Vuln Signal Radar
CRIT 3
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-101065, with 1 CVE, 0 KEV-listed records, EPSS percentile 36, and remediation references present. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 48. 0 critical clusters have unknown remediation references. The largest displayed cluster is CVE-2026-101065, with 1 CVE.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2020 new in 7d
Critical3canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors1from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-10-04 18:41 UTC / 2026-10-05 03:41 JST

Live Vulnerability Feed READ-ONLY

2026-10-04
defensive priority signal
CRITICALEPSS 0.0044 (36)NEW-NVD: Obot is an open-source AI agent/MCP platform. NVD: In all versions up to and including commit d7e6970, the Docker quickstart command d… Handoff
2026-10-04
defensive priority signal
CRITICALEPSS 0.0036 (27)NEW-NVD: Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. NVD: When the new optional dashboard_host set… Handoff
2026-10-04
defensive priority signal
CRITICALEPSS 0.0028 (18)NEW-NVD: obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to con… Handoff
2026-10-04
defensive priority signal
HIGHEPSS 0.0034 (25)NEW-NVD: Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dynamic client re… Handoff
2026-10-04
defensive priority signal
HIGHEPSS 0.0024 (14)NEW-NVD: Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows privileged user… Handoff
2026-10-04
defensive priority signal
HIGHEPSS 0.0032 (23)NEW-NVD: Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing authenticated use… Handoff
2026-10-04
defensive priority signal
HIGHEPSS 0.0025 (15)NEW-NVD: Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users to create mal… Handoff
2026-10-04
defensive priority signal
MEDIUMEPSS 0.0024 (14)NEW-NVD: Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authentication is en… Handoff
2026-10-04
defensive priority signal
MEDIUMEPSS 0.0063 (48)NEW-NVD: A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates a Flatpak app… Handoff
2026-10-04
defensive priority signal
MEDIUMEPSS 0.0018 (7)NEW-NVD: Nezha is a server and website monitoring tool. NVD: In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/singleton/… Handoff
2026-10-04
defensive priority signal
MEDIUMEPSS 0.0025 (15)NEW-NVD: A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: This im… Handoff
2026-10-04
defensive priority signal
MEDIUMEPSS 0.0025 (15)NEW-NVD: A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: This affects an… Handoff
2026-10-04
defensive priority signal
MEDIUMEPSS 0.0026 (16)NEW-NVD: Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS webhook URLs, but… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0015 (4)NEW-NVD: Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the bcrypt-hashed… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0028 (18)NEW-NVD: A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: Affected is… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0026 (17)NEW-NVD: A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: Affecte… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0021 (10)NEW-NVD: A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. NVD: The impac… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0021 (10)NEW-NVD: A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. NVD: Affected by this issue is the function SysUser.isAdmin of… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0020 (9)NEW-NVD: A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. NVD: This affects the function checkRoleAllowed of the fil… Handoff
2026-10-04
defensive priority signal
LOWEPSS 0.0019 (8)NEW-NVD: A weakness has been identified in zhistaredu StarTraining up to 3.8.1. NVD: This vulnerability affects unknown code of the file du-com… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-10-04 18:41 UTC / 2026-10-05 03:41 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

40 public-safe changes since the previous successful snapshot.

Added20
Changed0
Removed20
What changed
  • CVE-2026-100873: newly added to the public-safe set.
  • CVE-2026-100874: newly added to the public-safe set.
  • CVE-2026-100875: newly added to the public-safe set.
  • 37 more public-safe changes in the JSON feed.
Previous snapshot2026-10-04 14:53 UTC / 2026-10-04 23:53 JST
Items compared20 -> 20
Feed generated2026-10-04 18:41 UTC / 2026-10-05 03:41 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV10
Affected products0partial
CPE0partial
PURL0partial
Canonical vendor/product0partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-10-0420

Severity Distribution

  • CRITICAL 3
  • HIGH 4
  • MEDIUM 6
  • LOW 7
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
Vendor Advisory20
OSV10

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-101065
Critical / High3 / 4
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 3,
    "HIGH": 4,
    "LOW": 7,
    "MEDIUM": 6,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-101065"
}

Source Status

NVD20 signalsLast observed: 2026-10-04Status: healthy
EPSS20 signalsLast observed: 2026-10-04Status: healthy
OSV10 signalsLast observed: 2026-10-04Status: healthy
Vendor Advisory20 signalsLast observed: 2026-10-04Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled