Vuln Signal Radar
CRIT 2
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-54617, with 1 CVE, 0 KEV-listed records, EPSS percentile 64, and remediation references present. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 64. 0 critical clusters have unknown remediation references. The largest displayed cluster is CVE-2026-54617, with 1 CVE.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2020 new in 7d
Critical2canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors1from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-09-24 19:15 UTC / 2026-09-25 04:15 JST

Live Vulnerability Feed READ-ONLY

2026-09-24
defensive priority signal
CRITICALEPSS 0.0109 (64)NEW-NVD: GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. NVD: Prior to 5.7.12, an unauthenticated remote actor can… Handoff
2026-09-24
defensive priority signal
CRITICALEPSS 0.0070 (51)NEW-NVD: Anyquery is an SQL query engine built on top of SQLite. NVD: Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affec… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0057 (45)NEW-NVD: MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. NVD: From 1.13.0 until… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0032 (23)NEW-NVD: Faust.js is a headless WordPress toolkit. NVD: Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0052 (42)NEW-NVD: ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. NVD: Prior to 3.11.1, th… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0013 (2)NEW-NVD: There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq). NVD: This may resul… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0019 (8)NEW-NVD: uniget is a universal installer and updater for (container) tools. NVD: Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0052 (42)NEW-NVD: Elixir protobuf is a pure Elixir implementation of Google Protobuf. NVD: From 0.8.0 until 0.16.1, services that decode attacker-contro… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0028 (18)NEW-NVD: TS3 Manager is modern web interface for maintaining Teamspeak3 servers. NVD: Prior to 2.2.6, the /api/download handler in packages/ser… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0049 (39)NEW-NVD: Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. NVD: Bec… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0040 (31)NEW-NVD: A flaw was found in Keycloak. NVD: When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between th… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0059 (46)NEW-NVD: lxc-ci contains continuous integration and image-build scripts for LXC. NVD: Prior to the 2026-05-28 Arch Linux image publication, ima… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0048 (39)NEW-NVD: Frappe HR is an open-source human resources management solution (HRMS). NVD: Prior to 16.7.0, an authenticated user with the HR User r… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0039 (30)NEW-NVD: Traccar is an open source GPS tracking system. NVD: Prior to 6.14.0, an authenticated, non-readonly user with access to an object usab… Handoff
2026-09-24
defensive priority signal
HIGHEPSS 0.0014 (3)NEW-NVD: Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. NVD: Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSessio… Handoff
2026-09-24
defensive priority signal
MEDIUMEPSS 0.0053 (42)NEW-NVD: Traccar is an open source GPS tracking system. NVD: Prior to 6.14.0, an authenticated user with permission to manage groups and reques… Handoff
2026-09-24
defensive priority signal
LOWEPSS 0.0084 (56)NEW-NVD: punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. NVD: Prior to 1… Handoff
2026-09-24
defensive priority signal
LOWEPSS 0.0039 (31)NEW-NVD: A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. NVD: The affected element is an unknown function of the… Handoff
2026-09-24
defensive priority signal
LOWEPSS 0.0015 (4)NEW-NVD: uniget is a universal installer and updater for (container) tools. NVD: Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go… Handoff
2026-09-24
defensive priority signal
NONEEPSS 0.0044 (35)NEW-NVD: Kiwi TCMS is an open source test management system. NVD: Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tc… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-09-24 19:15 UTC / 2026-09-25 04:15 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

40 public-safe changes since the previous successful snapshot.

Added20
Changed0
Removed20
What changed
  • CVE-2026-19477: newly added to the public-safe set.
  • CVE-2026-45720: newly added to the public-safe set.
  • CVE-2026-47252: newly added to the public-safe set.
  • 37 more public-safe changes in the JSON feed.
Previous snapshot2026-09-24 14:17 UTC / 2026-09-24 23:17 JST
Items compared20 -> 20
Feed generated2026-09-24 19:15 UTC / 2026-09-25 04:15 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV17
Affected products0partial
CPE0partial
PURL0partial
Canonical vendor/product0partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-09-2420

Severity Distribution

  • CRITICAL 2
  • HIGH 13
  • MEDIUM 1
  • LOW 3
  • NONE 1
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
Vendor Advisory20
OSV17

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-54617
Critical / High2 / 13
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 2,
    "HIGH": 13,
    "LOW": 3,
    "MEDIUM": 1,
    "NONE": 1,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-54617"
}

Source Status

NVD20 signalsLast observed: 2026-09-24Status: healthy
EPSS20 signalsLast observed: 2026-09-24Status: healthy
OSV17 signalsLast observed: 2026-09-24Status: healthy
Vendor Advisory20 signalsLast observed: 2026-09-24Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled