Tool showcase / Self-hosted server

Simple CVE Tracker

A self-hosted server that watches public CVE feeds for vulnerabilities matching the vendors, products, and keywords you care about.

PolyForm Noncommercial License 1.0.0

Open GitHub ReleasesView source

Simple CVE Tracker dashboard in light and dark appearance.

Built for

MSP technicians and small IT teams that need relevant vulnerability notices without watching the full public feed.

  • Match keyword and vendor-product watchlists with optional CVSS thresholds
  • Flag CISA KEV entries and enrich findings with NVD CVSS and FIRST EPSS data
  • Show per-source synchronization health and support an immediate manual sync
  • Send optional coalesced email alerts with a retry queue

Get it

Download the source tarball from GitHub Releases, then use Docker Compose, run from Python 3.11+, or install the included systemd service. The site does not select or serve a version-specific artifact.

GitHub Releases

Release evidence

GitHub’s build-provenance attestation can be checked against the project release artifact.

gh attestation verify simple-cve-tracker-vX.Y.Z.tar.gz --repo JDE-Projects/Simple-CVE-Tracker --signer-repo JDE-Projects/Build-Tools

License

PolyForm Noncommercial License 1.0.0

Source repository