You can now browse VEX statements in Vulnerability-Lookup!
The new VEX page lets you explore 220k+ vendor VEX records (Red Hat, Microsoft MSRC, more coming), filter by source, search by CVE ID or title, see product statuses at a glance (fixed, known affected, not affected, under investigation) and pivot straight to the related vulnerability.
🔎 https://vulnerability.circl.lu/vex/
🧩 API: https://vulnerability.circl.lu/api/vex/
#VEX #VulnerabilityLookup #CVE #GCVE #OpenSource #CyberSecurity
282,000+ VEX records are now in Vulnerability-Lookup 🎉
🔎 https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
🧑💻 https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
Marius Biebel
@mariuxdeangelo@infosec.exchange
Somehow IT security related. The guy behind http://sbom-catalog.openssf.org/
infosec.exchange
Vulnerability Exploitability eXchange #VEX and its use in the industry as part of a master’s thesis.
To this end, he is conducting an online survey of companies from various industries to examine the current state of VEX usage (or lack thereof).
If you are willing to take part in this survey please let me know.
🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source.
Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents.
Example with both Red Hat and Microsoft VEX:
https://vulnerability.circl.lu/vuln/CVE-2026-53359#vex
#VEX #CSAF #VulnerabilityManagement #CVE #OpenSource
"Knowing if you are truly exposed is critical in this space."
For embedded systems, proof of non-exposure > remediation.
Learn how VEX and System BOMs are saving manufacturers millions in unnecessary patching cycles.
https://anchore.com/blog/the-s-in-sbom-is-for-system/
#VEX #SBOM
"Knowing if you are truly exposed is critical in this space."
For embedded systems, proof of non-exposure > remediation.
Learn how VEX and System BOMs are saving manufacturers millions in unnecessary patching cycles.
https://anchore.com/blog/the-s-in-sbom-is-for-system/
#VEX #SBOM
You've seen all posts