hex records
9 published records for vendor hex.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption2
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-613 Insufficient Session Expiration1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-21622No exploit | Password Reset Tokens Do Not Expirehex · hexpm · CWE-613 | Critical9.5 | — | 0.4% | Mar 5, 2026 |
35Monitor | CVE-2019-1000013No exploit | Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can reshex · hex core · CWE-345 | High8.8 | — | 0.9% | Feb 4, 2019 |
35Monitor | CVE-2019-1000012No exploit | Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result ihex · hex · CWE-345 | High8.8 | — | 0.9% | Feb 4, 2019 |
35Monitor | CVE-2026-32148No exploit | Lockfile checksums not verified in Hex allows dependency integrity bypasshex · hex · CWE-354 | High8.9 | — | 0.3% | Apr 30, 2026 |
34Monitor | CVE-2026-21618No exploit | Cross-site scripting (XSS) in OAuth Device Authorization screenhex · hexpm · CWE-79 | High8.5 | — | 0.3% | Jan 19, 2026 |
28Monitor | CVE-2026-23940No exploit | Denial of Service via Oversized Package Uploadhex · hexpm · CWE-400 | High7.1 | — | 0.4% | Mar 13, 2026 |
28Monitor | CVE-2026-21621No exploit | Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Accesshex · hexpm · CWE-863 | High7.0 | — | 0.3% | Mar 5, 2026 |
27Monitor | CVE-2026-23939No exploit | Path Traversal in Local File Store Backendhex · hexpm · CWE-22 | Medium6.9 | — | 0.4% | Feb 26, 2026 |
8Monitor | CVE-2026-21619No exploit | Unsafe Deserialization of Erlang Terms in hex_corehex · hex · CWE-400 | Low2.0 | — | 0.6% | Feb 27, 2026 |
- CVE-2026-2162238Monitor
Password Reset Tokens Do Not Expire
CriticalCVSS 9.5No exploitEPSS 0%hex · hexpmMar 5, 2026
- CVE-2019-100001335Monitor
Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can res
HighCVSS 8.8No exploitEPSS 1%hex · hex coreFeb 4, 2019
- CVE-2019-100001235Monitor
Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result i
HighCVSS 8.8No exploitEPSS 1%hex · hexFeb 4, 2019
- CVE-2026-3214835Monitor
Lockfile checksums not verified in Hex allows dependency integrity bypass
HighCVSS 8.9No exploitEPSS 0%hex · hexApr 30, 2026
- CVE-2026-2161834Monitor
Cross-site scripting (XSS) in OAuth Device Authorization screen
HighCVSS 8.5No exploitEPSS 0%hex · hexpmJan 19, 2026
- CVE-2026-2394028Monitor
Denial of Service via Oversized Package Upload
HighCVSS 7.1No exploitEPSS 0%hex · hexpmMar 13, 2026
- CVE-2026-2162128Monitor
Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access
HighCVSS 7.0No exploitEPSS 0%hex · hexpmMar 5, 2026
- CVE-2026-2393927Monitor
Path Traversal in Local File Store Backend
MediumCVSS 6.9No exploitEPSS 0%hex · hexpmFeb 26, 2026
- CVE-2026-216198Monitor
Unsafe Deserialization of Erlang Terms in hex_core
LowCVSS 2.0No exploitEPSS 1%hex · hexFeb 27, 2026