VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
81567 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2022-37601 | redhat_vex | loader-utils: prototype pollution in function parseQuery in parseQuery.js | fixed: 5 known affected: 56 known not affected: 93 | 2026-10-08T16:03:42+00:00 | Vulnerability · Source |
| CVE-2022-31129 | redhat_vex | moment: inefficient parsing algorithm resulting in DoS | fixed: 42 known affected: 115 known not affected: 367 | 2026-10-08T16:03:34+00:00 | Vulnerability · Source |
| CVE-2021-3918 | redhat_vex | nodejs-json-schema: Prototype pollution vulnerability | fixed: 242 known affected: 29 known not affected: 9 | 2026-10-08T16:02:25+00:00 | Vulnerability · Source |
| CVE-2023-49568 | redhat_vex | go-git: Maliciously crafted Git server replies can cause DoS on go-git clients | fixed: 612 known affected: 32 known not affected: 7136 under investigation: 1 | 2026-10-08T15:34:13+00:00 | Vulnerability · Source |
| CVE-2020-7660 | redhat_vex | npm-serialize-javascript: allows remote attackers to inject arbitrary code via the function deleteFunctions within index.js | fixed: 6 known affected: 5 known not affected: 2 | 2026-10-08T15:32:10+00:00 | Vulnerability · Source |
| CVE-2019-20933 | redhat_vex | influxdb: authentication bypass because a JWT token may have an empty SharedSecret | known not affected: 15 | 2026-10-08T15:31:42+00:00 | Vulnerability · Source |
| CVE-2023-49569 | redhat_vex | go-git: Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients | fixed: 1320 known affected: 27 known not affected: 7555 | 2026-10-08T15:30:33+00:00 | Vulnerability · Source |
| CVE-2026-61666 | redhat_vex | websocket-driver: github.com/faye/websocket-driver-ruby: websocket-driver: Denial of Service via malformed Host header | known not affected: 3 under investigation: 2 | 2026-10-08T15:23:51+00:00 | Vulnerability · Source |
| CVE-2026-97427 | redhat_vex | kernel: drm/amd/pm: bound pp_dpm_set_pp_table() memcpy | known affected: 233 known not affected: 42 | 2026-10-08T15:16:55+00:00 | Vulnerability · Source |
| CVE-2026-84359 | redhat_vex | chromium-browser: skia: chromium-browser: Information leak in Skia | known affected: 11 known not affected: 25 | 2026-10-08T15:16:52+00:00 | Vulnerability · Source |
| CVE-2026-93800 | redhat_vex | kernel: btrfs: fix use-after-free on reloc root after error in insert_dirty_subvol() | known affected: 77 known not affected: 198 | 2026-10-08T15:16:50+00:00 | Vulnerability · Source |
| CVE-2026-98183 | redhat_vex | kernel: wifi: mac80211: avoid out-of-bounds read for empty PREQ elements | known not affected: 277 | 2026-10-08T15:16:48+00:00 | Vulnerability · Source |
| CVE-2026-90460 | redhat_vex | openstack-keystone: openstack-keystone: PATCH /v3/credentials accepts unauthorized post-update project_id; EC2-derived tokens bypass delegation scope check | known affected: 10 | 2026-10-08T15:16:45+00:00 | Vulnerability · Source |
| CVE-2026-97422 | redhat_vex | kernel: drm/amdkfd: fix SMI event cross-process information leak | known affected: 185 known not affected: 90 | 2026-10-08T15:16:41+00:00 | Vulnerability · Source |
| CVE-2026-93017 | redhat_vex | insights-operator: gather ServiceAccount has cluster-wide Secret read plus nodes/proxy and cluster-reader | known affected: 2 | 2026-10-08T15:16:33+00:00 | Vulnerability · Source |
| CVE-2026-92542 | redhat_vex | github.com/moby/moby: Moby: Unauthorized traffic injection via forged VXLAN datagrams | known affected: 14 known not affected: 1 | 2026-10-08T15:16:22+00:00 | Vulnerability · Source |
| CVE-2026-107570 | redhat_vex | mutt: mutt: Memory corruption via crafted Content-Type header in email template | known affected: 9 | 2026-10-08T15:01:54+00:00 | Vulnerability · Source |
| CVE-2026-98182 | redhat_vex | kernel: wifi: mac80211: refuse to make a monitor active when it has no queue | known affected: 249 known not affected: 28 | 2026-10-08T15:01:52+00:00 | Vulnerability · Source |
| CVE-2026-98179 | redhat_vex | kernel: drm/amdgpu: fix rmmio iounmap skipped on device removal | known affected: 235 known not affected: 42 | 2026-10-08T15:01:48+00:00 | Vulnerability · Source |
| CVE-2026-98178 | redhat_vex | kernel: drm/amdgpu: Skip KFD mapping clear before initialization | known affected: 14 known not affected: 263 | 2026-10-08T15:01:44+00:00 | Vulnerability · Source |
| CVE-2026-98177 | redhat_vex | kernel: drm/amdkfd: Avoid integer underflow in EOP ring size calculation | known affected: 249 known not affected: 28 | 2026-10-08T15:01:39+00:00 | Vulnerability · Source |
| CVE-2026-93144 | redhat_vex | kernel: bpf: Reject writes through untrusted BTF pointers | known affected: 186 known not affected: 91 | 2026-10-08T15:01:38+00:00 | Vulnerability · Source |
| CVE-2026-93125 | redhat_vex | kernel: bpf: Reject rdonly/rdwr_buf_size kfunc arguments that exceed u32 max | known affected: 186 known not affected: 91 | 2026-10-08T15:01:38+00:00 | Vulnerability · Source |
| CVE-2026-18839 | redhat_vex | popt-devel: popt-static: size_t underflow in singleOptionHelp | fixed: 10 known affected: 14 | 2026-10-08T15:01:36+00:00 | Vulnerability · Source |
| CVE-2026-98371 | redhat_vex | kernel: xfrm: iptfs: fix runt reassembly panic from short inner tot_len | known not affected: 277 | 2026-10-08T14:57:21+00:00 | Vulnerability · Source |
| CVE-2024-9355 | redhat_vex | golang-fips: Golang FIPS zeroed buffer | fixed: 305 known affected: 148 known not affected: 240 | 2026-10-08T14:56:52+00:00 | Vulnerability · Source |
| CVE-2026-44918 | redhat_vex | openstack-ironic: Prevent rehoming resources to nodes with different owner | fixed: 16 known affected: 5 known not affected: 5235 | 2026-10-08T14:52:40+00:00 | Vulnerability · Source |
| CVE-2026-77037 | redhat_vex | multer: Multer: Denial of Service via file descriptor leak on aborted uploads | fixed: 2 known affected: 25 known not affected: 14 | 2026-10-08T14:48:27+00:00 | Vulnerability · Source |
| CVE-2026-67422 | redhat_vex | pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability | fixed: 3 known not affected: 10 | 2026-10-08T14:47:50+00:00 | Vulnerability · Source |
| CVE-2026-107315 | redhat_vex | org.postgresql/postgresql: PostgreSQL JDBC Driver: Information disclosure via residual send buffer padding | known affected: 11 known not affected: 58 | 2026-10-08T14:39:20+00:00 | Vulnerability · Source |
| CVE-2026-63328 | redhat_vex | github.com/aquasecurity/trivy: Trivy: Path Traversal allows arbitrary file write via malicious plugin | known not affected: 1 | 2026-10-08T14:38:54+00:00 | Vulnerability · Source |
| CVE-2026-37236 | redhat_vex | github.com/grpc-ecosystem/grpc-gateway: grpc-gateway: Access control bypass via X-HTTP-Method-Override header | known affected: 96 known not affected: 90 | 2026-10-08T14:38:44+00:00 | Vulnerability · Source |
| CVE-2026-93812 | redhat_vex | kernel: ksmbd: fix sd_ndr.data memory leak in ksmbd_vfs_set_sd_xattr | known affected: 77 known not affected: 200 | 2026-10-08T14:38:35+00:00 | Vulnerability · Source |
| CVE-2026-93827 | redhat_vex | kernel: virtio-fs: avoid double-free on failed queue setup | known affected: 183 known not affected: 92 | 2026-10-08T14:36:33+00:00 | Vulnerability · Source |
| CVE-2026-106412 | redhat_vex | chromium-browser: Race condition in Core | known not affected: 1 | 2026-10-08T14:36:03+00:00 | Vulnerability · Source |
| CVE-2026-106377 | redhat_vex | chromium-browser: Race condition in Fonts | known not affected: 1 | 2026-10-08T14:35:59+00:00 | Vulnerability · Source |
| CVE-2026-106369 | redhat_vex | chromium-browser: Missing authorization in Translate | known not affected: 1 | 2026-10-08T14:35:57+00:00 | Vulnerability · Source |
| CVE-2026-106293 | redhat_vex | chromium-browser: Type confusion in ANGLE | known not affected: 1 | 2026-10-08T14:35:53+00:00 | Vulnerability · Source |
| CVE-2026-106243 | redhat_vex | chromium-browser: Incomplete cleanup in Proxy Auth | known not affected: 1 | 2026-10-08T14:35:50+00:00 | Vulnerability · Source |
| CVE-2026-106239 | redhat_vex | chromium-browser: Integer overflow in WebGL | known not affected: 1 | 2026-10-08T14:35:46+00:00 | Vulnerability · Source |
| CVE-2026-106214 | redhat_vex | chromium-browser: Information leak in Proxy | known not affected: 1 | 2026-10-08T14:35:42+00:00 | Vulnerability · Source |
| CVE-2026-103262 | redhat_vex | tornado: Tornado: Denial of Service via decompression bomb in CurlAsyncHTTPClient | known affected: 66 known not affected: 5 | 2026-10-08T14:35:38+00:00 | Vulnerability · Source |
| CVE-2026-19024 | redhat_vex | hdf5: HDF5: Denial of service via malformed dataset | fixed: 21 known affected: 1 | 2026-10-08T14:25:13+00:00 | Vulnerability · Source |
| CVE-2026-98370 | redhat_vex | kernel: xfrm: fix compat ALLOCSPI request use-after-free | known affected: 200 known not affected: 77 | 2026-10-08T14:23:57+00:00 | Vulnerability · Source |
| CVE-2026-11573 | redhat_vex | qtbase: qt5-qtbase: qt6-qtbase: qtbase: Denial of Service via uncontrolled recursion in XML serialization | fixed: 23 known affected: 46 | 2026-10-08T14:23:53+00:00 | Vulnerability · Source |
| CVE-2026-98369 | redhat_vex | kernel: xfrm: add missing rcu_read_lock(), skb_dst_force() and dev_hold() for xfrm_trans_reinject() | known affected: 200 known not affected: 77 | 2026-10-08T14:23:47+00:00 | Vulnerability · Source |
| CVE-2026-98368 | redhat_vex | kernel: esp: downgrade zerocopy managed frags before mutating skb frags | known affected: 198 known not affected: 79 | 2026-10-08T14:23:38+00:00 | Vulnerability · Source |
| CVE-2026-98367 | redhat_vex | kernel: RDMA/siw: Clear association under lock if siw_qp_modify fails in siw_accept | known affected: 158 known not affected: 119 | 2026-10-08T14:23:33+00:00 | Vulnerability · Source |
| CVE-2026-98181 | redhat_vex | kernel: drm/gud: fix out-of-bounds write in gud_plane_atomic_check() | known affected: 186 known not affected: 91 | 2026-10-08T14:23:29+00:00 | Vulnerability · Source |
| CVE-2026-98180 | redhat_vex | kernel: drm/msm: RCU-free the scheduler-containing ring and VM objects | known not affected: 277 | 2026-10-08T14:23:24+00:00 | Vulnerability · Source |