SOC status:Duty analyst on shift

UK Cyber Defence

Tools / CVE Watchlist

Only the CVEs that are yours.

395,631 CVEs, a few hundred more every day, and perhaps a dozen that touch what you actually run. Tell this page what that is, or paste an inventory export, and it becomes a page that shows only those: new CVEs, additions to CISA’s known-exploited list, and EPSS scores that have jumped. Bookmark it, subscribe to its feed, or have it emailed.

Free text is matched against NVD’s vendor and product names; versions are ignored. A vendor on its own watches everything they make. Up to 60 entries.

Free · No account · Shareable link · RSS

What you get

A page that is yours

Every CVE for your products with CVSS, EPSS and KEV side by side, newest first, and a change log of what moved this week and this month. The link is the credential: share it with the team, and anyone with it can edit the list.

An RSS feed

The same change log as a feed, so it lands in whatever your team already reads. Four kinds of item: new CVE, newly scored, added to KEV, EPSS jump.

An email digest, if you want one

Weekly on Monday morning or daily when something changed, with KEV additions at the top. Double opt-in, one-click unsubscribe, and nothing is sent when nothing happened.

Matching that forgives spelling

Free text is matched against NVD's vendor and product names, versions are ignored, a vendor on its own watches everything they make, and “windows server” means every Windows Server. Where a name is ambiguous the page shows what it matched and the alternatives.

Inventory paste

Paste an export from your asset register or RMM, one product per line, and the parser does the rest. Lines it cannot place are listed so you can fix them.

The same data as the explorer

NVD, FIRST EPSS and CISA KEV, refreshed daily by the jobs that feed the CVE Explorer. Nothing is scraped from the pages you watch.