Tell us what you run.
We watch it for you.
Add the technologies in your estate — and optionally the versions — and every incoming CVE is matched against them. No agents to deploy, no scanner to schedule, nothing installed on your infrastructure.
Setup is a list of technology names. There is no step two.
Read from the corpus when this page was last built, refreshed hourly. Severity is bucketed on CVSS.
One list in.
Every matching disclosure out.
Left: six technologies, typed by hand, two of them without a version. Right: what those six actually match in the corpus — the counts and the CVEs below are read from the database, not illustrated. Nothing was installed to produce them.
- WordPress6.4481 matching CVEs in the corpus
- Linux kernel6.8343 matching CVEs in the corpus
- Apacheno version120 matching CVEs in the corpus
- Node.jsno version64 matching CVEs in the corpus
- PostgreSQL1662 matching CVEs in the corpus
- nginx1.2433 matching CVEs in the corpus
- 9.8criticalCVE-2026-11387← WordPress · named in affected systems
Privilege escalation via account takeover in WordPress OTP plugin
- 9.1criticalCVE-2026-84939← Apache · found in the analysis
Locale-based path traversal in Apache FreeMarker enabling arbitrary template access and possible RCE
- 8.8highCVE-2026-43503← Linux kernel · named in affected systems
Linux kernel frag-transfer frag-marker bug enables local privilege escalation
- 8.8highCVE-2026-19633← PostgreSQL · found in the analysis
PostgreSQL Anonymizer privilege escalation allows arbitrary code execution.
- 8.8highCVE-2026-1580← nginx · named in affected systems
Ingress-nginx auth-method annotation can inject config, enabling RCE and secret exposure.
- 8.7highCVE-2026-68489← Node.js · found in the analysis
Authenticated RCE as root via vulnerable Plesk Ruby & Node.js Toolkit extensions.
One row per technology, showing its most recent match. Across the six rows the matcher returns 1,103 matches — 162 of them because the disclosure named the technology outright, the rest because we recognised it anyway. Free accounts track two technologies; Premium and Max are unlimited.
There is nothing to install.
- An agent installed on every hostand a rollout plan for the next version of it
- Credentials privileged enough to read package statestored somewhere, rotated by someone
- A scan window operations will sign offauthenticated scans are not free at runtime
- Network reachability into every segmentincluding the ones deliberately unreachable
- Maintenance of the scanner itselfit becomes one more thing you patch
A list of the technologies you run.
Versions if you know them. No agent, no credentials, no inbound access, no scan window, nothing running on your machines. Matching happens server-side against every incoming disclosure.
A scanner discovers the host nobody told you about. This does not. It only knows what you declare, so an inventory that is wrong produces alerts that are wrong. That is the honest trade: a scanner audits reality and costs you a deployment; this watches your description of reality and costs you a text field. Plenty of teams should run both — but only one of them is working five minutes from now.
A thin vendor product list should not cost you the alert.
Plenty of disclosures never enumerate what they break. The advisory names a plugin, a library, a distribution — and the technology you actually operate appears nowhere in the structured product list.
So matching does not stop at CPE-style product names. It reads three things: the CVE’s own affected-systems list, the sector tags the analyser assigns, and the analysed summary and impact text. The text is matched on word boundaries, so php never trips phpmyadmin.
- WordPress124 named · 357 found anyway481
- Linux kernel31 named · 312 found anyway343
- Apache0 named · 120 found anyway120
Same scale across all three rows, counted with the matcher the product actually runs. At least one of these technologies is named outright by no disclosure at all — every one of its matches arrives through the analysed text.
Versions, honestly.
Record the release you are on and it travels with the technology — into the dashboard, into the PDF report, and out through the API. When a disclosure lands, the release you recorded sits right beside it, so checking it against the advisory takes a glance rather than a hunt through your own inventory.
What a version does not do is silently delete a CVE from your list. Matching is by technology name, so a rollout you have not finished cannot quietly hide a disclosure from you. We would rather show you one you have already patched than withhold one you have not.
Your stack is the single input.
Change the list once and everything downstream follows — the same definition of relevance decides what reaches your inbox, what fills the heatmap and what gets scored. There is no second place to keep this in sync.
The same matcher decides what you see in the dashboard and what gets sent to your inbox — one definition of relevance.
Six names and you are matching.
Add the technologies you run and the matcher starts on the next disclosure that arrives. Nothing to install, nothing to schedule, nothing to hand over.