Vuln Signal Radar
CRIT 4
public radar

Prioritized Vulnerability Signals for Defenders

Track CVE, KEV, EPSS, and vendor-advisory changes in one read-only radar—so teams can see what changed, why it matters, and what to verify next.

LIVE SIGNAL MAPDEFENSIVE PRIORITY CIRCUITLATEST STATIC SNAPSHOT
PRIORITY ORDER · NOT AN ATTACK PATH

Latest static defensive priority circuit. This is a review-priority visualization, not an attack path. 7 product clusters are shown. The highest urgency cluster is CVE-2026-66747, with 1 CVE, 0 KEV-listed records, EPSS percentile 45, and remediation reference unknown. 0 displayed clusters contain KEV-listed records. The highest displayed EPSS percentile is 45. 4 critical clusters have unknown remediation references. The largest displayed cluster is eclipse theia, with 3 CVEs. Additional affected products are present in the underlying record.

indexable public surfaceread-only datasetpublic-safe sourcesexternal execution disabledauto remediation disabled
Tracked CVEs2020 new in 7d
Critical4canonical CVSS
Known Exploited0KEV observed
High EPSS percentile (≥70)0EPSS percentile observed
Monitored Vendors2from current data
VULNERABILITY TREEMAP

DEFENSIVE PRIORITY SURFACE

Stable CVE grouping for defensive triage. Area changes by display mode; severity remains encoded by color.

LATEST STATIC SNAPSHOT2026-08-12 10:39 UTC / 2026-08-12 19:39 JST

Live Vulnerability Feed READ-ONLY

2026-08-12
defensive priority signal
CRITICALEPSS 0.0042 (35)NEW-NVD: Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and… Handoff
2026-08-12
defensive priority signal
CRITICALEPSS 0.0036 (29)NEW-NVD: IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin c… Handoff
2026-08-12
defensive priority signal
CRITICALEPSS 0.0058 (45)NEW-NVD: Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product li… Handoff
2026-08-12
defensive priority signal
CRITICALEPSS 0.0031 (24)NEW-NVD: DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0032 (25)NEWeclipse / theiaNVD: In Eclipse Theia versions up to and including 1.73.1, the @theia/filesystem backend binds POST /file-upload in every filesystem-enable… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0029 (21)NEW-NVD: Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT mes… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0029 (21)NEW-NVD: The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filte… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0020 (10)NEW-NVD: InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!!… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0020 (10)NEW-NVD: Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field value… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0022 (12)NEW-NVD: Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, un… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0022 (13)NEW-NVD: DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0041 (34)NEWeclipse / theiaNVD: In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the @theia/plugin-ext backend exposes the /hostedPlugin/:pluginId/:pat… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0028 (20)NEW-NVD: Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @log… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0024 (16)NEW-NVD: Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no aut… Handoff
2026-08-12
defensive priority signal
HIGHEPSS 0.0030 (22)NEW-NVD: MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a… Handoff
2026-08-12
defensive priority signal
MEDIUMEPSS 0.0020 (10)NEW-NVD: Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stor… Handoff
2026-08-12
defensive priority signal
MEDIUMEPSS 0.0028 (20)NEWeclipse / theiaNVD: In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the PreferenceUtils.merge function in @theia/core recursively merges pr… Handoff
2026-08-12
defensive priority signal
MEDIUMEPSS 0.0017 (7)NEWeclipse / accessibility_tools_frameworkNVD: In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based ap… Handoff
2026-08-12
defensive priority signal
MEDIUMEPSS 0.0019 (9)NEW-NVD: DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_requ… Handoff
2026-08-12
defensive priority signal
LOWEPSS 0.0015 (5)NEW-NVD: Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usag… Handoff
Critical High Medium Low KEVKnown Exploited NEWNewly ObservedJ / K Move · ↑ / ↓ Move · Enter Open · Esc Close

Agent Access Agent Data Surface

Read-only static JSON for humans and AI agents. This is a data contract, not an execution surface.

Knowledge Graph / JSON-LDlinks CVE signals, sources, affected products, and provenanceLocal-first Vaultbrowser-only personal review context; import/export/clear supportedRirastaFab Trust Layerhash-only integrity metadata, canonical envelopes, and proof endpointsCanonical Envelopeattestation-ready preflight metadata without onchain submission

Agents should start with /agent.json, validate the signal item schema, use the JSON-LD graph for provenance, and treat the Local Vault as private browser state that is never uploaded.

WebMCP read-only toolsEnabledRuntime server endpointsNoneStatic agent JSONEnabled
Allowedsearch / list / get / summarize / prioritize
Disabledscan / patch / exploit / external execution / auto remediation

Last generated: 2026-08-12 10:39 UTC / 2026-08-12 19:39 JST. Observed dates are per-source signal timestamps.

Latest Changes Diff Feed

previous successful latestpublic snapshot comparison

40 public-safe changes since the previous successful snapshot.

Added20
Changed0
Removed20
What changed
  • CVE-2026-12609: newly added to the public-safe set.
  • CVE-2026-14304: newly added to the public-safe set.
  • CVE-2026-14574: newly added to the public-safe set.
  • 37 more public-safe changes in the JSON feed.
Previous snapshot2026-08-12 05:14 UTC / 2026-08-12 14:14 JST
Items compared20 -> 20
Feed generated2026-08-12 10:39 UTC / 2026-08-12 19:39 JST
Open latest diff feed

Enrichment Coverage partial

Coverage is shown from the current public dataset. CPE, PURL, and canonical vendor/product are partial and may be unknown.

NVD20
Vendor Advisory20
OSV7
CISA KEV0
Affected products5partial
CPE5partial
PURL0partial
Canonical vendor/product5partial

Observed Buckets (current snapshot)

Current snapshot only. Historical trend appears after multiple generated runs.

2026-08-1220

Severity Distribution

  • CRITICAL 4
  • HIGH 11
  • MEDIUM 4
  • LOW 1
  • NONE 0
  • UNKNOWN 0

Source Distribution (current snapshot)

NVD20
Vendor Advisory20
OSV7

Monitored Vendors

View all vendors →

Vendor distribution from the current public snapshot. Neutral badges are not official vendor logos.

Local-first Personal Data Vault

A browser-only vault for human review context. It stores vendor / product / package / CPE prefix / saved signals / muted signals / preferences in localStorage, supports import/export/clear, validates shape on import, and never uploads data.

No watched signals yet. Use the heart control on a signal row to add one.

Saved Views

Save and reapply local filter sets. Nothing is uploaded.

No saved views. Enter a name and save the current filters.

Read-only Triage Report Preview

Generated from the current filters. Defensive checklist only; no exploit or scanning detail.

Filtered signals20
Top priority candidateCVE-2026-71237
Critical / High4 / 11
Safety moderead-only, public indexable, public-safe
Raw JSON details
{
  "count": 20,
  "defensive_checklist": [
    "Confirm affected products",
    "Review official source references",
    "Prioritize KEV, critical CVSS, and high EPSS percentile items",
    "Record human confirmation"
  ],
  "mode": "read_only_public_beta_dashboard",
  "safety": {
    "procedural_detail": false,
    "public_launch": true,
    "scanner_execution": false
  },
  "severity_distribution": {
    "CRITICAL": 4,
    "HIGH": 11,
    "LOW": 1,
    "MEDIUM": 4,
    "NONE": 0,
    "UNKNOWN": 0
  },
  "top_risk": "CVE-2026-71237"
}

Source Status

NVD20 signalsLast observed: 2026-08-12Status: healthy
EPSS20 signalsLast observed: 2026-08-12Status: healthy
OSV7 signalsLast observed: 2026-08-12Status: healthy
CISA KEV0 signalsLast observed: 2026-08-12Status: not observed
Vendor Advisory20 signalsLast observed: 2026-08-12Status: observed

Safety Guardrails

Public indexingEnabled
Read-only surfaceEnabled
Deploy controlsCodex managed deploy only
External notificationDisabled
Auto remediationDisabled
Runtime server endpointsNone
WebMCP read-only toolsEnabled
Static agent JSONEnabled