VEX records

Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.

Reset

81567 VEX records

API response
Vulnerability Source Title Product status Imported Links
CVE-2022-37601 redhat_vex loader-utils: prototype pollution in function parseQuery in parseQuery.js fixed: 5 known affected: 56 known not affected: 93 2026-10-08T16:03:42+00:00 Vulnerability · Source
CVE-2022-31129 redhat_vex moment: inefficient parsing algorithm resulting in DoS fixed: 42 known affected: 115 known not affected: 367 2026-10-08T16:03:34+00:00 Vulnerability · Source
CVE-2021-3918 redhat_vex nodejs-json-schema: Prototype pollution vulnerability fixed: 242 known affected: 29 known not affected: 9 2026-10-08T16:02:25+00:00 Vulnerability · Source
CVE-2023-49568 redhat_vex go-git: Maliciously crafted Git server replies can cause DoS on go-git clients fixed: 612 known affected: 32 known not affected: 7136 under investigation: 1 2026-10-08T15:34:13+00:00 Vulnerability · Source
CVE-2020-7660 redhat_vex npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js fixed: 6 known affected: 5 known not affected: 2 2026-10-08T15:32:10+00:00 Vulnerability · Source
CVE-2019-20933 redhat_vex influxdb: authentication bypass because a JWT token may have an empty SharedSecret known not affected: 15 2026-10-08T15:31:42+00:00 Vulnerability · Source
CVE-2023-49569 redhat_vex go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients fixed: 1320 known affected: 27 known not affected: 7555 2026-10-08T15:30:33+00:00 Vulnerability · Source
CVE-2026-61666 redhat_vex websocket-driver: github.com/faye/websocket-driver-ruby: websocket-driver: Denial of Service via malformed Host header known not affected: 3 under investigation: 2 2026-10-08T15:23:51+00:00 Vulnerability · Source
CVE-2026-97427 redhat_vex kernel: drm/amd/pm: bound pp_dpm_set_pp_table() memcpy known affected: 233 known not affected: 42 2026-10-08T15:16:55+00:00 Vulnerability · Source
CVE-2026-84359 redhat_vex chromium-browser: skia: chromium-browser: Information leak in Skia known affected: 11 known not affected: 25 2026-10-08T15:16:52+00:00 Vulnerability · Source
CVE-2026-93800 redhat_vex kernel: btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() known affected: 77 known not affected: 198 2026-10-08T15:16:50+00:00 Vulnerability · Source
CVE-2026-98183 redhat_vex kernel: wifi: mac80211: avoid out-of-bounds read for empty PREQ elements known not affected: 277 2026-10-08T15:16:48+00:00 Vulnerability · Source
CVE-2026-90460 redhat_vex openstack-keystone: openstack-keystone: PATCH /v3/credentials accepts unauthorized post-update project_id; EC2-derived tokens bypass delegation scope check known affected: 10 2026-10-08T15:16:45+00:00 Vulnerability · Source
CVE-2026-97422 redhat_vex kernel: drm/amdkfd: fix SMI event cross-process information leak known affected: 185 known not affected: 90 2026-10-08T15:16:41+00:00 Vulnerability · Source
CVE-2026-93017 redhat_vex insights-operator: gather ServiceAccount has cluster-wide Secret read plus nodes/proxy and cluster-reader known affected: 2 2026-10-08T15:16:33+00:00 Vulnerability · Source
CVE-2026-92542 redhat_vex github.com/moby/moby: Moby: Unauthorized traffic injection via forged VXLAN datagrams known affected: 14 known not affected: 1 2026-10-08T15:16:22+00:00 Vulnerability · Source
CVE-2026-107570 redhat_vex mutt: mutt: Memory corruption via crafted Content-Type header in email template known affected: 9 2026-10-08T15:01:54+00:00 Vulnerability · Source
CVE-2026-98182 redhat_vex kernel: wifi: mac80211: refuse to make a monitor active when it has no queue known affected: 249 known not affected: 28 2026-10-08T15:01:52+00:00 Vulnerability · Source
CVE-2026-98179 redhat_vex kernel: drm/amdgpu: fix rmmio iounmap skipped on device removal known affected: 235 known not affected: 42 2026-10-08T15:01:48+00:00 Vulnerability · Source
CVE-2026-98178 redhat_vex kernel: drm/amdgpu: Skip KFD mapping clear before initialization known affected: 14 known not affected: 263 2026-10-08T15:01:44+00:00 Vulnerability · Source
CVE-2026-98177 redhat_vex kernel: drm/amdkfd: Avoid integer underflow in EOP ring size calculation known affected: 249 known not affected: 28 2026-10-08T15:01:39+00:00 Vulnerability · Source
CVE-2026-93144 redhat_vex kernel: bpf: Reject writes through untrusted BTF pointers known affected: 186 known not affected: 91 2026-10-08T15:01:38+00:00 Vulnerability · Source
CVE-2026-93125 redhat_vex kernel: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max known affected: 186 known not affected: 91 2026-10-08T15:01:38+00:00 Vulnerability · Source
CVE-2026-18839 redhat_vex popt-devel: popt-static: size_t underflow in singleOptionHelp fixed: 10 known affected: 14 2026-10-08T15:01:36+00:00 Vulnerability · Source
CVE-2026-98371 redhat_vex kernel: xfrm: iptfs: fix runt reassembly panic from short inner tot_len known not affected: 277 2026-10-08T14:57:21+00:00 Vulnerability · Source
CVE-2024-9355 redhat_vex golang-fips: Golang FIPS zeroed buffer fixed: 305 known affected: 148 known not affected: 240 2026-10-08T14:56:52+00:00 Vulnerability · Source
CVE-2026-44918 redhat_vex openstack-ironic: Prevent rehoming resources to nodes with different owner fixed: 16 known affected: 5 known not affected: 5235 2026-10-08T14:52:40+00:00 Vulnerability · Source
CVE-2026-77037 redhat_vex multer: Multer: Denial of Service via file descriptor leak on aborted uploads fixed: 2 known affected: 25 known not affected: 14 2026-10-08T14:48:27+00:00 Vulnerability · Source
CVE-2026-67422 redhat_vex pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability fixed: 3 known not affected: 10 2026-10-08T14:47:50+00:00 Vulnerability · Source
CVE-2026-107315 redhat_vex org.postgresql/postgresql: PostgreSQL JDBC Driver: Information disclosure via residual send buffer padding known affected: 11 known not affected: 58 2026-10-08T14:39:20+00:00 Vulnerability · Source
CVE-2026-63328 redhat_vex github.com/aquasecurity/trivy: Trivy: Path Traversal allows arbitrary file write via malicious plugin known not affected: 1 2026-10-08T14:38:54+00:00 Vulnerability · Source
CVE-2026-37236 redhat_vex github.com/grpc-ecosystem/grpc-gateway: grpc-gateway: Access control bypass via X-HTTP-Method-Override header known affected: 96 known not affected: 90 2026-10-08T14:38:44+00:00 Vulnerability · Source
CVE-2026-93812 redhat_vex kernel: ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr known affected: 77 known not affected: 200 2026-10-08T14:38:35+00:00 Vulnerability · Source
CVE-2026-93827 redhat_vex kernel: virtio-fs: avoid double-free on failed queue setup known affected: 183 known not affected: 92 2026-10-08T14:36:33+00:00 Vulnerability · Source
CVE-2026-106412 redhat_vex chromium-browser: Race condition in Core known not affected: 1 2026-10-08T14:36:03+00:00 Vulnerability · Source
CVE-2026-106377 redhat_vex chromium-browser: Race condition in Fonts known not affected: 1 2026-10-08T14:35:59+00:00 Vulnerability · Source
CVE-2026-106369 redhat_vex chromium-browser: Missing authorization in Translate known not affected: 1 2026-10-08T14:35:57+00:00 Vulnerability · Source
CVE-2026-106293 redhat_vex chromium-browser: Type confusion in ANGLE known not affected: 1 2026-10-08T14:35:53+00:00 Vulnerability · Source
CVE-2026-106243 redhat_vex chromium-browser: Incomplete cleanup in Proxy Auth known not affected: 1 2026-10-08T14:35:50+00:00 Vulnerability · Source
CVE-2026-106239 redhat_vex chromium-browser: Integer overflow in WebGL known not affected: 1 2026-10-08T14:35:46+00:00 Vulnerability · Source
CVE-2026-106214 redhat_vex chromium-browser: Information leak in Proxy known not affected: 1 2026-10-08T14:35:42+00:00 Vulnerability · Source
CVE-2026-103262 redhat_vex tornado: Tornado: Denial of Service via decompression bomb in CurlAsyncHTTPClient known affected: 66 known not affected: 5 2026-10-08T14:35:38+00:00 Vulnerability · Source
CVE-2026-19024 redhat_vex hdf5: HDF5: Denial of service via malformed dataset fixed: 21 known affected: 1 2026-10-08T14:25:13+00:00 Vulnerability · Source
CVE-2026-98370 redhat_vex kernel: xfrm: fix compat ALLOCSPI request use-after-free known affected: 200 known not affected: 77 2026-10-08T14:23:57+00:00 Vulnerability · Source
CVE-2026-11573 redhat_vex qtbase: qt5-qtbase: qt6-qtbase: qtbase: Denial of Service via uncontrolled recursion in XML serialization fixed: 23 known affected: 46 2026-10-08T14:23:53+00:00 Vulnerability · Source
CVE-2026-98369 redhat_vex kernel: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() known affected: 200 known not affected: 77 2026-10-08T14:23:47+00:00 Vulnerability · Source
CVE-2026-98368 redhat_vex kernel: esp: downgrade zerocopy managed frags before mutating skb frags known affected: 198 known not affected: 79 2026-10-08T14:23:38+00:00 Vulnerability · Source
CVE-2026-98367 redhat_vex kernel: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept known affected: 158 known not affected: 119 2026-10-08T14:23:33+00:00 Vulnerability · Source
CVE-2026-98181 redhat_vex kernel: drm/gud: fix out-of-bounds write in gud_plane_atomic_check() known affected: 186 known not affected: 91 2026-10-08T14:23:29+00:00 Vulnerability · Source
CVE-2026-98180 redhat_vex kernel: drm/msm: RCU-free the scheduler-containing ring and VM objects known not affected: 277 2026-10-08T14:23:24+00:00 Vulnerability · Source