VEX records
Browse vendor VEX statements available in this Vulnerability-Lookup instance and pivot to the related vulnerability.
78903 VEX records
API response| Vulnerability | Source | Title | Product status | Imported | Links |
|---|---|---|---|---|---|
| CVE-2026-90227 | redhat_vex | kernel: nvme/ioctl: check SUBMIT_IO with nvme_cmd_allowed() | fixed: 150 known affected: 187 known not affected: 42 | 2026-10-05T12:50:28+00:00 | Vulnerability · Source |
| CVE-2026-89481 | redhat_vex | kernel: nvme-tcp: fix host memory disclosure on R2T for a read command | fixed: 459 known affected: 110 known not affected: 42 | 2026-10-05T12:50:21+00:00 | Vulnerability · Source |
| CVE-2026-80921 | redhat_vex | kernel: KVM: s390: vsie: zero stale crypto bits | fixed: 150 known affected: 187 known not affected: 42 | 2026-10-05T12:50:17+00:00 | Vulnerability · Source |
| CVE-2026-74744 | redhat_vex | kernel: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev | fixed: 150 known affected: 185 known not affected: 42 | 2026-10-05T12:50:07+00:00 | Vulnerability · Source |
| CVE-2026-74669 | redhat_vex | kernel: ipvs: clear IPv4 options after rebasing tunnel ICMP errors | fixed: 150 known affected: 213 known not affected: 14 | 2026-10-05T12:50:00+00:00 | Vulnerability · Source |
| CVE-2026-74569 | redhat_vex | kernel: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() | fixed: 459 known affected: 136 under investigation: 14 | 2026-10-05T12:49:54+00:00 | Vulnerability · Source |
| CVE-2026-74516 | redhat_vex | kernel: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active | fixed: 150 known affected: 185 known not affected: 42 | 2026-10-05T12:49:50+00:00 | Vulnerability · Source |
| CVE-2026-72255 | redhat_vex | kernel: netfilter: nf_queue: pin bridge device while NFQUEUE holds fake dst | fixed: 150 known affected: 213 under investigation: 14 | 2026-10-05T12:49:45+00:00 | Vulnerability · Source |
| CVE-2026-72052 | redhat_vex | kernel: net: ip6_gre: require CAP_NET_ADMIN in the device netns for changelink | fixed: 150 known affected: 185 known not affected: 42 | 2026-10-05T12:49:40+00:00 | Vulnerability · Source |
| CVE-2026-68432 | redhat_vex | kernel: vxlan: require CAP_NET_ADMIN in the device netns for changelink | fixed: 150 known affected: 214 known not affected: 14 | 2026-10-05T12:49:40+00:00 | Vulnerability · Source |
| CVE-2026-63829 | redhat_vex | kernel: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink | fixed: 150 known affected: 213 known not affected: 14 | 2026-10-05T12:49:25+00:00 | Vulnerability · Source |
| CVE-2026-52972 | redhat_vex | kernel: crypto: af_alg - Cap AEAD AD length to 0x80000000 | fixed: 453 known affected: 99 known not affected: 42 | 2026-10-05T12:49:19+00:00 | Vulnerability · Source |
| CVE-2026-98116 | redhat_vex | kernel: ALSA: pcm: Serialize PCM mmap with buffer reallocation to fix page UAF | known affected: 233 known not affected: 42 | 2026-10-05T12:48:31+00:00 | Vulnerability · Source |
| CVE-2026-104872 | redhat_vex | @opentelemetry/instrumentation-cassandra-driver: @opentelemetry/instrumentation-knex: @opentelemetry/instrumentation-mongoose: @opentelemetry/instrumentation-mysql: @opentelemetry/instrumentation-mysql2: @opentelemetry/instrumentation-oracledb: @opentelemetry/instrumentation-pg: @opentelemetry/instrumentation-tedious: opentelemetry-js-contrib: Information disclosure via default database username emission in telemetry data | known affected: 2 | 2026-10-05T11:21:28+00:00 | Vulnerability · Source |
| CVE-2026-93112 | redhat_vex | kernel: bpf: Require a BPF cpumask for bpf_cpumask_populate() | known affected: 77 known not affected: 200 | 2026-10-05T11:19:54+00:00 | Vulnerability · Source |
| CVE-2026-86138 | redhat_vex | libxml2: libxml2: Arbitrary code execution via heap-based buffer overflow | fixed: 158 known affected: 12 known not affected: 36 | 2026-10-05T11:19:48+00:00 | Vulnerability · Source |
| CVE-2026-91960 | redhat_vex | FreeRDP: FreeRDP: Denial of Service via integer overflow and double free in WinPR | fixed: 65 known affected: 24 | 2026-10-05T10:49:24+00:00 | Vulnerability · Source |
| CVE-2026-85089 | redhat_vex | FreeRDP: freerdp-proxy: FreeRDP: Information disclosure via uninitialized heap memory in Save Session Info PDU | fixed: 65 known not affected: 24 | 2026-10-05T10:49:09+00:00 | Vulnerability · Source |
| CVE-2026-91946 | redhat_vex | FreeRDP: FreeRDP: Information Disclosure via RDPGFX ResetGraphics PDU | fixed: 65 known affected: 19 known not affected: 5 | 2026-10-05T10:49:09+00:00 | Vulnerability · Source |
| CVE-2026-24329 | redhat_vex | wildfly-core: WildFly Core: Denial of Service via malformed payload injection by an authenticated administrative user. | known affected: 6 | 2026-10-05T10:43:12+00:00 | Vulnerability · Source |
| CVE-2026-44172 | redhat_vex | mariadb: MariaDB server: SQL injection vulnerability via improper handling of big5 character set with mysql_real_escape_string() | fixed: 241 known not affected: 126 | 2026-10-05T10:27:06+00:00 | Vulnerability · Source |
| CVE-2026-91950 | redhat_vex | FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service or information disclosure | fixed: 65 known affected: 24 | 2026-10-05T10:23:21+00:00 | Vulnerability · Source |
| CVE-2026-91947 | redhat_vex | FreeRDP: FreeRDP: Use-after-free vulnerability in DRDYNVC parser leads to memory corruption | fixed: 65 known affected: 19 known not affected: 5 | 2026-10-05T10:23:18+00:00 | Vulnerability · Source |
| CVE-2026-96512 | redhat_vex | sudo: sudo: TZ environment variable allows bypass of NOTBEFORE/NOTAFTER time-based authorization | fixed: 88 known affected: 3 | 2026-10-05T10:23:15+00:00 | Vulnerability · Source |
| CVE-2026-97185 | redhat_vex | gimp: gimp: out-of-bounds write in GIMPressionist plugin via crafted preset file | fixed: 24 known affected: 33 | 2026-10-05T10:22:58+00:00 | Vulnerability · Source |
| CVE-2026-92248 | redhat_vex | gimp: integer overflow when generating a thumbnail preview for a PSD file | fixed: 24 known affected: 33 | 2026-10-05T10:22:54+00:00 | Vulnerability · Source |
| CVE-2026-90948 | redhat_vex | gimp: gimp: heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions | fixed: 24 known affected: 29 | 2026-10-05T10:22:49+00:00 | Vulnerability · Source |
| CVE-2026-90947 | redhat_vex | gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file | fixed: 24 known affected: 29 | 2026-10-05T10:22:45+00:00 | Vulnerability · Source |
| CVE-2026-15561 | redhat_vex | undertow-core: OOM via missing limits in chunked trailer in EAP's Undertow | fixed: 748 known affected: 1 known not affected: 2189 | 2026-10-05T09:29:37+00:00 | Vulnerability · Source |
| CVE-2026-72099 | redhat_vex | kernel: dm-integrity: don't increment hash_offset twice | fixed: 470 known affected: 108 known not affected: 42 | 2026-10-05T09:11:58+00:00 | Vulnerability · Source |
| CVE-2026-64034 | redhat_vex | kernel: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer | fixed: 773 known affected: 22 known not affected: 43 | 2026-10-05T09:10:53+00:00 | Vulnerability · Source |
| CVE-2026-104853 | redhat_vex | nx: Nx: Arbitrary file write via path traversal in migration planning | known not affected: 26 | 2026-10-05T09:06:00+00:00 | Vulnerability · Source |
| CVE-2026-104988 | redhat_vex | pki-core: dogtag-pki: redhat-pki: pki: EST fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject | known affected: 2 known not affected: 87 | 2026-10-05T09:05:46+00:00 | Vulnerability · Source |
| CVE-2026-104854 | redhat_vex | nx: Nx: Arbitrary code execution via insecure socket permissions | known not affected: 26 | 2026-10-05T09:05:45+00:00 | Vulnerability · Source |
| CVE-2026-103552 | redhat_vex | org.apache.directory.api/api-ldap-codec-core: Apache Directory LDAP API: Denial of Service via deeply nested search filter | known affected: 1 | 2026-10-05T09:05:35+00:00 | Vulnerability · Source |
| CVE-2026-59323 | redhat_vex | io.micrometer/micrometer-tracing-bridge-brave: Micrometer Tracing Brave Bridge: Denial of Service via W3C Baggage Propagation | known affected: 2 | 2026-10-05T09:04:16+00:00 | Vulnerability · Source |
| CVE-2026-96740 | redhat_vex | streamshub/console: console-operator: Streams for Apache Kafka Console: Unfiltered Kafka client properties → SA-token exfiltration via config.providers | known affected: 2 | 2026-10-05T08:55:59+00:00 | Vulnerability · Source |
| CVE-2026-91866 | redhat_vex | Neethi: Neethi: Denial of Service via crafted WS-Policy documents | known affected: 8 known not affected: 2 | 2026-10-05T08:55:50+00:00 | Vulnerability · Source |
| CVE-2026-91865 | redhat_vex | org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents | known affected: 8 known not affected: 2 | 2026-10-05T08:55:49+00:00 | Vulnerability · Source |
| CVE-2026-91864 | redhat_vex | org.apache.neethi/neethi: Apache Neethi: Denial of Service via crafted WS-Policy documents | known affected: 8 known not affected: 2 | 2026-10-05T08:55:46+00:00 | Vulnerability · Source |
| CVE-2026-88881 | redhat_vex | renovate: Renovate before 44.11.3 Credential Exfiltration via Link Header | known not affected: 1 | 2026-10-05T08:55:44+00:00 | Vulnerability · Source |
| CVE-2026-91863 | redhat_vex | org.apache.neethi/neethi: Apache Neethi: Denial of Service via uncontrolled recursion in WS-Policy document parsing | known affected: 8 known not affected: 2 | 2026-10-05T08:55:44+00:00 | Vulnerability · Source |
| CVE-2021-3506 | redhat_vex | kernel: Out of bounds memory access bug in get_next_net_page() in fs/f2fs/node.c | known not affected: 197 | 2026-10-05T08:55:08+00:00 | Vulnerability · Source |
| CVE-2021-3739 | redhat_vex | kernel: null-ptr-dereference bug in btrfs_rm_device in fs/btrfs/volumes.c | known not affected: 197 | 2026-10-05T08:55:08+00:00 | Vulnerability · Source |
| CVE-2026-63622 | redhat_vex | libvirt: swtpm privilege escalation via symlink following | fixed: 4472 known affected: 32 known not affected: 6 | 2026-10-05T08:29:44+00:00 | Vulnerability · Source |
| CVE-2026-18917 | redhat_vex | libvirt: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow | fixed: 4472 known affected: 32 known not affected: 6 | 2026-10-05T08:29:44+00:00 | Vulnerability · Source |
| CVE-2026-72887 | redhat_vex | Net-OAuth: Net::OAuth::Client: Session fixation via OAuth 1.0a downgrade | known not affected: 1 | 2026-10-05T06:56:02+00:00 | Vulnerability · Source |
| CVE-2026-84305 | redhat_vex | sqlparse: sqlparse: Denial of Service via reindentation of tuple lists | known not affected: 10 under investigation: 191 | 2026-10-05T06:47:02+00:00 | Vulnerability · Source |
| CVE-2026-105302 | redhat_vex | keycloak-services: keycloak-services: User Session Note mapper exposes upstream IdP access tokens | known affected: 2 known not affected: 1 | 2026-10-05T06:15:16+00:00 | Vulnerability · Source |
| CVE-2026-105306 | redhat_vex | keycloak-services: keycloak-services: Token introspection audience bypass via Dynamic Client Registration | known affected: 2 known not affected: 1 | 2026-10-05T06:15:16+00:00 | Vulnerability · Source |