Vulnerability Intelligence

Stop manually checking for vulnerabilities

CVEPing monitors NVD, GitHub Advisory, and OSV.dev every 4 hours and pings you when new CVEs affect your stack. No agents. No code scanning. Just timely alerts.

Free tier available · No credit card required · 22+ technologies

How it works

📦

Pick your stack

Choose from 22 technologies or upload your composer.json / package.json to auto-detect everything.

🔍

We check every 4 hours

CVEPing polls NVD, GitHub Advisory, and OSV.dev. Each CVE is enriched with EPSS exploit probability scores.

🔔

Get pinged

Receive alerts via Email, Slack, Discord, or webhooks when critical or high-severity CVEs are published.

Platform Stats

CVEs Tracked
Critical
Technologies
Last Check

Updated automatically every 30 minutes to 4 hours depending on plan

22 technologies supported

PHP Language Node.js Language Python Language Go Language Rust Language Ruby Language Laravel Framework Symfony Framework Express Framework React Framework Django Framework WordPress Framework MySQL Database PostgreSQL Database MongoDB Database Redis Database Elasticsearch Database Nginx Infrastructure Apache HTTP Infrastructure Docker Infrastructure Kubernetes Infrastructure Apache Tomcat Infrastructure

Not another enterprise scanner

Others CVEPing
Subscribe to CPE vendor/product codes Click "PHP" or upload composer.json
New CVEs without CPE tags are silently missed Keyword + OSV.dev catches them
€19-49/month with complex setup Free tier, paid from €5/mo
Built for security teams with 50-page dashboards Built for developers who want a ping

What's included

EPSS Scoring

Each CVE shows real-world exploit probability from FIRST.org — know which vulnerabilities are actually being exploited, not just theoretically dangerous.

SBOM Import

Upload composer.json, package.json, requirements.txt, or Gemfile. Unmatched packages are auto-added as custom technologies on Dev+ plans.

3 Data Sources

NVD (NIST), GitHub Security Advisory, and OSV.dev — cross-referenced and deduplicated for comprehensive coverage.

Multi-channel Alerts

Email alerts on all plans. Slack (Dev+), Discord, and custom webhooks (Pro+). Configurable severity thresholds and real-time or digest delivery.

Status Tracking

Mark CVEs as patched, action required, monitoring, or dismissed. Filter by status to track your team's response to each vulnerability.

REST API + Custom Tech

Full filtering REST API for Pro+ users. Monitor any technology beyond the 22 built-in — add custom packages by NVD keyword.