Almost none of what we read
ever reaches you.
That restraint is the product. We analyse every disclosure, match it against the software you actually run, and send only the ones that touch it — with the summary, the impact and the affected systems already written.
- CVEs analysed
- 16,368
- Flagged major
- 3,415
- Last 30 days
- 2,572
- Per channel, per tick
- ≤ 3
One disclosure. Three clients. Sent once.
Below is a real row from the corpus — CVE-2026-57677, CRITICAL at 9.8 — rendered the way each sender formats it. Delivery is recorded per user, per CVE, per channel, so this arrives once on each and never again.
Unauthenticated PHP object injection leads to RCE in Novalnet gateway for WooCommerce <=12.10.3
- matched stack
- WordPress, WooCommerce
- affected
- WordPress, WooCommerce, Novalnet Payment Gateway for WooCommerce <=12.10.3
You’re getting this because WordPress, WooCommerce is in your tracked stack.
Unsubscribe · © 2026 vulneraibility.com
Unauthenticated PHP object injection leads to RCE in Novalnet gateway for WooCommerce <=12.10.3
Stack: WordPress, WooCommerce
Affected: WordPress, WooCommerce, Novalnet Payment Gateway for WooCommerce <=12.10.3
Open in dashboard · CVE detail
Unauthenticated PHP object injection leads to RCE in Novalnet gateway for WooCommerce <=12.10.3
Stack: WordPress, WooCommerce
Affected: WordPress, WooCommerce, Novalnet Payment Gateway for WooCommerce <=12.10.3
Open in dashboard · CVE detail
The row behind the alert, read live from the corpus. The two buttons open it: the dashboard entry where you triage it, and the full CVE record with the impact, the recommendation and the patch state.
Volume in. Silence out.
Drawn to scale from the last thirty days of intake, against an example six-technology stack. The last band is not a rendering artefact — that is how much of the feed is yours.
Everything, analysed
2,572 disclosures came through the pipeline in the last thirty days. Each one classified, summarised and scored before anything is decided about who should see it.
Matched to your stack
203 of them name one of the six technologies in the example stack among their affected systems. On a paid plan this is your stream. No stack match, no message.
The hairline
17 of those were flagged major — what a free account receives. Roughly one a day, and the throttle caps it at three per channel per tick regardless.
Counted live over the trailing thirty days. The example stack is WordPress, WooCommerce, nginx, PostgreSQL, Docker, Ubuntu; the query matches a disclosure when its affected-systems list names one of them — a deliberately loose test. The matcher that actually decides what reaches your inbox is stricter than this proxy, so the real volume for that stack runs lower still. Treat these as the shape of the collapse, not a quota.
Quiet is enforced, not promised.
Every one of these is a condition in the dispatch loop, not a setting we hope you configure correctly. The worker checks them on each pass and skips anything that fails.
- 01stack match required
- A disclosure is only eligible for you if it touches a technology on your list. Nothing else is ever considered, on any plan.
- 02free tier · major only
- Free accounts receive the major disclosures — 3,415 of 16,368 so far. Paid accounts receive the full stack-specific stream.
- 03no backfill
- Only CVEs published after you signed up can reach you. A new account does not open with months of history it can do nothing about.
- 04sent once, per channel
- One row is written per user, per CVE, per channel the moment it goes out. A crash mid-batch or a retry can never send the same alert twice — and email, Telegram and Slack are tracked independently.
- 05three per channel per tick
- A hard ceiling on messages per user per channel on every pass. A bad day upstream cannot turn into forty notifications.
- 06telegram + slack are max
- Email is on every plan. Telegram is linked by DMing the bot a one-time code; Slack by an incoming webhook. Both are Max-tier, and both drop away automatically on downgrade.
- 07one toggle off
- Alerts stop the moment you switch them off, and the one-click unsubscribe in every email is honoured on the very next pass.
Every disclosure is scored on CVSS, EPSS and CISA KEV before it earns a place in your inbox. 16,264 of the 16,368 CVEs analysed carry an EPSS score, and 135 of them appear in CISA’s Known Exploited Vulnerabilities catalogue — both read live and resynced by a background worker.
List your technologies. Wait for the quiet.
No agent to install and no scanner to schedule — you describe your stack and the matching happens here. Email alerts are on the free plan.
Start free