Vuln Signal Radar
CRIT 2
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-16585, with 1 CVE, 0 KEV-listed records, EPSS percentile 51, and remediation reference unknown. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 53. 1 critical cluster has unknown remediation references. The largest displayed cluster is CVE-2026-16585, with 1 CVE.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2018 new in 7d
Critical2canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors1from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-08-04 06:16 UTC / 2026-08-04 15:16 JST

Live Vulnerability Feed READ-ONLY

2026-08-04
defensive priority signal
CRITICALEPSS 0.0045 (37)NEW-NVD: A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2… Handoff
2026-08-04
defensive priority signal
CRITICALEPSS 0.0028 (20)NEW-NVD: The TrueBooker WordPress plugin before 1.2.4 does not validate account ownership when resetting a user's password through one of its f… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0078 (53)NEW-NVD: Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation durin… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0027 (20)NEW-NVD: In Bouncy Castle for Java from 1.73 to before 1.78, three ML-KEM (CRYSTALS-Kyber) routines divided secret-derived polynomial coefficie… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0051 (41)NEW-NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0030 (23)NEW-NVD: The WP Fast Total Search – The Power of Indexed Search plugin for WordPress is vulnerable to generic SQL Injection via the 'form_data[… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0025 (17)NEW-NVD: The Tablesome Table WordPress plugin before 1.1.31 does not perform any authentication, capability, or nonce checks in one of its AJAX… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0073 (51)NEW-NVD: The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file del… Handoff
2026-08-04
defensive priority signal
HIGHEPSS 0.0015 (4)NEW-NVD: The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.3 does not properly sanitise and escape a parame… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0025 (16)NEW-NVD: The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0032 (24)NEW-NVD: The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all ver… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0022 (12)NEW-NVD: Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. OSV: Versions… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0021 (11)NEW-NVD: The PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer plugin for WordPress is vulne… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0027 (19)NEW-NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-based SQL Injecti… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0022 (13)NEW-NVD: The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in all versions… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0022 (12)NEW-NVD: The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure Direct Object… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0013 (3)NEW-NVD: The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versio… Handoff
2026-08-04
defensive priority signal
MEDIUMEPSS 0.0014 (4)NEW-NVD: The FluentCart A New Era of eCommerce WordPress plugin before 1.4.0 does not verify that a subscription belongs to the requesting cust… Handoff
2026-08-04
defensive priority signal
LOWEPSS 0.0014 (4)NEW-NVD: The Event Tickets and Registration WordPress plugin before 5.28.4 does not properly escape event titles before outputting them in a ti… Handoff
2026-08-04
defensive priority signal
LOWEPSS 0.0017 (6)NEW-NVD: The Quiz and Survey Master (QSM) WordPress plugin before 11.1.5 does not perform a capability check before deleting output templates… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-08-04 06:16 UTC / 2026-08-04 15:16 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

32 public-safe changes since the previous successful snapshot.

Added16
Changed0
Removed16
What changed
  • CVE-2024-14041: newly added to the public-safe set.
  • CVE-2026-11756: newly added to the public-safe set.
  • CVE-2026-12741: newly added to the public-safe set.
  • 29 more public-safe changes in the JSON feed.
Previous snapshot2026-08-03 22:33 UTC / 2026-08-04 07:33 JST
Items compared20 -> 20
Feed generated2026-08-04 06:16 UTC / 2026-08-04 15:16 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV3
CISA KEV0
Affected products0partial
CPE0partial
PURL0partial
Canonical vendor/product0partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-08-0420

Severity Distribution

  • CRITICAL 2
  • HIGH 7
  • MEDIUM 9
  • LOW 2
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
Vendor Advisory20
OSV3

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-11756
Critical / High2 / 7
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 2,
    "HIGH": 7,
    "LOW": 2,
    "MEDIUM": 9,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-11756"
}

Source Status

NVD20 signalsLast observed: 2026-08-04Status: healthy
EPSS20 signalsLast observed: 2026-08-04Status: healthy
OSV3 signalsLast observed: 2026-08-04Status: healthy
CISA KEV0 signalsLast observed: 2026-08-04Status: not observed
Vendor Advisory20 signalsLast observed: 2026-08-04Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled