CVE catalogue · CISA KEV list

The vulnerabilities that concern you. Not the thousands of others.

CVEye matches the CVE catalogue and the CISA list of actively exploited flaws against what you actually run, and only alerts your team about what concerns it.

What concerns you last 24 h
CVE-2026-3187 log4j-core 2.14.1 EXPLOITED SBOM api 9.8
CVE-2026-3044 openssl 3.0.11 Watching: openssl 7.5
CVE-2026-2991 postgresql 16.1 SBOM api 5.4
137 CVEs were published that day. Three concerned you.
The problem

The CVE feed is not usable as it comes

Thousands of vulnerabilities are published every month. A handful touch your estate. Sorting them by hand is a full-time job — and the day one slips through, that is the one that gets you.

My watchlist
openssl product · immediate
postgresql product · immediate
apache vendor · digest 08:30
01 — Declare

Say what you run

A vendor, a specific product, or a keyword when the product is not in the catalogue yet. Each entry decides what reaches you — immediately, or in a digest at the hour you pick.

02 — Match

Or let your SBOM do the talking

Upload a CycloneDX file: CVEye reads your components, ties them to the catalogue and tells you which ones are affected. It counts what it could not tie separately, so an unassessed SBOM never passes for a clean one.

api.cdx.json 412 components
389 matched, monitored
23 unmatched, listed
log4j-core 2.14.1 3 CVEs
openssl 3.0.11 1 CVEs
guava 31.0
CVE tracking — my team
To review · 2
CVE-2026-3187 log4j-core
CVE-2026-3044 openssl
To handle · 1
CVE-2026-2991 Léa
In progress · 1
CVE-2026-2760 Marc
Handled · 12
CVE-2026-2455 redis · fixed
+ 11 more
03 — Handle

Your team handles it, not you alone

Every match opens a tracking record that moves through to a terminal status. Assignable to a teammate, annotable, and you see at a glance what is still open.

Actively exploited flaws

The ones that cannot wait until Monday

CVEye carries the CISA KEV catalogue — the vulnerabilities with confirmed exploitation in the wild. They rise to the top, flagged, with the expected remediation.

EXPLOITED CVE-2026-3187 ransomware confirmed
TRACKED CVE-2026-2991 assigned to Léa
AI assistant

Ask your estate a question

CVEye opens up to an AI assistant that works on your own data, after your explicit authorization, and only ever sees what you see yourself. That assistant is Sherlox, a XEFI product — contact your nearest XEFI agency to enable it.

sherlox.fr

Do we use log4j anywhere?

Yes, log4j-core 2.14.1 in the “api” SBOM. Three CVEs concern it, one of them in the KEV catalogue.

Start with a single watchlist entry

Declare one product you run. If a CVE touches it this week, you will know before anyone else.

Create an account