Vuln Signal Radar
REVIEW 20
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-100520, with 1 CVE, 0 KEV-listed records, EPSS percentile 59, and remediation references present. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 59. 0 critical clusters have unknown remediation references. The largest displayed cluster is CVE-2026-100520, with 1 CVE.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2020 new in 7d
Critical0canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors1from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-10-03 00:34 UTC / 2026-10-03 09:34 JST

Live Vulnerability Feed READ-ONLY

2026-10-03
defensive priority signal
HIGHEPSS 0.0094 (59)NEW-NVD: Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authen… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0019 (7)NEW-NVD: OpenClaw versions before 2026.8.1 fail to bind working directory context to reusable exec approvals, allowing approved commands to exe… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0026 (17)NEW-NVD: OpenClaw (npm package 'openclaw') versions >= 2026.4.5 and < 2026.8.1 can lose the originating requester's restrictions and untrusted… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0021 (9)NEW-NVD: OpenClaw versions before 2026.8.1 contain an authorization scope widening vulnerability in file-transfer allow-always approvals that a… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0013 (2)NEW-NVD: Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0027 (17)NEW-NVD: @openclaw/whatsapp (npm) before 2026.8.1 exposes the WhatsApp login tool through the generic channel-tool path without preserving the… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0043 (35)NEW-NVD: OpenClaw versions before 2026.8.1 fail to validate all source fields in structured message attachments, allowing attackers to hide unv… Handoff
2026-10-03
defensive priority signal
HIGHEPSS 0.0033 (24)NEW-NVD: The @openclaw/slack npm package before 2026.8.1 contains an authorization flaw in its Slack download-file handler: when a file lacks t… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0035 (26)NEW-NVD: OpenClaw before 2026.8.2 contains a denial of service vulnerability in the Browser extension relay that allows unauthenticated network… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0029 (20)NEW-NVD: OpenClaw versions before 2026.8.1 contain a path traversal vulnerability in the tools.fs.workspaceOnly feature where Unicode filename… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0028 (19)NEW-NVD: OpenClaw's Discord integration (npm package @openclaw/discord) before version 2026.9.3 could lose the sender-scoped media policy in th… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0024 (14)NEW-NVD: OpenClaw (npm package 'openclaw') before 2026.8.1 could send third-party provider credentials to the wrong endpoint. NVD: In affected… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0024 (14)NEW-NVD: The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.re… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0012 (2)NEW-NVD: Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform s… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0021 (10)NEW-NVD: Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly e… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0020 (9)NEW-NVD: Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs n… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0019 (8)NEW-NVD: Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0012 (2)NEW-NVD: Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused… Handoff
2026-10-03
defensive priority signal
MEDIUMEPSS 0.0012 (1)NEW-NVD: Ghidra versions 9.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-… Handoff
2026-10-03
defensive priority signal
LOWEPSS 0.0027 (17)NEW-NVD: OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that allows attackers… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-10-03 00:34 UTC / 2026-10-03 09:34 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

38 public-safe changes since the previous successful snapshot.

Added20
Changed0
Removed18
What changed
  • CVE-2026-100503: newly added to the public-safe set.
  • CVE-2026-100504: newly added to the public-safe set.
  • CVE-2026-100505: newly added to the public-safe set.
  • 35 more public-safe changes in the JSON feed.
Previous snapshot2026-10-02 20:00 UTC / 2026-10-03 05:00 JST
Items compared18 -> 20
Feed generated2026-10-03 00:34 UTC / 2026-10-03 09:34 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV20
Affected products0partial
CPE0partial
PURL0partial
Canonical vendor/product0partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-10-0320

Severity Distribution

  • CRITICAL 0
  • HIGH 8
  • MEDIUM 11
  • LOW 1
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
OSV20
Vendor Advisory20

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-100520
Critical / High0 / 8
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 0,
    "HIGH": 8,
    "LOW": 1,
    "MEDIUM": 11,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-100520"
}

Source Status

NVD20 signalsLast observed: 2026-10-03Status: healthy
EPSS20 signalsLast observed: 2026-10-03Status: healthy
OSV20 signalsLast observed: 2026-10-03Status: healthy
Vendor Advisory20 signalsLast observed: 2026-10-03Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled