patchletter vs. OpenCVE
OpenCVE is a CVE platform for security teams: it aggregates NVD, MITRE, CISA KEV and Red Hat, lets you subscribe to vendors and products and filter by CVSS/EPSS. There is a cloud version with a free entry tier and a self-hostable community edition.
patchletter takes a different angle. We follow the vendors' own release sources, pull in the demonstrably exploited flaws from CISA's KEV catalogue and record the end-of-support dates from endoflife.date. Whether you hear about it instantly, once a day or once a week is yours to set. The update radar costs nothing.
Side by side
| Feature | patchletter | OpenCVE |
|---|---|---|
| Release tracking for vendor products (Proxmox, FortiOS, Veeam …) | ✓ curated vendor sources: APIs, feeds, release-notes pages | ✗ |
| Actively exploited vulnerabilities (CISA KEV) | ✓ curated & low-noise — only demonstrably exploited CVEs; free to read, alert email with Pro | ✓ |
| End-of-life / support dates | ✓ endoflife.date data on every product page; warning email 90/30/7 days ahead with Pro | ✗ |
| Hardware / firmware (firewalls, NAS, switches) | ✓ | ✗ |
| Email instantly / daily / weekly | ✓ | ✓ |
| Slack / Teams / webhooks | partly Slack, Teams, webhook with Pro | ✓ |
| API | ✓ read-only REST API v1, free and without an account; plus an RSS feed per product | ✓ |
| Free to use | partly update emails free; security and EOL alerts with Pro | partly free tier is tightly limited (1 project); full features are paid |
When OpenCVE is the better choice
- A complete CVE database with hundreds of thousands of entries, CVSS/EPSS scoring and change history — patchletter deliberately shows only actively exploited CVEs (KEV).
- Webhooks and Slack integration for security workflows, plus team/project features on paid tiers.
- Self-hosting is available if data must stay on-premises.
Nothing wrong with running both: OpenCVE for its strengths, patchletter for the vendor gear it can’t see.
Tick off what you run
Confirm your address once, and after that an email arrives as soon as one of your vendors ships a new version. That is all we need.
Browse the catalogFacts about OpenCVE verified: 2026-08. Spotted something outdated? Let us know via the legal-notice contact. All product names are trademarks of their respective owners.