#vex

6 posts · Last used 23d

Back to Timeline
Cedric @cedric@social.circl.lu · Jul 15, 2026
You can now browse VEX statements in Vulnerability-Lookup! The new VEX page lets you explore 220k+ vendor VEX records (Red Hat, Microsoft MSRC, more coming), filter by source, search by CVE ID or title, see product statuses at a glance (fixed, known affected, not affected, under investigation) and pivot straight to the related vulnerability. 🔎 https://vulnerability.circl.lu/vex/ 🧩 API: https://vulnerability.circl.lu/api/vex/ #VEX #VulnerabilityLookup #CVE #GCVE #OpenSource #CyberSecurity
1
0
1
Cedric @cedric@social.circl.lu · Jul 20, 2026
282,000+ VEX records are now in Vulnerability-Lookup 🎉 🔎 https://vulnerability.circl.lu/vex SUSE just joined Red Hat and Microsoft as a VEX source — so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected. VEX statements are attached directly to each vulnerability and available via the open API. 🧑‍💻 https://github.com/vulnerability-lookup/vulnerability-lookup #VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
0
0
1
Marius Biebel @mariuxdeangelo@infosec.exchange · Jul 14, 2026
Vulnerability Exploitability eXchange #VEX and its use in the industry as part of a master’s thesis. To this end, he is conducting an online survey of companies from various industries to examine the current state of VEX usage (or lack thereof). If you are willing to take part in this survey please let me know.
0
0
0
Cedric @cedric@fosstodon.org · Jul 10, 2026
🆕 Vulnerability-Lookup now imports Microsoft CSAF VEX documents from MSRC — joining the Red Hat VEX feed as a vendor VEX enrichment source. Per-CVE VEX statements (product status, severity) are attached directly to CVE records, visible on the vulnerability page and via the API with the full CSAF documents. Example with both Red Hat and Microsoft VEX: https://vulnerability.circl.lu/vuln/CVE-2026-53359#vex #VEX #CSAF #VulnerabilityManagement #CVE #OpenSource
1
0
2
anchore @anchore@mstdn.business · Apr 05, 2026
"Knowing if you are truly exposed is critical in this space." For embedded systems, proof of non-exposure > remediation. Learn how VEX and System BOMs are saving manufacturers millions in unnecessary patching cycles. https://anchore.com/blog/the-s-in-sbom-is-for-system/ #VEX #SBOM
0
0
0
anchore @anchore__dup_33412@mstdn.business · Feb 26, 2026
"Knowing if you are truly exposed is critical in this space." For embedded systems, proof of non-exposure > remediation. Learn how VEX and System BOMs are saving manufacturers millions in unnecessary patching cycles. https://anchore.com/blog/the-s-in-sbom-is-for-system/ #VEX #SBOM
0
0
0

You've seen all posts