Every published CVE from the last 120 days with CVSS score, vendor and product, cross-referenced against CISA's Known Exploited Vulnerabilities catalog. 5 added to KEV in the last 7 days.
| CVE | CVSS | EPSS | KEV sources | Patch window | Vendor / product | Summary | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-82261 | 7.5 | — | — | — | svelte / sveltekit | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled conta | 43d ago |
| CVE-2026-82260 | 7.5 | — | — | — | svelte / sveltekit | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFu | 43d ago |
| CVE-2026-82259 | 7.5 | — | — | — | svelte / sveltekit | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the e | 43d ago |
| CVE-2026-42570 | 7.5 | — | — | — | svelte / devalue | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient fo | 123d ago |
| CVE-2026-42567 | 7.5 | — | — | — | svelte / svelte | Svelte is a performance oriented web framework. | 123d ago |
| CVE-2026-30226 | 7.5 | — | — | — | svelte / devalue | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient fo | 213d ago |
Sources: NIST National Vulnerability Database (descriptions, CVSS, CPE); CISA KEV, ENISA EUVD, CIRCL and VulnCheck (exploitation status, three catalogues counted; CIRCL shown as an aggregator); FIRST EPSS (exploitation probability). Patch window is the gap between CVE publication and the earliest KEV listing, so a negative value means a catalogue called it exploited before it was disclosed. Data refreshes every five hours.