patchletter vs. OpenCVE
OpenCVE is a CVE platform for security teams: it aggregates NVD, MITRE, CISA KEV and Red Hat, lets you subscribe to vendors and products and filter by CVSS/EPSS. There is a cloud version with a free entry tier and a self-hostable community edition.
patchletter takes a different angle: a free update radar for sysadmins that combines vendor release tracking, actively exploited vulnerabilities (CISA KEV) and end-of-life dates — delivered as one quiet email digest instead of a real-time firehose.
Side by side
| Feature | patchletter | OpenCVE |
|---|---|---|
| Release tracking for vendor products (Proxmox, FortiOS, Veeam …) | ✓ curated vendor sources: APIs, feeds, release-notes pages | ✗ |
| Actively exploited vulnerabilities (CISA KEV) | ✓ curated & low-noise — only demonstrably exploited CVEs | ✓ |
| End-of-life / support dates | ✓ endoflife.date data on every product page | ✗ |
| Hardware / firmware (firewalls, NAS, switches) | ✓ | ✗ |
| Email instantly / daily / weekly | ✓ | ✓ |
| Slack / Teams / webhooks | ✗ on the roadmap — patchletter is email-first | ✓ |
| API | partly RSS feed per product; API on the roadmap | ✓ |
| Free to use | ✓ completely free, no limits | partly free tier is tightly limited (1 project); full features are paid |
When OpenCVE is the better choice
- A complete CVE database with hundreds of thousands of entries, CVSS/EPSS scoring and change history — patchletter deliberately shows only actively exploited CVEs (KEV).
- Webhooks and Slack integration for security workflows, plus team/project features on paid tiers.
- Self-hosting is available if data must stay on-premises.
Nothing wrong with running both: OpenCVE for its strengths, patchletter for the vendor gear it can’t see.
Try patchletter — free
Pick the tools you run, confirm your email, get one email when something ships.
Browse the catalogFacts about OpenCVE verified: 2026-08. Spotted something outdated? Let us know via the legal-notice contact. All product names are trademarks of their respective owners.