# opencve/opencve

Vulnerability Intelligence Platform

Repository: https://github.com/opencve/opencve
Canonical: https://ross.abutalabs.com/products/opencve
Homepage: https://www.opencve.io
Language: Python
License: NOASSERTION
License Family: other
Topics: cve, vulnerabilities, security-tools, nvd, python, django, mitre, cybersecurity, infosec, vulnerability-management
Last push: 2026-08-14T09:25:04+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 97, release rhythm 86, longevity 100
- inputs: {"age_days": 2169, "days_push": 19, "days_rel": 19, "gap_med": 88.0, "n_releases_24m": 7}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2810, forks 336 (observed 2026-08-28T04:07:23.601624+00:00)

## What it is
OpenCVE is a self-hostable Vulnerability Intelligence Platform that aggregates CVE data from sources like MITRE, NVD, CISA KEV, Vulnrichment, and RedHat. It lets security teams search, filter, tag, and organize vulnerabilities, subscribe to vendors and products, track remediation with assignments and statuses, and receive alerts via email, webhook, or Slack.

## Use cases
- monitor new CVEs affecting my vendors and products
- filter vulnerabilities by CVSS, EPSS, KEV, or CWE
- receive alerts when a CVE is added or updated
- track remediation status of vulnerabilities across a team
- generate daily CVE reports for my projects
- self-host a CVE vulnerability management platform
- integrate CVE alerts into my own tools via webhook or REST API

## When to choose
- you need a self-hosted platform to centralize and triage CVE monitoring for your organization
- you want vendor/product subscriptions with change tracking and multi-channel notifications
- you need team collaboration features like CVE assignment, statuses, tags, and projects

## When to avoid
- you only need a one-off CVE lookup or raw NVD data feed without a full platform
- you want a lightweight CLI scanner rather than a web application with database infrastructure
- you require AI-powered CVE analysis and remediation insights, which are only in the hosted Cloud edition

## Facets
- artifact type: application
- maturity: active
- function: security, monitoring, alerting, search-engine, web-framework, api-framework, workflow-automation, webhook
- domain: security, self-hosted, developer-tools
- platform: python, self-hosted
- tags: cve, vulnerability-management, vulnerability-intelligence, nvd, mitre, cybersecurity, infosec, django, triage, cvss, epss, kev, automation, web-server, docker, linux

## Member repositories
- opencve/opencve (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:23.601624+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T08:14:24.071329+00:00, confidence not recorded.
  - readme: https://github.com/opencve/opencve (fetched 2026-08-28T04:07:23.601624+00:00, sha 0815f09d4f9b)
  - homepage: https://www.opencve.io (fetched 2026-08-29T09:54:23.556602+00:00, sha afef8b8d1eca)
  - site_page: https://docs.opencve.io/ (fetched 2026-08-29T09:54:23.565943+00:00, sha 2a68366e068e)
  - site_page: https://www.opencve.io/about (fetched 2026-08-29T09:54:23.567767+00:00, sha b0030c9c00e0)
  - registry_pypi: https://pypi.org/pypi/opencve/json (fetched 2026-08-29T09:54:23.569411+00:00, sha 7e1258135c9c)
- Data as of 2026-08-30T08:39:29.467469+00:00.
