Live data

Linux CVE tracker - the feed Noxen scans against

Noxen ships a daily-rebuilt vulnerability snapshot sourced from NVD and OSV.dev (Debian, Ubuntu, Rocky Linux, AlmaLinux). The numbers below are live - they're what the production manifest endpoint is reporting right now, fetched directly from the feed CDN.

  • Total CVE records Loading…
  • Last build Loading…
  • Snapshot size Loading…
  • Snapshot date Loading…

Sources

Where the data comes from

The feed is a unioned, deduped index across the upstream sources listed below. Each row's count is from the latest build.

Source What it covers Records (live)
NVD NIST's National Vulnerability Database, fetched directly from the NVD 2.0 API Loading…
OSV.dev Distro-specific backport tracking for Debian, Ubuntu, Rocky Linux, and AlmaLinux Loading…

Trust

How you can verify what's served

Every snapshot is signed with Ed25519. The Mac app verifies the manifest's signature against a bundled public key before importing any record. Sources are mirrored, not interpreted - Noxen never re-scores or fabricates CVE data.

Live listings

Top recent critical CVEs

The most-recently-published critical-severity CVEs in the feed, deduped to one row per CVE ID, newest first. Refreshed when the feed itself rebuilds.

Loading…

Top recent high-severity CVEs

Same shape as the critical list, one severity bucket down. High-CVSS findings still demand attention but typically allow a normal patch-cycle response.

Loading…

Want to know what an attacker would chain? Read our plain-English glossary of CVE/CVSS/CWE/CPE for the vocabulary that makes these listings useful.

Quick reference

Featured CVE reference cards

Per-CVE pages with affected versions, fix paths, scan commands, and links to the deep-dive blog post for the CVEs most relevant to homelabs.

By distribution

What Noxen tracks per distro

Per-ecosystem dashboards with the same headline numbers, framed for each distro.

Frequently asked

What sources does the Noxen CVE feed pull from?

NIST's NVD as the primary CVE source (fetched directly from the NVD 2.0 API) and OSV.dev for distro-specific backport tracking across Debian, Ubuntu, Rocky Linux, and AlmaLinux.

How often is the CVE feed updated?

The feed rebuilds daily. Each rebuild fetches the latest records from every upstream source, deduplicates across them, and publishes a fresh signed snapshot. Noxen subscribers get the daily refresh; the free tier receives a snapshot per Sparkle release.

How is severity computed for each CVE?

In precedence order: (1) the distro's own triage label from OSV (Ubuntu/Debian severity strings), (2) CVSS v3.x vector parsed into a 0.0–10.0 base score and bucketed into critical/high/medium/low, (3) database_specific.severity as a final fallback. Noxen never re-scores or fabricates severity.

What does 'last_affected' mean on a CVE row?

OSV records that don't yet have a published fix version use a 'last_affected' event to mark the latest known-vulnerable version. Noxen surfaces this with a '+next' suffix on the fix-in column - the fix landed somewhere after the listed version, but the precise fix version isn't yet in upstream data.

How can I verify the feed I downloaded is authentic?

The manifest at feed.noxen.app/manifest.json is signed with Ed25519. The Mac app verifies this signature against a bundled public key (6GP2QJveFk90XWEdWn86AXY5h7CjnrV1LnfhjdlCgO8=) before importing any record. The snapshot itself has a SHA-256 hash in the manifest that's verified post-download.

Is the feed free to use programmatically?

The /feed/summary and /feed/digest endpoints on metrics.noxen.app are publicly accessible, with CORS allow-origin set to https://noxen.app for browser fetches. The full snapshot on feed.noxen.app is fetched by the Noxen Mac app under the terms of use; commercial mirroring requires permission.

Want to scan your fleet?

Noxen matches this feed against your installed package versions over SSH. Mac-native. Agentless. $12/month.

If you are not yet sure what the fleet is, that question comes first: a CVE feed can only be matched against hosts you know about. PingKit's port scanner - a separate product from the same maker - answers what is listening on your network, which is the step before asking what is vulnerable. Noxen can also sweep your subnet itself during LAN discovery.