Free & Open Source
Know which vulnerabilities actually affect you
Free to use. No account. Search by CVE or upload an SBOM below.
Enter a CVE ID to see vendor VEX statements.
Pipe vex-hub into the scanner you already run. Copy-paste recipes, reproducible against public images.
Vendors publish statements saying whether a CVE actually affects their product. Scanners produce long lists of CVEs; VEX lets you quiet the noise.
Vendor confirms the CVE does not affect their product. Safe to suppress.
A fix is available. Update to the patched version.
Vendor is still assessing impact. Monitor for updates.
Vendor confirms the product is exploitable. Plan mitigation.
Free to use. No API key required.
/v1/cve/{CVE-ID}All vendor statements for one CVE.
/v1/resolveBatch match CVEs against product IDs. Optional source_formats filter.
/v1/sbomUpload a CycloneDX SBOM; get it back annotated with VEX analysis on each vulnerability.
/v1/statsVendor / CVE / statement / product-mapping counts.
Aggregated from vendor security feeds. Updated daily.