Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 10 added to KEV in the last 7 days.
| CVE | CVSS | EPSS | KEV sources | Patch window | Vendor / product | Summary | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-60104 | 8.7 | — | — | — | bitwarden / server | Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belong | 59d ago |
| CVE-2026-43640 | 8.1 | — | — | — | bitwarden / server | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating | 117d ago |
| CVE-2026-43639 | 8 | — | — | — | bitwarden / server | Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service | 117d ago |
| CVE-2026-57520 | 7.1 | — | — | — | bitwarden / server | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom us | 72d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE); CISA KEV, ENISA EUVD, CIRCL and VulnCheck (exploitation status, three catalogues counted; CIRCL shown as an aggregator); FIRST EPSS (exploitation probability). Patch window is the gap between CVE publication and the earliest KEV listing, so a negative value means a catalogue called it exploited before it was disclosed. Data refreshes every five hours.