product image

Patchlight

$29/ month
14 day trial

Self-hosted CVE prioritisation — patch what's exploited, not what's loudest

40,000 CVEs a year. Five matter to you this week — Patchlight finds those five by matching every CVE to what you actually run, then ranking by real exploitation evidence.

Features

  • Inventory three ways: product+version (auto-resolved to CPE), raw CPE, or CycloneDX/SPDX SBOM
  • Ranking by CISA KEV (known exploited) + EPSS probability + CVSS, numbers shown for every ranking
  • The daily diff: new CVE hitting your stack or newly added to KEV surfaces as a change; patched ones auto-resolve
  • Every finding actionable: “patch to ≥ x.y.z” with exploit evidence attached
  • Air-gap ready: point -nvd/-kev/-epss-url at a local mirror (every tier)

Server requirements

  • Linux x86-64; single static binary or Docker
  • Measured: ~10 MB binary, ~10 MB RAM idle, SQLite file — no database server
  • Minimum host: 1 vCPU, 1 GB RAM; allow 1 GB disk for cached NVD/KEV/EPSS data
  • Dashboard 127.0.0.1:8425; outbound HTTPS to NVD, CISA KEV and FIRST EPSS (or your mirror) — never to us

Tiers. Free: 150 items, webhook + syslog alerts (GitHub, v0.1.2). Pro: 500 items, SBOM import, custom interval, email/Slack/Telegram. Team: unlimited, PagerDuty/MS Teams, priority support. 14-day trial.

Self-hosted; your inventory never leaves your network; offline activation, no phone-home.

Delivery. Automatic: key by Whop DM right after checkout; download in the Downloads tab.

Whop sells paid licences only. Free: github.com/nizartuanku/patchlight