Free · no card
Free CVE email alerts for the vendors you actually run.
VulniPulse watches 32 official vendor advisory sources and emails you the ones that match your rules. No scanner, no agent, no card — a published advisory, matched to a product family you told us you run, with the CVEs and fixed versions the vendor stated.
- Vendor sources monitored
- 32
- Advisories tracked today
- 5,338
- Listed in CISA KEV
- 89
How it works
Three steps, then it is quiet
- 01
Pick what you run
Add a rule for a whole vendor, or narrow it to one platform — FortiGate rather than all of Fortinet, ESXi rather than all of VMware. Rules are saved to your account; drafts work before you sign up.
- 02
VulniPulse reads the official source
Each vendor's own PSIRT feed, bulletin index or CSAF endpoint is polled on a schedule and normalised into one record: severity, CVEs, affected and fixed versions, mitigations, CISA KEV status.
- 03
You get the match, not the firehose
When a newly ingested advisory matches a rule, it is emailed to your verified address. Choose all severities, high and critical only, or critical only per rule.
The alert
What lands in your inbox
- Vendor advisory title and its official URL
- CVE identifiers and vendor severity
- Affected and fixed releases as the vendor stated them
- CISA KEV listing and exploitation status when present
- A link to the normalised advisory page with the full record
Other ways to receive it
Email is not the only channel
- The Android app delivers the same matches as phone notifications, with the lifecycle checker built in.
- RSS for the whole feed, or one vendor at a time with
/feed.xml?vendor=fortinet. - Per-rule severity: every advisory, high and critical only, or critical only — set on each rule in your watchlist.
Be clear about it
What this is not
It reports, it does not block
VulniPulse tells you an advisory was published and what it affects. It does not patch, virtual-patch, scan or prevent exploitation — the fix is still the vendor's update.
Matching is by vendor and platform, not by your asset list
A rule matches the products a vendor names in the advisory. It does not know which build you are running unless you tell it, so treat a match as "check this", not "you are exploited".
The vendor page is authoritative
Every record links back to the source it was read from. Where a vendor publishes nothing — no fixed version, no date — the record says so instead of filling the gap.
Coverage
32 vendor sources you can build a rule on
Each name links to that vendor's tracked advisories and, where the vendor publishes lifecycle dates, to its end-of-support data. Vendor names are their owners' trademarks and appear here to say whose advisories are tracked — nothing more.
- Apache Software Foundation
- Atlassian
- Check Point
- Cisco
- Commvault
- Docker
- F5
- Fortinet
- GitLab
- HPE Aruba Networking
- Ivanti
- Juniper Networks
- Microsoft Server
- MikroTik
- NetApp
- Netgate pfSense
- NETGEAR
- NetScaler (Citrix)
- Omnissa (ex-VMware EUC)
- Palo Alto Networks
- Proxmox
- QNAP
- Red Hat Linux
- SonicWall
- Sophos
- Splunk
- Synology
- Ubiquiti
- Veeam
- VMware (Broadcom)
- WatchGuard
- Zyxel
Also useful: the end-of-life checker, the multi-vendor monitoring guide and how matching works.
Reference
Questions people ask first
Are the CVE email alerts really free?
Yes. Every supported vendor and platform is included at no cost, there is no card and no paid tier. You need a VulniPulse account with a verified email address so there is somewhere to deliver the alerts.
Can I get alerts for just one product instead of a whole vendor?
Yes. A rule can be scoped to a single platform — for example FortiGate, PAN-OS, ESXi or Junos — so a vendor's advisories for other product lines do not reach you.
How quickly does an alert arrive after a vendor publishes?
Direct vendor feeds are checked continuously; sources that rate-limit are polled on a slower, safe cadence. An alert is sent once the advisory has been ingested, normalised and matched to your rule.
Can I get the same feed without email?
Yes. Every advisory feed is available as RSS, including per-vendor feeds at /feed.xml?vendor=<slug>, and the Android app can deliver phone notifications instead of, or alongside, email.
Does an alert mean I am vulnerable?
No. It means a vendor published an advisory affecting a product family you asked about. Confirm your installed release against the affected and fixed versions in the linked vendor advisory before acting.
Start with one rule for the vendor you care about most.
Draft rules work before you sign in and transfer to your account when you do.