← All use cases security-ops

CVE and vulnerability feeds

New and actively exploited CVEs and vendor advisories, polled and deduplicated into one live event stream.

Tracks newly disclosed and actively exploited vulnerabilities from vendor security research teams and advisory publishers. Feeds from Zero Day Initiative, Rapid7, Tenable, Qualys, Cisco Talos, and security news outlets are polled and deduplicated so each new CVE, advisory, or patch note becomes a single event. Built for security engineers and vulnerability management teams who need to know the moment a bug moves from disclosed to exploited.

What you'll watch

The real sources this template sets up for you.

  • Zero Day Initiative: published advisories https://www.zerodayinitiative.com/rss/published/
    Feed every 6h
  • Rapid7 cybersecurity blog https://www.rapid7.com/blog/rss/
    Feed every 6h
  • Tenable blog https://www.tenable.com/blog/feed
    Feed every 6h
  • Cisco Talos blog https://blog.talosintelligence.com/rss/
    Feed every 6h
  • Qualys security blog https://blog.qualys.com/feed
    Feed every 12h
  • SANS Internet Storm Center https://isc.sans.edu/rssfeed_full.xml
    Feed every 6h
  • SecurityWeek https://www.securityweek.com/feed/
    Feed every 6h
  • BleepingComputer https://www.bleepingcomputer.com/feed/
    Feed every 6h

Included alerts

Boolean matches that fire on the sources above.

  • Actively exploited vulnerabilities "actively exploited" OR "in the wild" OR zero-day OR "exploited in"
  • Critical remote code execution "remote code execution" OR RCE OR unauthenticated OR critical
  • New CVE identifiers and PoCs CVE OR "proof of concept" OR PoC OR advisory

Wire up your first source in minutes

Point Hypeline at any feed, page, or push source and get one clean stream of real changes.

Free to start. No credit card required.