// Vulnerability Directory
Every CVE we've remediated.
Filterable. RSS-subscribable. The patch cadence is public by design — not theatre.
0
Total CVEs
0
Critical
0
High
0
Remediated
Stay current on new CVEs
Subscribe via RSS or email to get notified when OSSeva ships a new CVE patch. High-intent signal — we don't email anything else without your consent.
Frequently asked questions
What is a CVE?
CVE (Common Vulnerabilities and Exposures) is the industry-standard system for publicly disclosing software vulnerabilities. Each CVE is assigned a unique identifier (e.g., CVE-2021-44228, the Log4Shell flaw), a CVSS score (0–10, with 10 being most critical), and a description of the vulnerability and affected versions. When a CVE is disclosed for an EOL runtime, the upstream project will not release a patch — which is exactly the gap OSSeva fills.
What is CVSS scoring?
CVSS (Common Vulnerability Scoring System) is a standardized framework for rating the severity of security vulnerabilities. Scores range from 0.0 to 10.0: Critical (9.0–10.0), High (7.0–8.9), Medium (4.0–6.9), Low (0.1–3.9). CVSS v3.1 and v4.0 are both in use. OSSeva prioritizes patch delivery by CVSS score: Critical CVEs receive a 72-hour SLA.
How quickly does OSSeva patch newly disclosed CVEs?
OSSeva monitors CVE disclosures continuously across all supported technologies. Critical CVEs (CVSS ≥ 9.0) are patched within 72 hours of confirmation. High CVEs (CVSS 7.0–8.9) are patched within 2 business weeks. Medium and low severity vulnerabilities are bundled into monthly releases. Customers are notified via Slack and email when a patch is available for their covered stack.
How do I subscribe to CVE alerts for my technology stack?
You can subscribe to OSSeva's CVE alert feed directly from this page using the email subscription form. Select the technologies in your stack and you will receive email notifications when OSSeva remediates a new CVE affecting your versions. Alerts include the CVE ID, CVSS score, affected versions, and a link to the full remediation entry.
Does OSSeva disclose CVEs it has patched?
Yes. OSSeva publishes every remediated CVE in our public vulnerability directory within 90 days of patch delivery, or sooner if the CVE is already public knowledge. The entry includes the CVE ID, affected technology and versions, CVSS score, a plain-language description, and the OSSeva patch reference. Customers receive advance notice before public disclosure.
What CVEs has OSSeva addressed for RabbitMQ, Kafka, and PostgreSQL?
The directory above is being rebuilt from upstream advisories, and entries are added only once the CVE identifier, affected version range, upstream fix version and OSSeva remediation status have each been checked against the source. That is a deliberate choice for a security vendor: an unverifiable CVE list is worse than no list. If you need to know whether a specific advisory affects a version you run, send us the identifier and we will answer it against your estate.