Main feeds

Latest CVEs

Most recently published & modified CVEs.

feed.xml

New CVEs only

Only entries published since the last build. Ideal for alerts.

feed-new.xml

Critical severity

High & Critical CVSS only. Low volume, high impact.

feed-critical.xml

Feeds by product

We publish per-product RSS feeds for hundreds of technologies — Linux, Kubernetes, Chrome, PostgreSQL, and more.

Browse all feeds →

Each product also has a -severe.xml variant with only High & Critical CVEs, plus end-of-life feeds and calendar files where applicable.

Browser extension

Our free browser extension auto-detects CVE IDs on any web page (GitHub, Jira, Confluence, Slack…) and links them to NVD. Works with dynamically loaded content.

Install for Chrome Install for Firefox

Free tier: auto-linkify + right-click lookup. Pro: hover tooltips, KEV badges, CVE count, product lifecycle (EOL) lookup.

How it works

  1. We fetch CVE data from NVD multiple times a day.
  2. Each CVE is auto-tagged by product using pattern matching.
  3. RSS feeds are rebuilt — subscribe and get updates in your preferred reader.

Data sources: NVD, CISA KEV, endoflife.date. All CVE links point directly to NVD.