Skip to content
Private Beta ·invite-only access. Reach out to get in.
stack tracking

Tell us what you run.
We watch it for you.

Add the technologies in your estate — and optionally the versions — and every incoming CVE is matched against them. No agents to deploy, no scanner to schedule, nothing installed on your infrastructure.

Setup is a list of technology names. There is no step two.

16,368
CVEs analysed
6,334
critical
9,952
high
3,415
flagged major

Read from the corpus when this page was last built, refreshed hourly. Severity is bucketed on CVSS.

the whole mechanism

One list in.
Every matching disclosure out.

Left: six technologies, typed by hand, two of them without a version. Right: what those six actually match in the corpus — the counts and the CVEs below are read from the database, not illustrated. Nothing was installed to produce them.

your stackname required · version optional
  • WordPress6.4
    481 matching CVEs in the corpus
  • Linux kernel6.8
    343 matching CVEs in the corpus
  • Apacheno version
    120 matching CVEs in the corpus
  • Node.jsno version
    64 matching CVEs in the corpus
  • PostgreSQL16
    62 matching CVEs in the corpus
  • nginx1.24
    33 matching CVEs in the corpus
matched
  • 9.8
    critical
    CVE-2026-11387WordPress · named in affected systems

    Privilege escalation via account takeover in WordPress OTP plugin

  • 9.1
    critical
    CVE-2026-84939Apache · found in the analysis

    Locale-based path traversal in Apache FreeMarker enabling arbitrary template access and possible RCE

  • 8.8
    high
    CVE-2026-43503Linux kernel · named in affected systems

    Linux kernel frag-transfer frag-marker bug enables local privilege escalation

  • 8.8
    high
    CVE-2026-19633PostgreSQL · found in the analysis

    PostgreSQL Anonymizer privilege escalation allows arbitrary code execution.

  • 8.8
    high
    CVE-2026-1580nginx · named in affected systems

    Ingress-nginx auth-method annotation can inject config, enabling RCE and secret exposure.

  • 8.7
    high
    CVE-2026-68489Node.js · found in the analysis

    Authenticated RCE as root via vulnerable Plesk Ruby & Node.js Toolkit extensions.

+add a technologyversion optional

One row per technology, showing its most recent match. Across the six rows the matcher returns 1,103 matches — 162 of them because the disclosure named the technology outright, the rest because we recognised it anyway. Free accounts track two technologies; Premium and Max are unlimited.

agentless, precisely

There is nothing to install.

what a network scanner needs first
  • An agent installed on every host
    and a rollout plan for the next version of it
  • Credentials privileged enough to read package state
    stored somewhere, rotated by someone
  • A scan window operations will sign off
    authenticated scans are not free at runtime
  • Network reachability into every segment
    including the ones deliberately unreachable
  • Maintenance of the scanner itself
    it becomes one more thing you patch
what this needs

A list of the technologies you run.

Versions if you know them. No agent, no credentials, no inbound access, no scan window, nothing running on your machines. Matching happens server-side against every incoming disclosure.

time to first match
as long as it takes to type six names
where a scanner wins

A scanner discovers the host nobody told you about. This does not. It only knows what you declare, so an inventory that is wrong produces alerts that are wrong. That is the honest trade: a scanner audits reality and costs you a deployment; this watches your description of reality and costs you a text field. Plenty of teams should run both — but only one of them is working five minutes from now.

matching breadth

A thin vendor product list should not cost you the alert.

Plenty of disclosures never enumerate what they break. The advisory names a plugin, a library, a distribution — and the technology you actually operate appears nowhere in the structured product list.

So matching does not stop at CPE-style product names. It reads three things: the CVE’s own affected-systems list, the sector tags the analyser assigns, and the analysed summary and impact text. The text is matched on word boundaries, so php never trips phpmyadmin.

named outrightfound anyway
  • WordPress124 named · 357 found anyway
    481
  • Linux kernel31 named · 312 found anyway
    343
  • Apache0 named · 120 found anyway
    120

Same scale across all three rows, counted with the matcher the product actually runs. At least one of these technologies is named outright by no disclosure at all — every one of its matches arrives through the analysed text.

a technology row
technology
PostgreSQL
version
16
The version field is optional and can stay empty for as long as you like.

Versions, honestly.

Record the release you are on and it travels with the technology — into the dashboard, into the PDF report, and out through the API. When a disclosure lands, the release you recorded sits right beside it, so checking it against the advisory takes a glance rather than a hunt through your own inventory.

What a version does not do is silently delete a CVE from your list. Matching is by technology name, so a rollout you have not finished cannot quietly hide a disclosure from you. We would rather show you one you have already patched than withhold one you have not.

downstream

Your stack is the single input.

Change the list once and everything downstream follows — the same definition of relevance decides what reaches your inbox, what fills the heatmap and what gets scored. There is no second place to keep this in sync.

The same matcher decides what you see in the dashboard and what gets sent to your inbox — one definition of relevance.

Six names and you are matching.

Add the technologies you run and the matcher starts on the next disclosure that arrives. Nothing to install, nothing to schedule, nothing to hand over.