Ross ROSS = Recommend OSS · open-source software intelligence for agents

opencve/opencve

Vulnerability Intelligence Platform observed · 2026-08-28

github.com/opencve/opencve · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 97
  • Release rhythm 86
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 88.0
  • age_days: 2169
  • days_rel: 19
  • days_push: 19
  • n_releases_24m: 7

Full methodology

Adoption not part of the score

2810 stars · 336 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

OpenCVE is a self-hostable Vulnerability Intelligence Platform that aggregates CVE data from sources like MITRE, NVD, CISA KEV, Vulnrichment, and RedHat. It lets security teams search, filter, tag, and organize vulnerabilities, subscribe to vendors and products, track remediation with assignments and statuses, and receive alerts via email, webhook, or Slack.

Use cases

  • monitor new CVEs affecting my vendors and products
  • filter vulnerabilities by CVSS, EPSS, KEV, or CWE
  • receive alerts when a CVE is added or updated
  • track remediation status of vulnerabilities across a team
  • generate daily CVE reports for my projects
  • self-host a CVE vulnerability management platform
  • integrate CVE alerts into my own tools via webhook or REST API

When to choose

  • you need a self-hosted platform to centralize and triage CVE monitoring for your organization
  • you want vendor/product subscriptions with change tracking and multi-channel notifications
  • you need team collaboration features like CVE assignment, statuses, tags, and projects

When to avoid

  • you only need a one-off CVE lookup or raw NVD data feed without a full platform
  • you want a lightweight CLI scanner rather than a web application with database infrastructure
  • you require AI-powered CVE analysis and remediation insights, which are only in the hosted Cloud edition

Facets

application · maturity active

security monitoring alerting search-engine web-framework api-framework workflow-automation webhook security self-hosted developer-tools python self-hosted cve vulnerability-management vulnerability-intelligence nvd mitre cybersecurity infosec django triage cvss epss kev automation web-server docker linux

5 sources

Member repositories

RepositoryRoleHealth v2
opencve/opencvemain94

For agents

markdown · JSON · MCP: product_card(name="opencve/opencve")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem