patchletter vs. OpenCVE

OpenCVE is a CVE platform for security teams: it aggregates NVD, MITRE, CISA KEV and Red Hat, lets you subscribe to vendors and products and filter by CVSS/EPSS. There is a cloud version with a free entry tier and a self-hostable community edition.

patchletter takes a different angle. We follow the vendors' own release sources, pull in the demonstrably exploited flaws from CISA's KEV catalogue and record the end-of-support dates from endoflife.date. Whether you hear about it instantly, once a day or once a week is yours to set. The update radar costs nothing.

Side by side

FeaturepatchletterOpenCVE
Release tracking for vendor products (Proxmox, FortiOS, Veeam …)✓ curated vendor sources: APIs, feeds, release-notes pages✗
Actively exploited vulnerabilities (CISA KEV)✓ curated & low-noise — only demonstrably exploited CVEs; free to read, alert email with Pro✓
End-of-life / support dates✓ endoflife.date data on every product page; warning email 90/30/7 days ahead with Pro✗
Hardware / firmware (firewalls, NAS, switches)✓✗
Email instantly / daily / weekly✓✓
Slack / Teams / webhookspartly Slack, Teams, webhook with Pro✓
API✓ read-only REST API v1, free and without an account; plus an RSS feed per product✓
Free to usepartly update emails free; security and EOL alerts with Propartly free tier is tightly limited (1 project); full features are paid

When OpenCVE is the better choice

Nothing wrong with running both: OpenCVE for its strengths, patchletter for the vendor gear it can’t see.

Tick off what you run

Confirm your address once, and after that an email arrives as soon as one of your vendors ships a new version. That is all we need.

Browse the catalog

Facts about OpenCVE verified: 2026-08. Spotted something outdated? Let us know via the legal-notice contact. All product names are trademarks of their respective owners.