CVEDetails Alternative
CVEDetails is a reference lookup database: you search it for a vulnerability, a vendor or a product, in English. TechWatchAlert does the opposite: it starts from your components and alerts you when one of them is affected, in French, with end of support tracked. Two different uses, not two levels of quality.
In short, before you scroll
- Built and hosted in France
- Free plan, no credit card
- Publicly listed prices
- Export your data at any time
A CVE (Common Vulnerabilities and Exposures) is the public identifier of a vulnerability. Looking one up and receiving one are opposite actions: the first assumes you know what to look for, and when.
What CVEDetails is, exactly
CVEDetails aggregates data from the NVD and other sources into pages you can browse by CVE, by vendor and by product. It is a long-standing database, very well indexed by search engines, and free to read. It also offers email alerts (by vendor, product, version, KEV catalog listing or CNA), an API in NVD format by subscription, and custom RSS feeds.
Its core remains lookup: English interface, subscriptions declared by hand, paid subscription for the API.
Searching for a CVE, or being found by it
| Criterion | TechWatchAlert | CVEDetails |
|---|---|---|
| Stack targeting (CPE, SBOM) | Yes | Manual vendor / product subscriptions |
| Interface in French | French and English | English |
| End-of-life (EOL) tracking | Yes | No |
| KEV + EPSS prioritization in the alert | Yes | KEV visible, manual sorting |
| Email alerts | Yes | Yes |
| Slack, Teams, webhook, workflows | Yes | Email, RSS, API |
| REST API | Yes | Yes, by subscription |
| Searchable archive depth | In-app search | Yes |
| Data hosting | France | United States |
CVEDetails wins on archive depth. We win on everything related to targeted action: being alerted, in French, on the right scope, without having to maintain a list of subscriptions.
What CVEDetails does better than we do
The archive is deeper, and free. To trace a product’s full history, cross-reference older statistics or prepare an audit file, it is richer than our built-in search.
There is nothing to configure before you start reading. One URL, one search, one answer. No account, no stack to declare. For a one-off question, it is unbeatable.
The RSS feeds can be freely reused by any in-house tool. If you already have a processing pipeline, it is a simple input.
What we do differently
Your scope is not a list to maintain. On CVEDetails, you create one subscription per product and keep it up to date. With us, your declared stack, whether entered by hand, imported from an SBOM (the inventory of your components) or detected from a URL, acts as the filter, versions included.
The alert arrives already prioritized. Listing in KEV (confirmed exploitation, published by CISA), EPSS (probability of exploitation within 30 days), then CVSS (severity). In that order, because the third is the one most often wrong: most so-called critical CVEs are never exploited. The full reasoning is laid out in our guide to CVE monitoring.
End of support is tracked. CVEDetails does not cover this; yet a version that will no longer receive patches is a risk that never closes.
Everything is in French: interface, bulletins and support, with English as an option.
Data freshness, and the NVD backlog
Since February 2024, CVE enrichment by the NVD has slowed sharply: a large share of new vulnerabilities went months without full analysis, and therefore without a score or a usable product reference. Any service built solely on the NVD inherits that gap.
We cross-check seven feeds: CVE List, NVD, KEV, EPSS, published proofs of concept, GitHub advisories and OSV. That is what keeps us usable when one of them falls behind. For details, source by source and license by license, see data sources.
Who it's for, in practice
Analyst digging through twenty years of archives. CVEDetails remains built for this use. Our built-in search covers the same data, but it is designed to start from your stack, not for historical exploration.
Team running about ten components. The free plan is enough: stack declared once, email alerts, and no more subscription list to update whenever a version changes.
Team that wants to plug monitoring into its own tools. Slack or Teams for critical items, a daily digest for everything else, and the API for the rest of the pipeline. A practical tip: do not send everything to Slack, or notifications will be muted within a week.
Method and verification date
Facts checked on on the vendors’ public pages, without privileged access or real-world testing of their product. The alert, API and RSS feed features come from CVEDetails’ public documentation. Spotted an error or a change in offering? Report it via our contact page: we correct the row and re-date the page.