Self-hosted · Agentless · AGPL-3.0
Agentless CVE scanning and fleet remediation for Linux hosts, over SSH.
Findings are ranked by what is being exploited, not just by what scores highest. When CveDeck doesn't know something, it tells you it doesn't know.
Index
How it works
-
KEV → EPSS → CVSS
Prioritisation
Known exploitation outranks theoretical severity, so a fleet's hundreds of Highs sort into the few that matter this week. How findings are ranked -
Partial
Honest reporting
A scan whose data source failed is partial, never clean. Unchecked exploitation status is unknown, never "not exploited". What a result really means -
Linux over SSH
Distributions
Debian, Ubuntu, RHEL and derivatives, Alpine, openSUSE and more, matched against each distribution's own advisories. Supported distributions -
Self-hosted
Self-host
One container, one port, one data directory. Includes a demo mode with a fictional fleet and scanning disabled. Run it yourself
Scope
Limits, stated plainly
Linux only
Windows hosts can be discovered and enrolled, but scans are refused, because Windows inventory can't be matched against vulnerability data yet. A scan would finish with no findings, and that would look like a clean host.
You stay in control
CveDeck never runs commands on your hosts. Upgrade commands are generated for you to review, and there are no scheduled scans or automated remediation.
No built-in authentication
Keep it on a trusted network, or behind a reverse proxy with access control and TLS. Read the security notes.