Skip to content
Noroxi

hex records

9 published records for vendor hex.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

9 records
  • Password Reset Tokens Do Not Expire

    CriticalCVSS 9.5No exploitEPSS 0%

    hex · hexpmMar 5, 2026

  • Hex package manager hex_core version 0.3.0 and earlier contains a Signing oracle vulnerability in Package registry verification that can res

    HighCVSS 8.8No exploitEPSS 1%

    hex · hex coreFeb 4, 2019

  • Hex package manager version 0.14.0 through 0.18.2 contains a Signing oracle vulnerability in Package registry verification that can result i

    HighCVSS 8.8No exploitEPSS 1%

    hex · hexFeb 4, 2019

  • Lockfile checksums not verified in Hex allows dependency integrity bypass

    HighCVSS 8.9No exploitEPSS 0%

    hex · hexApr 30, 2026

  • Cross-site scripting (XSS) in OAuth Device Authorization screen

    HighCVSS 8.5No exploitEPSS 0%

    hex · hexpmJan 19, 2026

  • Denial of Service via Oversized Package Upload

    HighCVSS 7.1No exploitEPSS 0%

    hex · hexpmMar 13, 2026

  • Improper Scope Enforcement in OAuth client_credentials Flow Allows Read-Only API Key to Escalate to Full Access

    HighCVSS 7.0No exploitEPSS 0%

    hex · hexpmMar 5, 2026

  • Path Traversal in Local File Store Backend

    MediumCVSS 6.9No exploitEPSS 0%

    hex · hexpmFeb 26, 2026

  • Unsafe Deserialization of Erlang Terms in hex_core

    LowCVSS 2.0No exploitEPSS 1%

    hex · hexFeb 27, 2026