VEX records

Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.

Reset

81700 VEX records

API response
Vulnerability Source Title Product status Imported Links
CVE-2026-103009 redhat_vex elasticsearch: Elasticsearch: Information disclosure via crafted cross-cluster search requests known affected: 1 known not affected: 2 2026-10-08T11:34:57+00:00 Vulnerability · Source
CVE-2026-84637 redhat_vex thunderbird: Thunderbird: Arbitrary code execution via malicious calendar invitation attachments known not affected: 6 2026-10-08T11:34:52+00:00 Vulnerability · Source
CVE-2026-84125 redhat_vex firefox: Firefox: Arbitrary code execution via use-after-free in DOM: Core & HTML known not affected: 9 2026-10-08T11:34:47+00:00 Vulnerability · Source
CVE-2024-26147 redhat_vex helm: Missing YAML Content Leads To Panic fixed: 122 known affected: 10 known not affected: 2499 2026-10-08T11:34:02+00:00 Vulnerability · Source
CVE-2024-25620 redhat_vex helm: Dependency management path traversal fixed: 82 known affected: 7 known not affected: 1181 2026-10-08T11:34:02+00:00 Vulnerability · Source
CVE-2026-98364 redhat_vex kernel: xfrm: hold net_device reference under RCU in bundle creation known affected: 263 under investigation: 14 2026-10-08T11:33:29+00:00 Vulnerability · Source
CVE-2023-27561 redhat_vex runc: volume mount race condition (regression of CVE-2019-19921) fixed: 556 known affected: 40 known not affected: 1666 2026-10-08T11:28:59+00:00 Vulnerability · Source
CVE-2021-36157 redhat_vex cortex: Grafana Cortex directory traversal fixed: 8 known affected: 3 known not affected: 830 2026-10-08T11:28:54+00:00 Vulnerability · Source
CVE-2026-80521 redhat_vex kernel: af_unix: Unlink scc_entry in unix_del_edge() fixed: 307 known affected: 77 known not affected: 198 2026-10-08T11:21:44+00:00 Vulnerability · Source
CVE-2026-64007 redhat_vex kernel: netfilter: synproxy: refresh tcphdr after skb_ensure_writable fixed: 1235 known affected: 127 known not affected: 15 2026-10-08T11:21:41+00:00 Vulnerability · Source
CVE-2026-52924 redhat_vex kernel: sctp: purge outqueue on stale COOKIE-ECHO handling fixed: 2122 known affected: 22 known not affected: 42 2026-10-08T11:21:34+00:00 Vulnerability · Source
CVE-2026-64582 redhat_vex kernel: RDMA/rxe: Fix a use-after-free problem in rxe_mmap fixed: 1305 known affected: 50 known not affected: 91 2026-10-08T11:21:19+00:00 Vulnerability · Source
CVE-2026-64386 redhat_vex kernel: smb: client: fix query_info() replay double-free fixed: 1224 known affected: 22 known not affected: 91 2026-10-08T11:21:14+00:00 Vulnerability · Source
CVE-2026-64383 redhat_vex kernel: smb: client: fix double-free in SMB2_flush() replay fixed: 1224 known affected: 22 known not affected: 90 2026-10-08T11:21:05+00:00 Vulnerability · Source
CVE-2026-88815 redhat_vex perl-DBI: perl-DBI: Denial of Service via invalid memory read during numeric type casting fixed: 36 known affected: 4 2026-10-08T11:20:54+00:00 Vulnerability · Source
CVE-2026-91964 redhat_vex FreeRDP: FreeRDP: Remote code execution via heap buffer overflow in Server Redirection PDU fixed: 195 known affected: 12 2026-10-08T11:20:50+00:00 Vulnerability · Source
CVE-2026-91963 redhat_vex FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure fixed: 195 known affected: 12 2026-10-08T11:20:37+00:00 Vulnerability · Source
CVE-2024-45338 redhat_vex golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html fixed: 2836 known affected: 126 known not affected: 16031 2026-10-08T11:14:46+00:00 Vulnerability · Source
CVE-2025-22865 redhat_vex crypto/x509: ParsePKCS1PrivateKey panic with partial keys in crypto/x509 fixed: 25 known affected: 4 known not affected: 328 2026-10-08T11:07:48+00:00 Vulnerability · Source
CVE-2024-29041 redhat_vex express: cause malformed URLs to be evaluated fixed: 227 known affected: 59 known not affected: 600 2026-10-08T11:04:07+00:00 Vulnerability · Source
CVE-2025-21614 redhat_vex go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies fixed: 527 known affected: 18 known not affected: 968 under investigation: 221 2026-10-08T11:03:30+00:00 Vulnerability · Source
CVE-2025-21613 redhat_vex go-git: argument injection via the URL field fixed: 553 known affected: 16 known not affected: 1075 2026-10-08T11:03:11+00:00 Vulnerability · Source
CVE-2024-38816 redhat_vex spring-webmvc: Path Traversal Vulnerability in Spring Applications Using RouterFunctions and FileSystemResource fixed: 2 known affected: 8 known not affected: 8 2026-10-08T10:55:14+00:00 Vulnerability · Source
CVE-2024-7885 redhat_vex undertow: Improper State Management in Proxy Protocol parsing causes information leakage fixed: 146 known affected: 9 known not affected: 2198 2026-10-08T10:55:07+00:00 Vulnerability · Source
CVE-2023-33953 redhat_vex gRPC: hpack table accounting errors can lead to denial of service fixed: 9 known not affected: 479 2026-10-08T10:54:25+00:00 Vulnerability · Source
CVE-2024-21626 redhat_vex runc: file descriptor leak fixed: 2007 known affected: 38 known not affected: 2786 2026-10-08T10:53:41+00:00 Vulnerability · Source
CVE-2024-47072 redhat_vex com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream fixed: 35 known affected: 10 known not affected: 12 2026-10-08T10:53:15+00:00 Vulnerability · Source
CVE-2024-29415 redhat_vex node-ip: Incomplete fix for CVE-2023-42282 fixed: 3 known affected: 6 known not affected: 136 2026-10-08T10:48:15+00:00 Vulnerability · Source
CVE-2024-47875 redhat_vex dompurify: nesting-based mutation XSS vulnerability fixed: 224 known affected: 15 known not affected: 2689 2026-10-08T10:46:43+00:00 Vulnerability · Source
CVE-2026-106550 redhat_vex convict: convict: Denial of Service via prototype pollution in config.set() known affected: 1 2026-10-08T09:53:12+00:00 Vulnerability · Source
CVE-2026-85234 redhat_vex tftp: tftp-hpa: Denial of Service due to out-of-bounds read/write in remap engine fixed: 21 known affected: 8 known not affected: 1 2026-10-08T09:13:25+00:00 Vulnerability · Source
CVE-2026-103008 redhat_vex elasticsearch: elasticsearch: Denial of Service via uncontrolled recursion in scripted runtime fields known affected: 1 known not affected: 2 2026-10-08T09:09:24+00:00 Vulnerability · Source
CVE-2026-103005 redhat_vex elasticsearch: Elasticsearch: Denial of Service via excessive memory allocation in connector descriptions known affected: 1 known not affected: 2 2026-10-08T09:09:19+00:00 Vulnerability · Source
CVE-2026-107466 redhat_vex flatpak-builder: Local File Exfiltration via `file known affected: 4 2026-10-08T08:52:16+00:00 Vulnerability · Source
CVE-2026-98173 redhat_vex kernel: smb: client: fix use-after-free of iface in cifs_try_adding_channels() known affected: 234 known not affected: 43 2026-10-08T08:52:13+00:00 Vulnerability · Source
CVE-2026-97404 redhat_vex zaqar: OpenStack Zaqar: authentication bypass via empty URL-Signature header known affected: 4 2026-10-08T08:52:11+00:00 Vulnerability · Source
CVE-2025-61163 redhat_vex Cohere North AI: Cohere North AI: Information disclosure via improper Origin header validation known not affected: 1 2026-10-08T08:52:07+00:00 Vulnerability · Source
CVE-2017-7214 redhat_vex openstack-nova: Sensitive information included in legacy notification exception contexts fixed: 43 known affected: 42 known not affected: 37 2026-10-08T08:52:01+00:00 Vulnerability · Source
CVE-2026-78030 redhat_vex perl-DBI: DBI: Loading of arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM known affected: 10 2026-10-08T08:51:42+00:00 Vulnerability · Source
CVE-2025-61164 redhat_vex Cohere North AI: Cohere North AI: Information Leak via WebSocket Endpoint known not affected: 1 2026-10-08T08:51:38+00:00 Vulnerability · Source
CVE-2022-3100 redhat_vex openstack-barbican: access policy bypass via query string injection fixed: 23 known not affected: 19 2026-10-08T08:51:32+00:00 Vulnerability · Source
CVE-2025-61162 redhat_vex Cohere North AI: Cohere North AI: Arbitrary user information overwrite via incorrect access control known not affected: 1 2026-10-08T08:51:32+00:00 Vulnerability · Source
CVE-2021-40085 redhat_vex openstack-neutron: arbitrary dnsmasq reconfiguration via extra_dhcp_opts fixed: 56 known not affected: 15 2026-10-08T08:51:30+00:00 Vulnerability · Source
CVE-2020-17376 redhat_vex openstack-nova: Soft reboot after live-migration reverts instance to original source domain XML fixed: 93 known affected: 13 known not affected: 13 2026-10-08T08:51:18+00:00 Vulnerability · Source
CVE-2015-1195 redhat_vex openstack-glance: unrestricted path traversal flaw (incomplete fix for CVE-2014-9493) (OSSA 2015-002) known not affected: 14 2026-10-08T08:51:18+00:00 Vulnerability · Source
CVE-2014-9493 redhat_vex openstack-glance: unrestricted path traversal flaw fixed: 12 known affected: 1 known not affected: 11 2026-10-08T08:51:18+00:00 Vulnerability · Source
CVE-2016-0737 redhat_vex openstack-swift: Client to proxy DoS through Large Objects fixed: 42 known affected: 18 known not affected: 6 2026-10-08T08:51:18+00:00 Vulnerability · Source
CVE-2016-2140 redhat_vex openstack-nova: Host data leak through resize/migration fixed: 65 known not affected: 59 2026-10-08T08:51:18+00:00 Vulnerability · Source
CVE-2026-18212 redhat_vex keycloak-services: keycloak-services: SAML Redirect DEFLATE helpers leak native zlib state fixed: 20 known affected: 2 known not affected: 1 2026-10-08T08:23:57+00:00 Vulnerability · Source
CVE-2026-15573 redhat_vex keycloak-services: keycloak-services: Authorization bypass via unnormalized URI matching in PathMatcher fixed: 20 known affected: 2 known not affected: 1 2026-10-08T08:23:52+00:00 Vulnerability · Source