Vuln Signal Radar
CRIT 5
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2024-58387, with 1 CVE, 0 KEV-listed records, EPSS percentile 44, and remediation reference unknown. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 64. 1 critical cluster has unknown remediation references. The largest displayed cluster is accellion kiteworks, with 8 CVEs.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2020 new in 7d
Critical5canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors2from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-10-07 20:41 UTC / 2026-10-08 05:41 JST

Live Vulnerability Feed READ-ONLY

2026-10-07
defensive priority signal
CRITICALEPSS 0.0040 (32)NEW-NVD: iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() f… Handoff
2026-10-07
defensive priority signal
CRITICALEPSS 0.0027 (17)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. NVD: Kiteworks Email Protection… Handoff
2026-10-07
defensive priority signal
CRITICALEPSS 0.0027 (17)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). NVD: A server-side reques… Handoff
2026-10-07
defensive priority signal
CRITICALEPSS 0.0023 (13)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). NVD: A server-side reques… Handoff
2026-10-07
defensive priority signal
CRITICALEPSS 0.0023 (13)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). NVD: A server-side reques… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0055 (44)NEW-NVD: Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unau… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0046 (38)NEW-NVD: Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0045 (37)NEW-NVD: iDocView contains a server-side request forgery vulnerability in its /doc/upload endpoint that allows remote unauthenticated attackers… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0022 (11)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-Site Scripting. NVD: A stored cross-site scripting (XSS) weakness in… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0021 (10)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to Stored Cross-site Scripting (XSS) that could allow an authenticated user to store… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0031 (21)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to Deserialization of Untrusted Data. NVD: A deserialization weakness in Kiteworks C… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0032 (23)NEW-NVD: Kiteworks Secure Data Forms before version 9.5.0 is vulnerable to Server-Side Request Forgery that could allow an unauthenticated, rem… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0109 (64)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to OS Command Injection that allows an authenticated administrator to upload a confi… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0071 (52)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. NVD: Kiteworks Email Protection Gatewa… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0064 (49)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. NVD: An improper restriction of a user-supplied file path i… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0050 (41)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import functio… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0047 (39)NEW-NVD: Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Unsafe Reflection and does not sufficiently restrict the code… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0034 (25)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to Improper Privilege Management and does not correctly enforce restrictions on role… Handoff
2026-10-07
defensive priority signal
HIGHEPSS 0.0032 (24)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. NVD: A stored SQL injection vulnerability in a Kiteworks administr… Handoff
2026-10-07
defensive priority signal
MEDIUMEPSS 0.0020 (9)NEWaccellion / kiteworksNVD: Kiteworks Core before version 9.5.1 is vulnerable to Content Injection. NVD: A URL parameter in the PDF viewer was insufficiently vali… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-10-07 20:41 UTC / 2026-10-08 05:41 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

40 public-safe changes since the previous successful snapshot.

Added20
Changed0
Removed20
What changed
  • CVE-2023-54402: newly added to the public-safe set.
  • CVE-2023-54403: newly added to the public-safe set.
  • CVE-2024-58387: newly added to the public-safe set.
  • 37 more public-safe changes in the JSON feed.
Previous snapshot2026-10-07 16:41 UTC / 2026-10-08 01:41 JST
Items compared20 -> 20
Feed generated2026-10-07 20:41 UTC / 2026-10-08 05:41 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV0
Affected products8partial
CPE8partial
PURL0partial
Canonical vendor/product8partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-10-0720

Severity Distribution

  • CRITICAL 5
  • HIGH 14
  • MEDIUM 1
  • LOW 0
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
Vendor Advisory20

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-101276
Critical / High5 / 14
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 5,
    "HIGH": 14,
    "LOW": 0,
    "MEDIUM": 1,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-101276"
}

Source Status

NVD20 signalsLast observed: 2026-10-07Status: healthy
EPSS20 signalsLast observed: 2026-10-07Status: healthy
OSV0 signalsLast observed: 2026-10-07Status: not observed
Vendor Advisory20 signalsLast observed: 2026-10-07Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled