Tools / CVE Watchlist
Only the CVEs that are yours.
395,626 CVEs, a few hundred more every day, and perhaps a dozen that touch what you actually run. Tell this page what that is, or paste an inventory export, and it becomes a page that shows only those: new CVEs, additions to CISA’s known-exploited list, and EPSS scores that have jumped. Bookmark it, subscribe to its feed, or have it emailed.
What you get
A page that is yours
Every CVE for your products with CVSS, EPSS and KEV side by side, newest first, and a change log of what moved this week and this month. The link is the credential: share it with the team, and anyone with it can edit the list.
An RSS feed
The same change log as a feed, so it lands in whatever your team already reads. Four kinds of item: new CVE, newly scored, added to KEV, EPSS jump.
An email digest, if you want one
Weekly on Monday morning or daily when something changed, with KEV additions at the top. Double opt-in, one-click unsubscribe, and nothing is sent when nothing happened.
Matching that forgives spelling
Free text is matched against NVD's vendor and product names, versions are ignored, a vendor on its own watches everything they make, and “windows server” means every Windows Server. Where a name is ambiguous the page shows what it matched and the alternatives.
Inventory paste
Paste an export from your asset register or RMM, one product per line, and the parser does the rest. Lines it cannot place are listed so you can fix them.
The same data as the explorer
NVD, FIRST EPSS and CISA KEV, refreshed daily by the jobs that feed the CVE Explorer. Nothing is scraped from the pages you watch.