Vuln Signal Radar
CRIT 3
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is haxx curl, with 9 CVEs, 0 KEV-listed records, EPSS percentile 65, and remediation references present. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 65. 0 critical clusters have unknown remediation references. The largest displayed cluster is haxx curl, with 9 CVEs.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2020 new in 7d
Critical3canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors2from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-09-13 18:14 UTC / 2026-09-14 03:14 JST

Live Vulnerability Feed READ-ONLY

2026-09-13
defensive priority signal
CRITICALEPSS 0.0116 (65)NEWhaxx / curlNVD: A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initia… Handoff
2026-09-13
defensive priority signal
CRITICALEPSS 0.0049 (40)NEW-NVD: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server… Handoff
2026-09-13
defensive priority signal
CRITICALEPSS 0.0090 (58)NEWhaxx / curlNVD: A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0054 (44)NEWhaxx / curlNVD: When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a Set-Cookie header whe… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0094 (59)NEWhaxx / curlNVD: A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup for a given hostname even when using a different Native CA… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0090 (58)NEWhaxx / curlNVD: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. NVD: In Op… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0068 (51)NEWhaxx / curlNVD: A Set-Cookie: header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the Secure attribute… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0057 (45)NEWhaxx / curlNVD: When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and C… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0043 (36)NEWhaxx / curlNVD: With the wolfSSL backend, when CA caching is enabled and an CURLOPT_SSL_CTX_FUNCTION callback replaces the trust store, libcurl can si… Handoff
2026-09-13
defensive priority signal
HIGHEPSS 0.0064 (49)NEWhaxx / curlNVD: A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a succe… Handoff
2026-09-13
defensive priority signal
MEDIUMEPSS 0.0027 (19)NEW-NVD: A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. NVD: This impacts the function mysqli_query of the… Handoff
2026-09-13
defensive priority signal
MEDIUMEPSS 0.0027 (19)NEW-NVD: A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected is the function mysqli_query of… Handoff
2026-09-13
defensive priority signal
MEDIUMEPSS 0.0027 (19)NEW-NVD: A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. NVD: This affects the function mysqli_query of… Handoff
2026-09-13
defensive priority signal
MEDIUMEPSS 0.0026 (18)NEW-NVD: A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. NVD: The affected element is the function mysqli… Handoff
2026-09-13
defensive priority signal
MEDIUMEPSS 0.0026 (18)NEW-NVD: A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. NVD: The impacted element is the function mysqli_query… Handoff
2026-09-13
defensive priority signal
MEDIUMEPSS 0.0026 (18)NEW-NVD: A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. NVD: Affected by this vulnerability is the fun… Handoff
2026-09-13
defensive priority signal
LOWEPSS 0.0027 (20)NEW-NVD: A security flaw has been discovered in mwiede jsch up to 2.28.5. NVD: Affected is the function getRevokedKeys of the file src/main/jav… Handoff
2026-09-13
defensive priority signal
LOWEPSS 0.0023 (13)NEW-NVD: A security vulnerability has been detected in JeecgBoot up to 3.9.3. NVD: This vulnerability affects the function exportXls of the fil… Handoff
2026-09-13
defensive priority signal
LOWEPSS 0.0019 (9)NEW-NVD: A security flaw has been discovered in Projectwolds Online Attendance System 1.0. NVD: Affected by this issue is some unknown function… Handoff
2026-09-13
defensive priority signal
LOWEPSS 0.0032 (25)NEW-NVD: A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. NVD: This affects the function kvstoreGetHashtable of the file s… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-09-13 18:14 UTC / 2026-09-14 03:14 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

29 public-safe changes since the previous successful snapshot.

Added9
Changed11
Removed9
What changed
  • CVE-2026-13608: priority score and EPSS percentile changed.
  • CVE-2026-18924: priority score and EPSS percentile changed.
  • CVE-2026-19931: priority score and EPSS percentile changed.
  • 26 more public-safe changes in the JSON feed.
Previous snapshot2026-09-13 13:51 UTC / 2026-09-13 22:51 JST
Items compared20 -> 20
Feed generated2026-09-13 18:14 UTC / 2026-09-14 03:14 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV13
Affected products9partial
CPE9partial
PURL0partial
Canonical vendor/product9partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-09-1320

Severity Distribution

  • CRITICAL 3
  • HIGH 7
  • MEDIUM 6
  • LOW 4
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
Vendor Advisory20
OSV13

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-19931
Critical / High3 / 7
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 3,
    "HIGH": 7,
    "LOW": 4,
    "MEDIUM": 6,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-19931"
}

Source Status

NVD20 signalsLast observed: 2026-09-13Status: healthy
EPSS20 signalsLast observed: 2026-09-13Status: healthy
OSV13 signalsLast observed: 2026-09-13Status: healthy
Vendor Advisory20 signalsLast observed: 2026-09-13Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled