New

Vulnerability Monitoring

Uptime monitoring tells you a service is up. This tells you whether it is still safe to leave up.

The gap nobody is watching

You already know the moment a service goes down. What you do not know is the moment it becomes dangerous to keep running.

A vulnerability gets published against the version you happen to be running. Nothing breaks. Nothing pages anyone. The service stays green on every dashboard you own, and the first you hear about it is a stranger's cold email or something considerably worse.

One row per service, not one per CVE

A database twenty-eight findings behind is still one upgrade. So the list gives each service a single row carrying the version to move to and how much of the backlog it clears, ordered worst first.

Vulnerabilities
ServiceProductUpgradeFindingsClears
Dashboard
Lucy & Jack Clothing
Metabasev0.56.1158.28
crit 4med 3
7all of them
Orders Database
Lucy & Jack Clothing
PostgreSQL18.418.5
high 18med 7low 3
28all of them

Upgrade path visualisation

Security fixes ship in point releases, so a version that looks nearly current can still be carrying most of the backlog. The path counts what each release closes and what it leaves: here, 0.58.16 looks close enough and still leaves one finding open.

Dashboard · Metabase v0.56.11
v0.56.11 58.28clears all 7 findings

Every finding here is fixed by one upgrade. Stopping short leaves the rest open.

v0.56.11
running now
0.56.23
clears 2 · 5 left
0.56.25
clears 3 · 4 left
0.58.13
clears 4 · 3 left
0.58.15.1
clears 5 · 2 left
0.58.16
clears 6 · 1 left
58.28
clears 7 · none left

Every finding names the version that fixes it

Grouped worst first, with the CVSS score, what the vulnerability actually does, and a link to the advisory itself. Nothing needs looking up twice.

Orders Database · PostgreSQL 18.4
High18 findings · CVSS 7.2–8.8
CVE-2026-146628.8Integer wraparound in PostgreSQL tsvector and tsquery data type functionsfixed in 18.5
CVE-2026-146648.8Heap buffer overflow in PostgreSQL regexpfixed in 18.5
CVE-2026-146688.1Type confusion in the PostgreSQL ctid selectivity estimatorfixed in 18.5
CVE-2026-146698.8Heap buffer overflow in PostgreSQL to_char(timestamptz)fixed in 18.5
CVE-2026-146708.8Heap buffer overflow in PostgreSQL plperl return of a tied hashfixed in 18.5

+ 13 more high

On the monitor you already watch

The three worst findings and the one upgrade that clears them sit on the monitor page, next to the uptime you were already checking.

Turning it on is one switch. Turning it off asks first, because what you would stop receiving is a security alert.

Vulnerability detectionMetabase v0.56.11
7 known vulnerabilities

4 critical, 3 medium. All clear at 58.28.

CVE-2026-50148CriticalRemote Code Execution via Snowflake JDBC Driver Arbitrary File Writefixed in 0.56.25
CVE-2026-59826CriticalArbitrary Code Execution via Database Connection Detail Bypassfixed in 0.58.15.1
GHSA-433r-hw2v-rv9gMediumQuery Context Trusted from Client Bypasses Data Access Controlsfixed in 0.56.23
View all 7 findings4 more →
Watch for known vulnerabilities

Straight to your inbox, once

You do not have to be looking. When an advisory is published against a version you are running, it arrives as one email to whoever owns security — grouped, so a bad week is still one message.

The first one lists everything already known about what you are running. After that you only hear from us when something new appears, and each finding is reported once. Nobody learns to ignore it.

NoDisruptVulnerability report
Dashboard · v0.56.11

Security findings for Dashboard

You just switched on vulnerability detection. This first email lists everything already known to affect the version currently running. After this you will only hear from us when something new appears.

4
Critical
3
Medium
Core
Critical GHSA-r495-55cx-fjh7
Multiple vulnerabilities across query validation, permissions, and network exposure
fixed in 58.28
Read the advisory
Medium GHSA-3hg9-2v8h-4vjh
Snippet Content Disclosure via Query Metadata Template Tags
fixed in 0.56.23
Read the advisory
Critical GHSA-cwxq-fmxq-jv8h
Arbitrary File Read/Write via Unsafe H2 Built-in Functions
fixed in 0.58.16
Read the advisory

+ 4 more findings

Nothing to install

It runs from the monitoring you already have. No agent, no credentials, no new access.

Checked daily

A vulnerability disclosed this morning does not sit unnoticed until your next audit.

Honest about gaps

A component that reports no version is named, not counted as clean. An unchecked thing is not a safe one.

Matched on version

Advisories are matched against the version you are genuinely running, not the product in general.

Never on your status page

Findings stay private to your team. Nothing about them is ever exposed on a public status page.

Read-only by design

We look at what a service reports about itself. We do not attempt to exploit anything or change your systems.

Find out before someone else does

Vulnerability monitoring is included on Pro and Elite, alongside everything else NoDisrupt watches for you.