VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
81596 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2026-84782 | redhat_vex | openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission | fixed: 147 known affected: 310 known not affected: 403 | 2026-10-08T14:22:31+00:00 | Vulnerability · Source |
| CVE-2026-11788 | redhat_vex | 389-ds-base: 389-ds-base: NULL pointer dereference in deref control plugin BER parser | fixed: 485 known affected: 6 | 2026-10-08T14:15:08+00:00 | Vulnerability · Source |
| CVE-2026-11770 | redhat_vex | 389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check | fixed: 485 known affected: 6 | 2026-10-08T14:15:02+00:00 | Vulnerability · Source |
| CVE-2026-76560 | redhat_vex | 389-ds-base: 389-ds: anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN | fixed: 486 known affected: 15 known not affected: 1 | 2026-10-08T14:14:57+00:00 | Vulnerability · Source |
| CVE-2026-19843 | redhat_vex | 389-ds-base: 389-ds-base: Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor | fixed: 69 known affected: 27 known not affected: 13 | 2026-10-08T14:14:55+00:00 | Vulnerability · Source |
| CVE-2026-18922 | redhat_vex | 389-ds-base: 389-ds-base: SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property | fixed: 496 known affected: 1 known not affected: 1 | 2026-10-08T14:14:53+00:00 | Vulnerability · Source |
| CVE-2026-18453 | redhat_vex | 389-ds-base: 389-ds-base: pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search | fixed: 486 known affected: 5 known not affected: 1 | 2026-10-08T14:14:49+00:00 | Vulnerability · Source |
| CVE-2026-18355 | redhat_vex | 389-ds-base: 389-ds-base: heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet() | fixed: 486 known affected: 1 known not affected: 5 | 2026-10-08T14:14:48+00:00 | Vulnerability · Source |
| CVE-2026-15722 | redhat_vex | 389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica ID parsing | fixed: 485 known affected: 5 known not affected: 1 | 2026-10-08T14:14:43+00:00 | Vulnerability · Source |
| CVE-2026-94286 | redhat_vex | libXtst: libXtst: Denial of Service via out-of-bounds read in RECORD reply parser | fixed: 5 known affected: 12 | 2026-10-08T14:13:06+00:00 | Vulnerability · Source |
| CVE-2026-98176 | redhat_vex | kernel: drm/amdkfd: Avoid integer underflow with ffs in EOP ring size calc | known affected: 200 known not affected: 77 | 2026-10-08T12:06:30+00:00 | Vulnerability · Source |
| CVE-2023-5752 | redhat_vex | pip: Mercurial configuration injectable in repo revision when installing via pip | fixed: 8 known affected: 5 known not affected: 296 | 2026-10-08T12:06:21+00:00 | Vulnerability · Source |
| CVE-2026-98362 | redhat_vex | kernel: clk: scpi: bound-check DVFS index in scpi_dvfs_recalc_rate | known affected: 235 known not affected: 42 | 2026-10-08T12:06:20+00:00 | Vulnerability · Source |
| CVE-2024-3177 | redhat_vex | kubernetes: kube-apiserver: bypassing mountable secrets policy imposed by the ServiceAccount admission plugin | fixed: 24 known affected: 18 known not affected: 277 | 2026-10-08T12:06:19+00:00 | Vulnerability · Source |
| CVE-2026-77408 | redhat_vex | github.com/rabbitmq/amqp091-go: RabbitMQ amqp091-go: Silent Data Truncation and State Corruption via Shortstr Integer Overflow | known affected: 9 known not affected: 5 | 2026-10-08T12:03:08+00:00 | Vulnerability · Source |
| CVE-2026-77301 | redhat_vex | adm-zip: adm-zip: Denial of Service via uncontrolled memory allocation | known affected: 24 known not affected: 2 | 2026-10-08T12:03:07+00:00 | Vulnerability · Source |
| CVE-2026-22028 | redhat_vex | preact: Preact: Arbitrary script execution via JSON serialization protection bypass | fixed: 1 known affected: 16 known not affected: 691 | 2026-10-08T12:03:02+00:00 | Vulnerability · Source |
| CVE-2026-98366 | redhat_vex | kernel: RDMA/rxe: validate access flags before swapping the MR's PD | known affected: 107 known not affected: 170 | 2026-10-08T12:02:53+00:00 | Vulnerability · Source |
| CVE-2026-102409 | redhat_vex | elasticsearch: Elasticsearch: Denial of Service via uncontrolled recursion | known affected: 1 known not affected: 2 | 2026-10-08T12:02:35+00:00 | Vulnerability · Source |
| CVE-2026-89058 | redhat_vex | resteasy-core: RESTEasy: CorsFilter Reflects Arbitrary Origin with Credentials under Wildcard Config | known affected: 91 | 2026-10-08T12:02:24+00:00 | Vulnerability · Source |
| CVE-2026-98365 | redhat_vex | kernel: RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access | known affected: 186 known not affected: 91 | 2026-10-08T12:02:22+00:00 | Vulnerability · Source |
| CVE-2026-98175 | redhat_vex | kernel: smb: client: cancel reconnect work in clean_demultiplex_info() | known affected: 235 known not affected: 42 | 2026-10-08T12:02:18+00:00 | Vulnerability · Source |
| CVE-2026-98174 | redhat_vex | kernel: smb: client: fix rlist race and missing initialization | known affected: 235 known not affected: 42 | 2026-10-08T12:02:17+00:00 | Vulnerability · Source |
| CVE-2026-93019 | redhat_vex | perl-Imager: Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read | known not affected: 1 | 2026-10-08T12:02:16+00:00 | Vulnerability · Source |
| CVE-2026-98363 | redhat_vex | kernel: firmware: arm_scpi: reject DVFS OPP count above MAX_DVFS_OPPS | known affected: 235 known not affected: 42 | 2026-10-08T12:02:16+00:00 | Vulnerability · Source |
| CVE-2026-45991 | redhat_vex | kernel: udf: fix partition descriptor append bookkeeping | fixed: 1311 known affected: 22 known not affected: 28 under investigation: 14 | 2026-10-08T12:01:58+00:00 | Vulnerability · Source |
| CVE-2026-43186 | redhat_vex | kernel: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() | fixed: 616 known affected: 14 known not affected: 184 | 2026-10-08T12:01:57+00:00 | Vulnerability · Source |
| CVE-2025-40237 | redhat_vex | kernel: fs/notify: call exportfs_encode_fid with s_umount | fixed: 616 known affected: 108 known not affected: 90 | 2026-10-08T12:01:56+00:00 | Vulnerability · Source |
| CVE-2026-80864 | redhat_vex | kernel: RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp | fixed: 852 known affected: 186 known not affected: 91 | 2026-10-08T12:01:48+00:00 | Vulnerability · Source |
| CVE-2026-80863 | redhat_vex | kernel: RDMA/rxe: Fix OOB in free_rd_atomic_resources() | fixed: 852 known affected: 169 known not affected: 108 | 2026-10-08T12:01:46+00:00 | Vulnerability · Source |
| CVE-2026-46133 | redhat_vex | kernel: RDMA/rxe: Reject unknown opcodes before ICRC processing | fixed: 1305 known affected: 50 known not affected: 91 | 2026-10-08T12:01:37+00:00 | Vulnerability · Source |
| CVE-2026-46114 | redhat_vex | kernel: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads | fixed: 841 known affected: 22 known not affected: 167 | 2026-10-08T12:01:36+00:00 | Vulnerability · Source |
| CVE-2026-46043 | redhat_vex | kernel: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv | fixed: 1305 known affected: 50 known not affected: 91 | 2026-10-08T12:01:35+00:00 | Vulnerability · Source |
| CVE-2026-45910 | redhat_vex | kernel: RDMA/rxe: Fix race condition in QP timer handlers | fixed: 841 known affected: 22 known not affected: 167 | 2026-10-08T12:01:30+00:00 | Vulnerability · Source |
| CVE-2026-91956 | redhat_vex | FreeRDP: FreeRDP: Denial of Service via out-of-bounds read in URBDRC channel | fixed: 195 known affected: 12 | 2026-10-08T12:01:26+00:00 | Vulnerability · Source |
| CVE-2026-91954 | redhat_vex | FreeRDP: FreeRDP: Denial of Service via crafted Surface Bits command | fixed: 195 known affected: 12 | 2026-10-08T12:01:24+00:00 | Vulnerability · Source |
| CVE-2026-91953 | redhat_vex | FreeRDP: FreeRDP: Heap buffer overflow via oversized LB_LOAD_BALANCE_INFO routing token can lead to heap corruption. | fixed: 195 known affected: 12 | 2026-10-08T12:01:22+00:00 | Vulnerability · Source |
| CVE-2026-91959 | redhat_vex | FreeRDP: FreeRDP: Denial of Service due to buffer over-read in RPC gateway | fixed: 195 known affected: 12 | 2026-10-08T12:01:21+00:00 | Vulnerability · Source |
| CVE-2025-26791 | redhat_vex | dompurify: Mutation XSS in DOMPurify Due to Improper Template Literal Handling | fixed: 285 known affected: 36 known not affected: 418 | 2026-10-08T12:00:14+00:00 | Vulnerability · Source |
| CVE-2025-24976 | redhat_vex | distribution: Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT | fixed: 24 known affected: 12 known not affected: 300 | 2026-10-08T11:59:59+00:00 | Vulnerability · Source |
| CVE-2023-26125 | redhat_vex | golang-github-gin-gonic-gin: Improper Input Validation | fixed: 9 known affected: 15 known not affected: 906 | 2026-10-08T11:59:16+00:00 | Vulnerability · Source |
| CVE-2024-8184 | redhat_vex | org.eclipse.jetty:jetty-server: jetty: Jetty ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks | fixed: 3 known affected: 11 known not affected: 6 | 2026-10-08T11:59:02+00:00 | Vulnerability · Source |
| CVE-2024-2700 | redhat_vex | quarkus-core: Leak of local configuration properties into Quarkus applications | fixed: 146 known affected: 7 known not affected: 2067 | 2026-10-08T11:59:00+00:00 | Vulnerability · Source |
| CVE-2023-1428 | redhat_vex | gRPC: Reachable Assertion | fixed: 9 known affected: 6 known not affected: 299 | 2026-10-08T11:58:37+00:00 | Vulnerability · Source |
| CVE-2023-29401 | redhat_vex | golang-github-gin-gonic-gin: Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function | fixed: 13 known affected: 16 known not affected: 2030 | 2026-10-08T11:58:19+00:00 | Vulnerability · Source |
| CVE-2024-9676 | redhat_vex | Podman: Buildah: CRI-O: symlink traversal vulnerability in the containers/storage library can cause Denial of Service (DoS) | fixed: 711 known affected: 19 known not affected: 4893 | 2026-10-08T11:58:04+00:00 | Vulnerability · Source |
| CVE-2026-104846 | redhat_vex | seroval: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of CVE-2026-59940) | known affected: 1 | 2026-10-08T11:57:54+00:00 | Vulnerability · Source |
| CVE-2026-102282 | redhat_vex | adm-zip: adm-zip: Privilege escalation via unfiltered permission bits in extracted archives | known affected: 22 known not affected: 2 | 2026-10-08T11:57:50+00:00 | Vulnerability · Source |
| CVE-2024-1139 | redhat_vex | cluster-monitoring-operator: credentials leak | fixed: 679 known affected: 1 known not affected: 1945 | 2026-10-08T11:57:15+00:00 | Vulnerability · Source |
| CVE-2023-3462 | redhat_vex | Hashicorp/vault: Vault’s LDAP Auth Method Allows for User Enumeration | fixed: 15 known affected: 4 known not affected: 1492 | 2026-10-08T11:57:14+00:00 | Vulnerability · Source |