Tool showcase / Self-hosted server
Simple CVE Tracker
A self-hosted server that watches public CVE feeds for vulnerabilities matching the vendors, products, and keywords you care about.
Built for
MSP technicians and small IT teams that need relevant vulnerability notices without watching the full public feed.
- Match keyword and vendor-product watchlists with optional CVSS thresholds
- Flag CISA KEV entries and enrich findings with NVD CVSS and FIRST EPSS data
- Show per-source synchronization health and support an immediate manual sync
- Send optional coalesced email alerts with a retry queue
Get it
Download the source tarball from GitHub Releases, then use Docker Compose, run from Python 3.11+, or install the included systemd service. The site does not select or serve a version-specific artifact.
Release evidence
GitHub’s build-provenance attestation can be checked against the project release artifact.
gh attestation verify simple-cve-tracker-vX.Y.Z.tar.gz --repo JDE-Projects/Simple-CVE-Tracker --signer-repo JDE-Projects/Build-ToolsLicense
PolyForm Noncommercial License 1.0.0