VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
81851 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2026-98238 | suse_vex | SUSE CVE CVE-2026-98238 | known affected: 30 known not affected: 317 | 2026-10-07T23:45:40+00:00 | Vulnerability · Source |
| CVE-2026-98248 | suse_vex | SUSE CVE CVE-2026-98248 | known affected: 146 known not affected: 201 | 2026-10-07T23:45:37+00:00 | Vulnerability · Source |
| CVE-2026-98263 | suse_vex | SUSE CVE CVE-2026-98263 | known affected: 30 known not affected: 317 | 2026-10-07T23:45:34+00:00 | Vulnerability · Source |
| CVE-2026-98265 | suse_vex | SUSE CVE CVE-2026-98265 | known affected: 49 known not affected: 298 | 2026-10-07T23:45:31+00:00 | Vulnerability · Source |
| CVE-2026-98277 | suse_vex | SUSE CVE CVE-2026-98277 | known affected: 29 known not affected: 318 | 2026-10-07T23:45:28+00:00 | Vulnerability · Source |
| CVE-2026-98306 | suse_vex | SUSE CVE CVE-2026-98306 | known affected: 254 known not affected: 93 | 2026-10-07T23:45:25+00:00 | Vulnerability · Source |
| CVE-2026-98325 | suse_vex | SUSE CVE CVE-2026-98325 | known affected: 265 known not affected: 82 | 2026-10-07T23:45:22+00:00 | Vulnerability · Source |
| CVE-2026-98332 | suse_vex | SUSE CVE CVE-2026-98332 | known affected: 265 known not affected: 82 | 2026-10-07T23:45:20+00:00 | Vulnerability · Source |
| CVE-2026-98338 | suse_vex | SUSE CVE CVE-2026-98338 | known affected: 347 | 2026-10-07T23:45:17+00:00 | Vulnerability · Source |
| CVE-2026-98361 | suse_vex | SUSE CVE CVE-2026-98361 | known not affected: 347 | 2026-10-07T23:45:15+00:00 | Vulnerability · Source |
| CVE-2026-98368 | suse_vex | SUSE CVE CVE-2026-98368 | known affected: 108 known not affected: 239 | 2026-10-07T23:45:13+00:00 | Vulnerability · Source |
| CVE-2026-103484 | suse_vex | SUSE CVE CVE-2026-103484 | known affected: 36 recommended: 1 | 2026-10-07T23:45:09+00:00 | Vulnerability · Source |
| CVE-2026-63990 | redhat_vex | kernel: bonding: refuse to enslave CAN devices | known affected: 275 known not affected: 1 | 2026-10-07T23:37:25+00:00 | Vulnerability · Source |
| CVE-2015-8851 | redhat_vex | nodejs-node-uuid: insecure entropy source - Math.random() | fixed: 14 known affected: 1 | 2026-10-07T23:31:27+00:00 | Vulnerability · Source |
| CVE-2021-20267 | redhat_vex | openstack-neutron: Anti-spoofing bypass using Open vSwitch | known affected: 58 known not affected: 1 | 2026-10-07T23:31:24+00:00 | Vulnerability · Source |
| CVE-2026-63986 | redhat_vex | kernel: ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure | known affected: 185 known not affected: 90 | 2026-10-07T23:30:25+00:00 | Vulnerability · Source |
| CVE-2019-16943 | redhat_vex | jackson-databind: Serialization gadgets in com.p6spy.engine.spy.P6DataSource | fixed: 441 known affected: 23 known not affected: 3 | 2026-10-07T23:30:24+00:00 | Vulnerability · Source |
| CVE-2026-69248 | redhat_vex | python-cryptography: python-cryptography: python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees | fixed: 36 known affected: 8 known not affected: 9 | 2026-10-07T23:25:13+00:00 | Vulnerability · Source |
| CVE-2026-89425 | redhat_vex | com.fasterxml.jackson.core/jackson-core: Jackson-core: Denial of Service via unbounded StringBuilder growth during malformed token processing | known affected: 141 known not affected: 42 | 2026-10-07T23:06:45+00:00 | Vulnerability · Source |
| CVE-2023-5077 | redhat_vex | hashicorp/vault: Google Cloud Secrets Engine Removed Existing IAM Conditions When Creating / Updating Rolesets | fixed: 8 known affected: 5 known not affected: 746 | 2026-10-07T22:53:33+00:00 | Vulnerability · Source |
| CVE-2023-3775 | redhat_vex | hashicorp/vault: vault enterprise’s sentinel RGP policies allowed for cross-namespace denial of service | fixed: 4 known not affected: 676 | 2026-10-07T22:53:28+00:00 | Vulnerability · Source |
| CVE-2026-103885 | redhat_vex | org.apache.directory.api/api-ldap-model: Apache Directory LDAP API: Denial of Service via crafted telephone numbers | known affected: 1 | 2026-10-07T22:50:12+00:00 | Vulnerability · Source |
| CVE-2026-103877 | redhat_vex | org.apache.directory.api/api-ldap-client-api: Apache Directory LDAP API: Remote code execution via untrusted Java object deserialization | known affected: 1 | 2026-10-07T22:50:08+00:00 | Vulnerability · Source |
| CVE-2021-27290 | redhat_vex | nodejs-ssri: Regular expression DoS (ReDoS) when parsing malicious SRI in strict mode | fixed: 200 known affected: 52 known not affected: 3 | 2026-10-07T22:49:23+00:00 | Vulnerability · Source |
| CVE-2021-23440 | redhat_vex | nodejs-set-value: type confusion allows bypass of CVE-2019-10747 | fixed: 3 known affected: 26 known not affected: 82 | 2026-10-07T22:49:20+00:00 | Vulnerability · Source |
| CVE-2021-23382 | redhat_vex | nodejs-postcss: ReDoS via getAnnotationURL() and loadAnnotation() in lib/previous-map.js | fixed: 4 known affected: 15 known not affected: 398 | 2026-10-07T22:49:16+00:00 | Vulnerability · Source |
| CVE-2021-23368 | redhat_vex | nodejs-postcss: Regular expression denial of service during source map parsing | fixed: 4 known affected: 20 known not affected: 395 | 2026-10-07T22:49:13+00:00 | Vulnerability · Source |
| CVE-2020-27813 | redhat_vex | golang-github-gorilla-websocket: integer overflow leads to denial of service | fixed: 19 known affected: 31 known not affected: 533 | 2026-10-07T22:46:05+00:00 | Vulnerability · Source |
| CVE-2017-16138 | redhat_vex | nodejs-mime: Regular expression Denial of Service | fixed: 1 known affected: 4 known not affected: 20 | 2026-10-07T22:45:47+00:00 | Vulnerability · Source |
| CVE-2024-1102 | redhat_vex | jberet: jberet-core logging database credentials | fixed: 24 known affected: 11 known not affected: 2768 | 2026-10-07T22:44:29+00:00 | Vulnerability · Source |
| CVE-2023-4639 | redhat_vex | undertow: Cookie Smuggling/Spoofing | fixed: 27 known affected: 1 known not affected: 2449 under investigation: 10 | 2026-10-07T22:44:26+00:00 | Vulnerability · Source |
| CVE-2026-85494 | redhat_vex | thrift: thrift: Denial of Service via improper message handling in language bindings | fixed: 13 known affected: 12 | 2026-10-07T22:40:49+00:00 | Vulnerability · Source |
| CVE-2020-9547 | redhat_vex | jackson-databind: Serialization gadgets in ibatis-sqlmap | fixed: 2591 known affected: 12 known not affected: 18 | 2026-10-07T22:39:41+00:00 | Vulnerability · Source |
| CVE-2021-29505 | redhat_vex | XStream: remote command execution attack by manipulating the processed input stream | fixed: 18 known affected: 10 known not affected: 4 | 2026-10-07T22:07:37+00:00 | Vulnerability · Source |
| CVE-2020-9546 | redhat_vex | jackson-databind: Serialization gadgets in shaded-hikari-config | fixed: 2590 known affected: 13 known not affected: 18 | 2026-10-07T22:07:21+00:00 | Vulnerability · Source |
| CVE-2024-1635 | redhat_vex | undertow: Out-of-memory Error after several closed connections with wildfly-http-client protocol | fixed: 109 known affected: 4 known not affected: 2456 | 2026-10-07T21:29:48+00:00 | Vulnerability · Source |
| CVE-2023-1973 | redhat_vex | undertow: unrestricted request storage leads to memory exhaustion | fixed: 99 known not affected: 2444 | 2026-10-07T21:29:22+00:00 | Vulnerability · Source |
| CVE-2026-63991 | redhat_vex | kernel: Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() | known affected: 77 known not affected: 198 | 2026-10-07T21:22:39+00:00 | Vulnerability · Source |
| CVE-2026-102267 | redhat_vex | pyjwt: pyjwt: Verification key substitution via unvalidated JWKS redirects | known not affected: 4 | 2026-10-07T21:22:01+00:00 | Vulnerability · Source |
| CVE-2026-102266 | redhat_vex | pyjwt: pyjwt: Authentication bypass via empty HMAC key acceptance | known not affected: 4 | 2026-10-07T21:21:55+00:00 | Vulnerability · Source |
| CVE-2016-0738 | redhat_vex | openstack-swift: Proxy to server DoS through Large Objects | fixed: 42 known affected: 18 known not affected: 6 | 2026-10-07T21:20:10+00:00 | Vulnerability · Source |
| CVE-2026-105743 | redhat_vex | docling: docling: Server-Side Request Forgery via improper URL validation | known affected: 7 | 2026-10-07T20:28:47+00:00 | Vulnerability · Source |
| CVE-2026-105742 | redhat_vex | docling: docling: Information disclosure via cross-origin header leakage during remote image fetching | known affected: 7 | 2026-10-07T20:28:45+00:00 | Vulnerability · Source |
| CVE-2026-95368 | redhat_vex | chromium-browser: Incorrect authorization in DevTools | known not affected: 1 | 2026-10-07T20:28:43+00:00 | Vulnerability · Source |
| CVE-2026-95385 | redhat_vex | chromium-browser: Inappropriate implementation in PlatformIntegration | known not affected: 1 | 2026-10-07T20:28:43+00:00 | Vulnerability · Source |
| CVE-2026-95380 | redhat_vex | chromium-browser: Type confusion in V8 | known not affected: 1 | 2026-10-07T20:28:40+00:00 | Vulnerability · Source |
| CVE-2026-95367 | redhat_vex | chromium-browser: Information leak in DataTransfer | known not affected: 1 | 2026-10-07T20:28:36+00:00 | Vulnerability · Source |
| CVE-2026-95364 | redhat_vex | chromium-browser: Improper input validation in Passwords | known not affected: 1 | 2026-10-07T20:28:35+00:00 | Vulnerability · Source |
| CVE-2026-95361 | redhat_vex | chromium-browser: Confused deputy in DevTools | known not affected: 1 | 2026-10-07T20:28:34+00:00 | Vulnerability · Source |
| CVE-2026-95352 | redhat_vex | chromium-browser: Incorrect authorization in DevTools | known not affected: 1 | 2026-10-07T20:28:30+00:00 | Vulnerability · Source |