Live data
Linux CVE tracker - the feed Noxen scans against
Noxen ships a daily-rebuilt vulnerability snapshot sourced from NVD and OSV.dev (Debian, Ubuntu, Rocky Linux, AlmaLinux). The numbers below are live - they're what the production manifest endpoint is reporting right now, fetched directly from the feed CDN.
- Total CVE records Loading…
- Last build Loading…
- Snapshot size Loading…
- Snapshot date Loading…
Sources
Where the data comes from
The feed is a unioned, deduped index across the upstream sources listed below. Each row's count is from the latest build.
| Source | What it covers | Records (live) |
|---|---|---|
| NVD | NIST's National Vulnerability Database, fetched directly from the NVD 2.0 API | Loading… |
| OSV.dev | Distro-specific backport tracking for Debian, Ubuntu, Rocky Linux, and AlmaLinux | Loading… |
Trust
How you can verify what's served
Every snapshot is signed with Ed25519. The Mac app verifies the manifest's signature against a bundled public key before importing any record. Sources are mirrored, not interpreted - Noxen never re-scores or fabricates CVE data.
-
Public key
6GP2QJveFk90XWEdWn86AXY5h7CjnrV1LnfhjdlCgO8= - Manifest URL feed.noxen.app/manifest.json
- Signing algorithm Ed25519 over canonicalised JSON (sorted keys at every level)
- Snapshot format Gzipped NDJSON (one JSON record per line, LF-delimited)
Live listings
Top recent critical CVEs
The most-recently-published critical-severity CVEs in the feed, deduped to one row per CVE ID, newest first. Refreshed when the feed itself rebuilds.
Top recent high-severity CVEs
Same shape as the critical list, one severity bucket down. High-CVSS findings still demand attention but typically allow a normal patch-cycle response.
Quick reference
Featured CVE reference cards
Per-CVE pages with affected versions, fix paths, scan commands, and links to the deep-dive blog post for the CVEs most relevant to homelabs.
- Dirty Frag - CVE-2026-43284 / CVE-2026-43500Linux kernel LPE via shared paged skb frags (xfrm + rxrpc) - public PoC →
- CVE-2024-47176 - CUPS cups-browsedUnauthenticated RCE chain via mDNS printer discovery (4-CVE chain) →
- CVE-2024-23897 - Jenkins CLIArbitrary file read → RCE via @file arg expansion (KEV) →
- CVE-2024-9264 - Grafana SQL ExpressionsAuthenticated Viewer-role RCE via DuckDB system() exposure →
- CVE-2024-21626 - runc "Leaky Vessels"Container breakout via internal fd handle leak (Docker, LXC, Proxmox) →
- CVE-2024-4577 - PHP-CGI argument injectionPre-auth RCE via Best-Fit encoding bypass (KEV, Akira weaponised) →
- CVE-2024-6387 - regreSSHionOpenSSH pre-auth RCE - fix versions and scan check →
- CVE-2024-3661 - TunnelVisionDHCP option 121 abuse leaks VPN traffic to the LAN →
- CVE-2024-3094 - xz/liblzma backdoorSupply-chain backdoor in xz-utils 5.6.0/5.6.1 →
- CVE-2024-1086 - nf_tables UAF (LPE)Linux kernel use-after-free, KEV-listed - the stage-2 multiplier →
- CVE-2023-4863 - libwebp heap overflowBundled-library RCE in Chromium / Electron / Plex / HA →
- CVE-2022-3602 - OpenSSL X.509 (4-byte)OpenSSL 3.0 punycode buffer overflow →
- CVE-2022-3786 - OpenSSL X.509 (1-byte)Companion OpenSSL 3.0 overflow →
By distribution
What Noxen tracks per distro
Per-ecosystem dashboards with the same headline numbers, framed for each distro.
- Ubuntu 24.04 LTSCVE coverage for Ubuntu 24.04 →
- Ubuntu 22.04 LTSCVE coverage for Ubuntu 22.04 →
- Ubuntu 20.04 LTSCVE coverage for Ubuntu 20.04 (ESM-aware) →
- Debian 13 TrixieCVE coverage for Debian 13 →
- Debian 12 BookwormCVE coverage for Debian 12 →
- Debian 11 BullseyeCVE coverage for Debian 11 (LTS) →
- AlmaLinux 9CVE coverage for AlmaLinux 9 →
- AlmaLinux 8CVE coverage for AlmaLinux 8 →
- Rocky Linux 9CVE coverage for Rocky 9 →
- Rocky Linux 8CVE coverage for Rocky 8 →
Frequently asked
What sources does the Noxen CVE feed pull from?
NIST's NVD as the primary CVE source (fetched directly from the NVD 2.0 API) and OSV.dev for distro-specific backport tracking across Debian, Ubuntu, Rocky Linux, and AlmaLinux.
How often is the CVE feed updated?
The feed rebuilds daily. Each rebuild fetches the latest records from every upstream source, deduplicates across them, and publishes a fresh signed snapshot. Noxen subscribers get the daily refresh; the free tier receives a snapshot per Sparkle release.
How is severity computed for each CVE?
In precedence order: (1) the distro's own triage label from OSV (Ubuntu/Debian severity strings), (2) CVSS v3.x vector parsed into a 0.0–10.0 base score and bucketed into critical/high/medium/low, (3) database_specific.severity as a final fallback. Noxen never re-scores or fabricates severity.
What does 'last_affected' mean on a CVE row?
OSV records that don't yet have a published fix version use a 'last_affected' event to mark the latest known-vulnerable version. Noxen surfaces this with a '+next' suffix on the fix-in column - the fix landed somewhere after the listed version, but the precise fix version isn't yet in upstream data.
How can I verify the feed I downloaded is authentic?
The manifest at feed.noxen.app/manifest.json is signed with Ed25519. The Mac app verifies this signature against a bundled public key (6GP2QJveFk90XWEdWn86AXY5h7CjnrV1LnfhjdlCgO8=) before importing any record. The snapshot itself has a SHA-256 hash in the manifest that's verified post-download.
Is the feed free to use programmatically?
The /feed/summary and /feed/digest endpoints on metrics.noxen.app are publicly accessible, with CORS allow-origin set to https://noxen.app for browser fetches. The full snapshot on feed.noxen.app is fetched by the Noxen Mac app under the terms of use; commercial mirroring requires permission.
Want to scan your fleet?
Noxen matches this feed against your installed package versions over SSH. Mac-native. Agentless. $12/month.
If you are not yet sure what the fleet is, that question comes first: a CVE feed can only be matched against hosts you know about. PingKit's port scanner - a separate product from the same maker - answers what is listening on your network, which is the step before asking what is vulnerable. Noxen can also sweep your subnet itself during LAN discovery.