VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
81596 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2026-64386 | redhat_vex | kernel: smb: client: fix query_info() replay double-free | fixed: 1224 known affected: 22 known not affected: 91 | 2026-10-08T11:21:14+00:00 | Vulnerability · Source |
| CVE-2026-64383 | redhat_vex | kernel: smb: client: fix double-free in SMB2_flush() replay | fixed: 1224 known affected: 22 known not affected: 90 | 2026-10-08T11:21:05+00:00 | Vulnerability · Source |
| CVE-2026-88815 | redhat_vex | perl-DBI: perl-DBI: Denial of Service via invalid memory read during numeric type casting | fixed: 36 known affected: 4 | 2026-10-08T11:20:54+00:00 | Vulnerability · Source |
| CVE-2026-91964 | redhat_vex | FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU | fixed: 195 known affected: 12 | 2026-10-08T11:20:50+00:00 | Vulnerability · Source |
| CVE-2026-91963 | redhat_vex | FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure | fixed: 195 known affected: 12 | 2026-10-08T11:20:37+00:00 | Vulnerability · Source |
| CVE-2024-45338 | redhat_vex | golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html | fixed: 2836 known affected: 126 known not affected: 16031 | 2026-10-08T11:14:46+00:00 | Vulnerability · Source |
| CVE-2025-22865 | redhat_vex | crypto/x509: ParsePKCS1PrivateKey panic with partial keys in crypto/x509 | fixed: 25 known affected: 4 known not affected: 328 | 2026-10-08T11:07:48+00:00 | Vulnerability · Source |
| CVE-2024-29041 | redhat_vex | express: cause malformed URLs to be evaluated | fixed: 227 known affected: 59 known not affected: 600 | 2026-10-08T11:04:07+00:00 | Vulnerability · Source |
| CVE-2025-21614 | redhat_vex | go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies | fixed: 527 known affected: 18 known not affected: 968 under investigation: 221 | 2026-10-08T11:03:30+00:00 | Vulnerability · Source |
| CVE-2025-21613 | redhat_vex | go-git: argument injection via the URL field | fixed: 553 known affected: 16 known not affected: 1075 | 2026-10-08T11:03:11+00:00 | Vulnerability · Source |
| CVE-2024-38816 | redhat_vex | spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource | fixed: 2 known affected: 8 known not affected: 8 | 2026-10-08T10:55:14+00:00 | Vulnerability · Source |
| CVE-2024-7885 | redhat_vex | undertow: Improper State Management in Proxy Protocol parsing causes information leakage | fixed: 146 known affected: 9 known not affected: 2198 | 2026-10-08T10:55:07+00:00 | Vulnerability · Source |
| CVE-2023-33953 | redhat_vex | gRPC: hpack table accounting errors can lead to denial of service | fixed: 9 known not affected: 479 | 2026-10-08T10:54:25+00:00 | Vulnerability · Source |
| CVE-2024-21626 | redhat_vex | runc: file descriptor leak | fixed: 2007 known affected: 38 known not affected: 2786 | 2026-10-08T10:53:41+00:00 | Vulnerability · Source |
| CVE-2024-47072 | redhat_vex | com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream | fixed: 35 known affected: 10 known not affected: 12 | 2026-10-08T10:53:15+00:00 | Vulnerability · Source |
| CVE-2024-29415 | redhat_vex | node-ip: Incomplete fix for CVE-2023-42282 | fixed: 3 known affected: 6 known not affected: 136 | 2026-10-08T10:48:15+00:00 | Vulnerability · Source |
| CVE-2024-47875 | redhat_vex | dompurify: nesting-based mutation XSS vulnerability | fixed: 224 known affected: 15 known not affected: 2689 | 2026-10-08T10:46:43+00:00 | Vulnerability · Source |
| CVE-2026-106550 | redhat_vex | convict: convict: Denial of Service via prototype pollution in config.set() | known affected: 1 | 2026-10-08T09:53:12+00:00 | Vulnerability · Source |
| CVE-2026-85234 | redhat_vex | tftp: tftp-hpa: Denial of Service due to out-of-bounds read/write in remap engine | fixed: 21 known affected: 8 known not affected: 1 | 2026-10-08T09:13:25+00:00 | Vulnerability · Source |
| CVE-2026-103008 | redhat_vex | elasticsearch: elasticsearch: Denial of Service via uncontrolled recursion in scripted runtime fields | known affected: 1 known not affected: 2 | 2026-10-08T09:09:24+00:00 | Vulnerability · Source |
| CVE-2026-103005 | redhat_vex | elasticsearch: Elasticsearch: Denial of Service via excessive memory allocation in connector descriptions | known affected: 1 known not affected: 2 | 2026-10-08T09:09:19+00:00 | Vulnerability · Source |
| CVE-2026-107466 | redhat_vex | flatpak-builder: Local File Exfiltration via `file | known affected: 4 | 2026-10-08T08:52:16+00:00 | Vulnerability · Source |
| CVE-2026-98173 | redhat_vex | kernel: smb: client: fix use-after-free of iface in cifs_try_adding_channels() | known affected: 234 known not affected: 43 | 2026-10-08T08:52:13+00:00 | Vulnerability · Source |
| CVE-2026-97404 | redhat_vex | zaqar: OpenStack Zaqar: authentication bypass via empty URL-Signature header | known affected: 4 | 2026-10-08T08:52:11+00:00 | Vulnerability · Source |
| CVE-2025-61163 | redhat_vex | Cohere North AI: Cohere North AI: Information disclosure via improper Origin header validation | known not affected: 1 | 2026-10-08T08:52:07+00:00 | Vulnerability · Source |
| CVE-2017-7214 | redhat_vex | openstack-nova: Sensitive information included in legacy notification exception contexts | fixed: 43 known affected: 42 known not affected: 37 | 2026-10-08T08:52:01+00:00 | Vulnerability · Source |
| CVE-2026-78030 | redhat_vex | perl-DBI: DBI: Loading of arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM | known affected: 10 | 2026-10-08T08:51:42+00:00 | Vulnerability · Source |
| CVE-2025-61164 | redhat_vex | Cohere North AI: Cohere North AI: Information Leak via WebSocket Endpoint | known not affected: 1 | 2026-10-08T08:51:38+00:00 | Vulnerability · Source |
| CVE-2022-3100 | redhat_vex | openstack-barbican: access policy bypass via query string injection | fixed: 23 known not affected: 19 | 2026-10-08T08:51:32+00:00 | Vulnerability · Source |
| CVE-2025-61162 | redhat_vex | Cohere North AI: Cohere North AI: Arbitrary user information overwrite via incorrect access control | known not affected: 1 | 2026-10-08T08:51:32+00:00 | Vulnerability · Source |
| CVE-2021-40085 | redhat_vex | openstack-neutron: arbitrary dnsmasq reconfiguration via extra_dhcp_opts | fixed: 56 known not affected: 15 | 2026-10-08T08:51:30+00:00 | Vulnerability · Source |
| CVE-2020-17376 | redhat_vex | openstack-nova: Soft reboot after live-migration reverts instance to original source domain XML | fixed: 93 known affected: 13 known not affected: 13 | 2026-10-08T08:51:18+00:00 | Vulnerability · Source |
| CVE-2015-1195 | redhat_vex | openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002) | known not affected: 14 | 2026-10-08T08:51:18+00:00 | Vulnerability · Source |
| CVE-2014-9493 | redhat_vex | openstack-glance: unrestricted path traversal flaw | fixed: 12 known affected: 1 known not affected: 11 | 2026-10-08T08:51:18+00:00 | Vulnerability · Source |
| CVE-2016-0737 | redhat_vex | openstack-swift: Client to proxy DoS through Large Objects | fixed: 42 known affected: 18 known not affected: 6 | 2026-10-08T08:51:18+00:00 | Vulnerability · Source |
| CVE-2016-2140 | redhat_vex | openstack-nova: Host data leak through resize/migration | fixed: 65 known not affected: 59 | 2026-10-08T08:51:18+00:00 | Vulnerability · Source |
| CVE-2026-56449 | redhat_vex | httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html | fixed: 23 known affected: 49 known not affected: 18 | 2026-10-08T08:28:16+00:00 | Vulnerability · Source |
| CVE-2026-18212 | redhat_vex | keycloak-services: keycloak-services: SAML Redirect DEFLATE helpers leak native zlib state | fixed: 20 known affected: 2 known not affected: 1 | 2026-10-08T08:23:57+00:00 | Vulnerability · Source |
| CVE-2026-15573 | redhat_vex | keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher | fixed: 20 known affected: 2 known not affected: 1 | 2026-10-08T08:23:52+00:00 | Vulnerability · Source |
| CVE-2026-5680 | redhat_vex | undertow-core: Undertow: Denial of Service via WebSocket permessage-deflate processing | fixed: 443 known affected: 12 known not affected: 12 | 2026-10-08T08:23:43+00:00 | Vulnerability · Source |
| CVE-2026-15565 | redhat_vex | undertow: undertow-websockets: Undertow: Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method | fixed: 748 known affected: 5 known not affected: 2189 | 2026-10-08T08:23:43+00:00 | Vulnerability · Source |
| CVE-2026-17615 | redhat_vex | resteasy-core: RESTeasy SourceProvider remote unauthenticated file read | fixed: 20 known affected: 8 known not affected: 7 | 2026-10-08T08:07:17+00:00 | Vulnerability · Source |
| CVE-2026-84641 | redhat_vex | thunderbird: Information disclosure due to malicious IMAP server response | fixed: 78 known affected: 5 | 2026-10-08T08:04:00+00:00 | Vulnerability · Source |
| CVE-2026-84640 | redhat_vex | thunderbird: One byte overflow read in mail parser | fixed: 78 known affected: 5 | 2026-10-08T08:03:45+00:00 | Vulnerability · Source |
| CVE-2026-84131 | redhat_vex | firefox: Privilege escalation due to invalid pointer in the Graphics component | fixed: 238 known affected: 8 | 2026-10-08T08:03:43+00:00 | Vulnerability · Source |
| CVE-2026-84639 | redhat_vex | thunderbird: Uninitialized memory in MIME parsing | fixed: 78 known affected: 5 | 2026-10-08T08:03:40+00:00 | Vulnerability · Source |
| CVE-2026-84145 | redhat_vex | firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 | fixed: 238 known affected: 8 | 2026-10-08T08:03:37+00:00 | Vulnerability · Source |
| CVE-2026-84143 | redhat_vex | firefox: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 | fixed: 238 known affected: 8 | 2026-10-08T08:03:36+00:00 | Vulnerability · Source |
| CVE-2026-84122 | redhat_vex | firefox: Use-after-free in the Audio/Video component | fixed: 238 known affected: 8 | 2026-10-08T08:03:33+00:00 | Vulnerability · Source |
| CVE-2026-84124 | redhat_vex | firefox: Use-after-free in the DOM: Core & HTML component | fixed: 238 known affected: 6 known not affected: 2 | 2026-10-08T08:03:32+00:00 | Vulnerability · Source |