OpenCVE aggregates major vulnerability feeds (MITRE, NVD, RedHat, CISA, etc.) into a continuously updated repository with granular filtering by vendor, product, CVSS, EPSS, KEV, CWE, and custom tags. It provides project‑based dashboards, role‑based assignment workflows, real‑time alerts (email, Slack, webhook), AI‑generated daily risk summaries, and a REST API for integration, available as SaaS or on‑premise.
Funding
Funding not disclosed
Founders
Product
Problem
Security teams must ingest vulnerability data from numerous feeds (MITRE, NVD, RedHat, CISA, etc.), then manually filter, prioritize, and assign CVEs across disparate tools. This fragmented workflow leads to missed critical exposures, delayed remediation, and inefficient coordination among analysts.
Solution
OpenCVE consolidates all major vulnerability feeds into a single, continuously updated repository and provides granular filtering by vendor, product, CVSS, EPSS, KEV, CWE, and custom tags. Users can organize CVEs into independent projects with dedicated dashboards, assign ownership, and track each vulnerability through configurable lifecycle states. Real‑time alerts are delivered via email, Slack, or webhook, while an AI‑powered daily summary highlights the highest‑risk items. The platform exposes a RESTful API for seamless integration with SIEM, ITSM, and ticketing systems, and it is available both as a managed SaaS and an on‑premise open‑source deployment.
Target Audience
OpenCVE is designed for SecOps, vulnerability management, and SOC teams in enterprises, MSSPs, and regulated industries that need centralized CVE tracking and automated remediation workflows. It also serves ITSM and DevSecOps groups requiring programmatic access to vulnerability data.
Features
- Multi‑source aggregation engine pulling CVE data from MITRE, NVD, RedHat, CISA, Vulnrichment, and other feeds in near‑real time
- Advanced query builder supporting filters on vendor, product, CVSS, EPSS, KEV, CWE, and user‑defined tags
- Project‑based workspaces with customizable dashboards built from drag‑and‑drop widgets for status, priority, and assignee views
- Role‑based assignment workflow with configurable status fields and audit‑log tracking of all changes
- Multi‑channel notification system (email, Slack, webhook) with rule‑based routing for new or updated CVEs
- AI‑generated daily report summarizing critical exposures, trend analysis, and recommended actions
- REST API with rate‑limit tiers (100 / hour to unlimited) for integration with security orchestration platforms
- Export options (CSV, JSON) and built‑in CSV download for downstream reporting and compliance audits