Self-hosted · Agentless · AGPL-3.0

Agentless CVE scanning and fleet remediation for Linux hosts, over SSH.

Findings are ranked by what is being exploited, not just by what scores highest. When CveDeck doesn't know something, it tells you it doesn't know.

The CveDeck fleet overview in demo mode: triage cards for exploited, critical and high findings and hosts needing attention, above a table of fictional hosts such as app-alma.lan and db-primary.lan.
Demo mode, with a fictional fleet and scanning disabled. The intel feeds were never loaded in this instance, so the dashboard says so, and the exploitation column shows a dash, not a zero.
Scope

Limits, stated plainly

Linux only

Windows hosts can be discovered and enrolled, but scans are refused, because Windows inventory can't be matched against vulnerability data yet. A scan would finish with no findings, and that would look like a clean host.

You stay in control

CveDeck never runs commands on your hosts. Upgrade commands are generated for you to review, and there are no scheduled scans or automated remediation.

No built-in authentication

Keep it on a trusted network, or behind a reverse proxy with access control and TLS. Read the security notes.