CVE Alerts
Watch NVD, CISA, and vendor advisories for the stack you run. Not every CVE on earth.

CVE alerts watch NVD, CISA, and vendor advisories for the products you actually run.
A generic CVE firehose is how security inboxes die. NVD publishes constantly. Most of those IDs are not in your cluster. The ones that are in your cluster show up on a vendor page, a GitHub advisory, or a CISA note, and then exploit chatter follows. You want that short list, in language a human can patch from, before the morning standup.
Scope it to the stack
Name the products. Node, nginx, PostgreSQL, your Linux image, the one Java library you cannot replace. Paste the vendor security URL if it exists. Add a topic for "critical CVE or advisory affecting those names." Do not ask for every CVSS 4 in existence. You will mute it. The longer guide is CVE and security vulnerability alerts.
AyeWatch watches the public pages and topics you name. It is not a complete NVD subscription and it does not promise every CVE will hit your feed. Pair it with the scanner you already run. This is the public-web layer. GitHub tags still belong on release alerts. License surprises belong on license monitoring.
How to set the watch
URL watch on nvd.nist.gov search pages is brittle. Prefer the vendor advisory index plus a topic that states the product names and "critical or high severity." Write "ignore scanner marketing and course ads." Push for critical. Slack or email for the rest. Free Preview is six lifetime runs across three topics. Pro is $9 a month. Paid webhooks can page the on-call. See webhook pipelines.
Start a monitor in under a minute
Free Preview is six lifetime runs across three topics. No card.
Try AyeWatch freeWhat AyeWatch is not
It is not Tenable. It is not a container scanner. It is not a guaranteed mirror of NVD. If your auditor wants a signed feed from NIST, buy that feed. If you want a ping when a public advisory for OpenSSL or your PaaS shows up in words you can read, a topic on those pages is the job.
One product first
Start with the runtime you patch most slowly. Watch its advisory page for a week. If an alert names a CVE you would have caught only from Twitter, keep the topic and add the next vendor. Three Free Preview topics is enough for a small stack. Upgrade when the weekend advisory is the one that would have waited until Monday.