions before 0.8.0 contain an unauthenticated remote code execution vulnerability in the Docker API deployment. Attackers can send malicio...
📅 22 days ago • Feb 12, 2026A path traversal vulnerability in the ZBT WE2001 router's check_token function allows remote attackers to bypass authentication by manipulating sessio...
📅 23 days ago • Feb 11, 2026CVE-2026-25632 is a critical remote code execution vulnerability in EPyT-Flow's REST API. Attackers can send malicious JSON payloads that trigger dyna...
📅 28 days ago • Feb 6, 2026CVE-2026-25641 is a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandbox restrictions by ...
📅 28 days ago • Feb 6, 2026SandboxJS versions before 0.8.29 have a critical sandbox escape vulnerability that allows attackers to obtain the host's Function constructor and exec...
📅 28 days ago • Feb 6, 2026This CVE describes a sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can bypass JavaScript sandboxing by shadowing...
📅 28 days ago • Feb 6, 2026CVE-2026-25587 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.29. Attackers can overwrite Map.prototype.has to br...
📅 28 days ago • Feb 6, 2026This vulnerability allows malicious code running inside Claude Code's sandbox to create a missing settings.json file and inject persistent hooks that ...
📅 28 days ago • Feb 6, 2026This vulnerability in Go's crypto/tls package allows TLS session resumption to succeed when it should fail due to certificate authority configuration ...
📅 29 days ago • Feb 5, 2026This vulnerability allows authenticated attackers to execute arbitrary system commands by manipulating uploaded file names. It affects Zenitel communi...
📅 30 days ago • Feb 4, 2026The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter's web management interface lacks authentication, allowing any unauthenticated user to acce...
📅 31 days ago • Feb 4, 2026An unauthenticated SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 allows attackers to bypass authentication completely. Successful expl...
📅 31 days ago • Feb 3, 2026CVE-2025-70841 allows unauthenticated attackers to access the .env configuration file in Dokans Multi-Tenancy eCommerce Platform, exposing sensitive c...
📅 31 days ago • Feb 3, 2026CVE-2026-25142 is a critical sandbox escape vulnerability in SandboxJS library versions before 0.8.27. Attackers can use the __lookupGetter__ method t...
📅 32 days ago • Feb 2, 2026This CVE describes a critical GitHub Actions vulnerability in Eclipse Theia's website repository where the pull_request_target trigger allowed untrust...
📅 35 days ago • Jan 30, 2026A vulnerability in Kata Containers allows malformed container images with no layers to cause the host's block device to be mounted as read-only, poten...
📅 36 days ago • Jan 29, 2026CVE-2026-24897 is a critical path traversal vulnerability in Erugo file-sharing platform that allows authenticated low-privileged users to upload arbi...
📅 37 days ago • Jan 28, 2026CVE-2025-57792 is a critical SQL injection vulnerability in Explorance Blue software that allows unauthenticated attackers to execute arbitrary SQL co...
📅 37 days ago • Jan 28, 2026SandboxJS versions before 0.8.26 have a critical sandbox escape vulnerability that allows attackers to execute arbitrary code outside the sandbox cont...
📅 38 days ago • Jan 28, 2026This vulnerability allows attackers to bypass authentication and exploit weak password recovery mechanisms in Birebirsoft Sufirmam software. Attackers...
📅 42 days ago • Jan 23, 2026A critical file upload vulnerability in TMS Global Software TMS Management Console allows remote attackers to upload malicious files through the Logo ...
📅 43 days ago • Jan 22, 2026A critical vulnerability in Node.js v25's experimental permission model allows attacker-controlled inputs to bypass network restrictions and connect t...
📅 45 days ago • Jan 20, 2026This vulnerability allows attackers to escalate privileges in Modular DS modular-connector WordPress plugin. Attackers can gain higher-level permissio...
📅 49 days ago • Jan 16, 2026This critical vulnerability in Modular DS allows attackers to escalate privileges due to incorrect privilege assignment. It affects all versions up to...
📅 51 days ago • Jan 14, 2026CVE-2026-22686 is a critical sandbox escape vulnerability in enclave-vm that allows untrusted JavaScript code to execute arbitrary code in the host No...
📅 52 days ago • Jan 14, 2026OpenC3 COSMOS versions 5.0.0 through 6.10.1 contain a critical remote code execution vulnerability in the JSON-RPC API. Unauthenticated attackers can ...
📅 52 days ago • Jan 13, 2026This CVE describes a sandbox escape vulnerability in the Messaging System component of Firefox and Thunderbird. Attackers can potentially execute arbi...
📅 52 days ago • Jan 13, 2026This critical vulnerability allows unauthenticated remote attackers to bypass authentication on specific API endpoints and impersonate legitimate user...
📅 52 days ago • Jan 13, 2026CVE-2025-63314 is a critical authentication bypass vulnerability in DDSN Interactive Acora CMS v10.7.1 where static password reset tokens allow attack...
📅 53 days ago • Jan 12, 2026This critical SQL injection vulnerability allows unauthenticated attackers to execute arbitrary SQL commands on internet-exposed services. Successful ...
📅 54 days ago • Jan 12, 2026This vulnerability allows authenticated attackers to execute arbitrary commands on affected devices by manipulating the hostname parameter. It affects...
📅 56 days ago • Jan 9, 2026Why Track Trending CVEs?
Stay ahead of emerging threats: Newly discovered vulnerabilities pose the highest risk as attackers race to exploit them before patches are deployed. Trending CVEs represent the most critical security issues requiring immediate attention from security teams worldwide.
Prioritize remediation efforts: With thousands of CVEs published annually, security teams need to focus on the most recent and severe threats first. Our trending CVE dashboard highlights critical and high-severity vulnerabilities from the past 7, 30, or 90 days, helping you prioritize patching efforts.
🚀 Automated Trending CVE Monitoring
- Scan your servers to detect packages affected by trending CVEs
- Receive instant email alerts when critical vulnerabilities are discovered
- Dashboard shows CVE age, severity, CVSS scores, and affected systems
- Filter by time period (7/30/90 days) to focus on recent threats