A date is not a risk assessment
Every EOL table on the internet tells you the same thing: this version stopped being supported on this date. That is true and almost useless for the conversation you actually have to win, which is convincing someone to fund an upgrade. "Support ended fourteen months ago" is an abstraction. It does not sound like anything is on fire.
end-of-life.org pairs each dead version with the CVEs it has already missed — the vulnerabilities patched in supported branches that will never be backported to yours. The output stops being a date and becomes a count: this box is missing N security fixes, these are their severities, here is what each one does.
That is a number you can put in a budget request.
What it tracks
Hundreds of products across both software and hardware, covering thousands of individual versions — operating systems, runtimes, databases, frameworks, firmware. For each:
- End-of-life and end-of-support dates, with a days-remaining countdown for versions still in support
-
- CVEs missed by versions already past EOL
-
- Search by product and version, so you can check a specific build rather than scanning a table
-
- A reaching-EOL-in-90-days list for planning rather than reacting
Rebuilt daily, vendor-first
The data is regenerated every day from vendor sources first, aggregators second. EOL dates move — vendors extend, truncate, and quietly revise them — and a table built once and left alone starts lying within months.
Public API, no signup
There is a public JSON API so the data can go into your own dashboards, CI checks, or inventory tooling instead of staying on a web page someone has to remember to visit. No account required for either the site or the API.









