Vuln Signal Radar
REVIEW 19
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-13170, with 1 CVE, 0 KEV-listed records, EPSS percentile 33, and remediation reference unknown. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 33. 0 critical clusters have unknown remediation references. The largest displayed cluster is CVE-2026-13170, with 1 CVE.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs1919 new in 7d
Critical0canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors1from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-08-17 04:10 UTC / 2026-08-17 13:10 JST

Live Vulnerability Feed READ-ONLY

2026-08-17
defensive priority signal
HIGHEPSS 0.0028 (20)NEW-NVD: The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public… Handoff
2026-08-17
defensive priority signal
HIGHEPSS 0.0012 (2)NEW-NVD: A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a rel… Handoff
2026-08-17
defensive priority signal
HIGHEPSS 0.0026 (17)NEW-NVD: The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only acces… Handoff
2026-08-17
defensive priority signal
HIGHEPSS 0.0034 (27)NEW-NVD: The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress… Handoff
2026-08-17
defensive priority signal
HIGHEPSS 0.0032 (24)NEW-NVD: The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form d… Handoff
2026-08-17
defensive priority signal
HIGHEPSS 0.0040 (33)NEW-NVD: The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file… Handoff
2026-08-17
defensive priority signal
HIGHEPSS 0.0026 (18)NEW-NVD: The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in th… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0024 (15)NEW-NVD: The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline scrip… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0018 (7)NEW-NVD: libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrog… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0013 (3)NEW-NVD: A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0017 (6)NEW-NVD: The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-r… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0017 (6)NEW-NVD: The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0024 (15)NEW-NVD: The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied i… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0022 (13)NEW-NVD: The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint tha… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0018 (8)NEW-NVD: The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauth… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0017 (7)NEW-NVD: The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front en… Handoff
2026-08-17
defensive priority signal
MEDIUMEPSS 0.0019 (8)NEW-NVD: The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using… Handoff
2026-08-17
defensive priority signal
LOWEPSS 0.0015 (5)NEW-NVD: The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider)… Handoff
2026-08-17
defensive priority signal
LOWEPSS 0.0019 (9)NEW-NVD: The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with t… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-08-17 04:10 UTC / 2026-08-17 13:10 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

34 public-safe changes since the previous successful snapshot.

Added17
Changed0
Removed17
What changed
  • CVE-2026-12971: newly added to the public-safe set.
  • CVE-2026-13133: newly added to the public-safe set.
  • CVE-2026-13170: newly added to the public-safe set.
  • 31 more public-safe changes in the JSON feed.
Previous snapshot2026-08-16 21:43 UTC / 2026-08-17 06:43 JST
Items compared19 -> 19
Feed generated2026-08-17 04:10 UTC / 2026-08-17 13:10 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD19
Vendor Advisory19
OSV2
CISA KEV0
Affected products0partial
CPE0partial
PURL0partial
Canonical vendor/product0partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-08-1719

Severity Distribution

  • CRITICAL 0
  • HIGH 7
  • MEDIUM 10
  • LOW 2
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD19
Vendor Advisory19
OSV2

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals19
Top priority candidateCVE-2026-14293
Critical / High0 / 7
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 19,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 0,
    "HIGH": 7,
    "LOW": 2,
    "MEDIUM": 10,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-14293"
}

Source Status

NVD20 signalsLast observed: 2026-08-17Status: healthy
EPSS19 signalsLast observed: 2026-08-17Status: healthy
OSV2 signalsLast observed: 2026-08-17Status: healthy
CISA KEV0 signalsLast observed: 2026-08-17Status: not observed
Vendor Advisory19 signalsLast observed: 2026-08-17Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled