Exposure discovery EU-developed
OpenCVE
Tracks published vulnerabilities for selected vendors and products, with CVE filtering, subscriptions, notifications and shared remediation tracking for security teams.
By Amber Security / OpenCVE project · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Exposure discovery
- Developer or maintainer
- Amber Security / OpenCVE project
- Recorded country
- France
- Product model
- Source available
- Deployment
- Self-hosted / SaaS
- Software license
- BUSL-1.1
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteOpenCVE identifies Amber Security SAS as its publisher; the French company describes OpenCVE as its own vulnerability-monitoring solution and lists its registered office in Lille.
Reported capabilities
- Vendor and product CVE subscriptions
- Risk filtering and notification workflows
- Docker deployment or hosted Cloud service
Scope and limits
The current Community code uses Business Source License 1.1, not an open-source license. Its additional grant restricts commercial security monitoring and alerting services for third parties; separate commercial terms may be needed. The inspected license names a 2030-08-14 change date to Apache-2.0 for that version. The hosted Cloud service has separate commercial terms; Cloud-only features are not assumed to be included in Community. This tracks disclosed CVEs and does not scan assets for vulnerabilities.
Inspect the research evidence 7 source observations
identity / capabilities
The upstream README describes a vulnerability-intelligence application with vendor/product subscriptions, CVE filters, notifications and team workflows; it separates Community from Cloud features.
Read sourceorigin
OpenCVE names its two creators and identifies the publisher as Amber Security SAS.
Read sourceorigin / country
Amber Security describes creating its OpenCVE solution and gives its French SAS registration and Lille office. This establishes the French publisher/steward, not every contributor location.
Read sourcelicense
Actual LICENSE text is Business Source License 1.1 with an additional-use restriction on providing commercial security monitoring and alerting services to third parties. It explicitly is not an open-source license; the inspected version changes to Apache-2.0 on 2030-08-14.
Read sourcedeployment
Current installation documentation describes a complete Docker stack and directs users to OpenCVE Cloud as the hosted option.
Read sourcelicense / deployment
The official service agreement governs subscription-based SaaS access and limits customer rights; the hosted service is not covered by a blanket open-source grant.
Read sourcemaintenance
The upstream changelog records version 3.1.0 on 2026-08-14 with API and access-control changes. Release activity is not a support guarantee.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Scope exposure discovery, validate vulnerability findings, prioritize affected assets and verify remediation. Practical guidance with documented European tools.
From vulnerability finding to verified remediation