247 new CVEs a day. We notify you about the ones that matter.
You own the stack and you carry the pager. Nobody is going to read all of them for you, so we do. Free, one field, nothing to install.
Free major-CVE alerts. No scanner, no agent, no card.
- Scored on CVSS, EPSS and CISA KEV
- 16,368 CVEs analysed so far
- One-click unsubscribe
247 CVEs drop every day.
Only a handful can hurt you.
The NVD firehose, and it is accelerating: 247 a day so far in 2026 against 136 in 2025. Nobody reads that. Nobody can.
Of 386,879 CVEs ever published, 1,695 are on CISA’s Known Exploited Vulnerabilities list. That is the set actually being used against people. The rest is homework.
No agent. No network access. Declare what you run once, and we do the matching.
How you get from 247 CVEs a day to a short list
We score every CVE on CVSS severity, EPSS exploit probability and CISA’s confirmed-exploited list, match it against the technologies you run, and notify you about the ones that survive, in scheduled batches through the day, with KEV re-checked hourly.
Give us your email
One field, no card, no scanner to install. Free major-CVE alerts start with the next batch.
How alerting worksAdd your stack
Tell us the technologies you run. We match CVEs to your infrastructure.
How stack tracking worksGet targeted alerts
AI filtered CVE alerts for your specific stack. No noise, only what threatens you.
How we score riskSee it as a map
Your stack lit up by real risk, so you know where to look first rather than reading a list.
See the risk heatmapPre-auth SSRF in SonicWall SMA1000 allows auth bypass and unauthorized admin access.
- matched stack
- sonicwall
- affected
- SonicWall SMA1000 Appliance
The last 8 CVEs we analysed
most recent 2026-09-16- CVE-2026-920138.8CanvasWebGL bounds bug in Firefox/Thunderbird allows local privilege escalation.
- CVE-2026-920068.8Canvas WebGL boundary bug in Firefox/Thunderbird enabling local privilege escalation.
- CVE-2026-834568.8Remote privilege escalation allows takeover of Oracle Demand Signal Repository.
- CVE-2026-834558.1Low-privilege remote exploit in Oracle Demand Signal Repository allows full data access.
- CVE-2026-834548.8Remote privilege escalation in Oracle Document Management enabling full takeover.
- CVE-2026-834529.8Unauthenticated remote takeover of Oracle Document Management (EBS)
- CVE-2026-834518.5Remote privilege-escalation in Oracle Product Workbench allowing full takeover.
- CVE-2026-834508.0Privilege-escalation in Oracle E-Business Suite Bills of Material allows takeover
Read live from the same table the screener serves. Not a curated list. Every row above is checkable, with its CVSS, EPSS and KEV status, and it needs no account. Audit all 16,368 of them →
Talk to your CVEs
from Claude, Cursor, or any AI.
Our MCP server lets your favourite AI assistant search your CVE backlog, read every vulnerability's impact, and update statuses, without leaving the chat. Manage your vulnerabilities with AI.
Pick the plan that matches your stack
Start free. Upgrade when you need more. No credit card for the free tier.
Free
Essentials to get started with major CVE alerts
- Major CVE alerts by email
- Track 2 technologies
- Delivered to Email
- 100 CVEs of searchable history
Premium
Full CVE intelligence, 1k backlog, categories, ticketing
- High · Critical · Major CVE alerts by email
- Track unlimited technologies
- Delivered to Email
- 1,000 CVEs of searchable history
- Triage Workflow & Risk Acceptance
- Filter alerts by category
Max
Everything in Premium, plus Slack/Telegram alerts, AI fix instructions, unlimited backlog, and full programmatic access (REST API + MCP)
- High · Critical · Major CVE alerts by email
- Track unlimited technologies
- Delivered to Email, Slack, Telegram
- Unlimited searchable CVE history
- Triage Workflow & Risk Acceptance
- AI fix instructions and enrichment
- Filter alerts by category
- REST API access
- MCP server for Claude, Cursor and other AI tools
Questions security teams ask before signing up
Do I need to install a scanner?
No. Declare the technologies you run and we cross-reference every new CVE against them. No agent on your hosts. No network access. No credentials.
Why not just use free NVD or CISA KEV email alerts?
If you already read them and they work for you, keep them. They are the same public data we start from. The difference is what arrives: NVD mails you everything, which in 2026 is about 247 CVEs a day, and CISA mails you the exploited ones whether or not you run the affected software. We match every CVE against the specific technologies you tell us you run, score it on CVSS, EPSS and KEV together, and only mail you what clears the bar. The free feeds are a firehose and a watchlist; this is a filter.
What's the difference between Premium and Max?
Premium unlocks unlimited technologies, categories, and the 1,000-CVE backlog. Max adds Slack + Telegram alerts, AI fix instructions, unlimited backlog, and API access for programmatic consumption.
How accurate is the AI filtering?
Every CVE is scored on three public signals: CVSS severity, EPSS exploit probability, and membership of the CISA KEV catalogue. An LLM pass then adds context. We have not published a recall figure against expert review and will not quote one until we can show the working. You can audit the output yourself: the screener lists every CVE we have analysed, with its scores, and needs no account.
How quickly do alerts arrive?
We ingest new CVEs from NVD in scheduled batches through the day, then re-check the CISA KEV catalogue every hour and EPSS scores daily, so a CVE that becomes known-exploited after publication is re-flagged the same day. Alerts dispatch within a minute of a matching CVE landing in our database. We are in private beta and do not yet publish a latency SLA.
Is the free tier really free?
Yes. Major-CVE alerts, stack matching, and email delivery, no card, no trial clock. It stops at 2 technologies because that's where Free becomes Premium.
Can I export CVEs or hit this from an API?
A REST API with per-user keys is included in Max today. Authenticate with a bearer token and filter by your stack. The public screener is also open to everyone, with no account, if you just want to search the corpus.
What data do you store?
Just the technology list you declare and your account email. We never see your infrastructure, servers, code, or traffic. Data is encrypted at rest and never shared.
Can I use an anonymized email and name?
Yes, please do. We care about delivering the best CVE data for your stack, not about knowing who you are. Sign up with a privacy-forwarding alias (Apple Hide My Email, SimpleLogin, anonaddy, ProtonMail aliases, +tag addresses, anything you like) and put whatever you want as your username. The Service has no need for your real identity to work.
What happens when I delete my account?
Immediate deletion. The moment you hit delete in your dashboard, your account row, declared stack, alert history, and integration bindings are removed from the database. Only billing records mandated by law (invoices, tax receipts) are retained for the statutory accounting period. No 30-day grace window, no soft-delete recovery.
Can I cancel anytime?
Yes. Premium and Max are month-to-month via Stripe. Downgrade or cancel from your dashboard, access continues until the end of the current period.
Stop drowning in CVE noise.
386,879 CVEs exist and 247 more land every day. Tell us what you run, and we will tell you which of them are actually yours.
Free major-CVE alerts. No scanner, no agent, no card.
No credit card required · Cancel anytime