Skip to main content

Vulnerability Explorer (vex)

Python Version Code style: ruff CLI: Rich License: MIT

A git-native, interactive terminal reference and structured knowledge base for software vulnerabilities.

Imagine man pages built specifically for application security. Vulnerability Explorer is a curated, structured knowledge base of software vulnerabilities combined with a versatile command-line tool (vex).

❯ vex list

                                     Catalog Entries
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━┓
┃ ID                                  ┃ Type          ┃ Title                  ┃ Langs  ┃
┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━┩
│ injection.sql-injection             │ concept       │ SQL Injection          │ -      │
│ injection.sql.inband.go-database... │ manifestation │ Classic In-Band SQLi...│ go     │
│ injection.sql.inband.java-jdbc...   │ manifestation │ Classic In-Band SQLi...│ java   │
│ injection.sql.inband.php-mysqli...  │ manifestation │ Classic In-Band SQLi...│ php    │
│ injection.sql.inband.python-psyc... │ manifestation │ Classic In-Band SQLi...│ python │
└─────────────────────────────────────┴───────────────┴────────────────────────┴────────┘

Why Vulnerability Explorer?

Traditional vulnerability databases (like CVEs or the NVD) focus on tracking patches for specific software versions. Vulnerability Explorer focuses on the code.

Every entry in our catalog is an atomic Markdown file enriched with strict YAML frontmatter. We document concrete vulnerability mechanisms (manifestations) across specific languages, frameworks, and architectures:

  • White-box identification: Side-by-side vulnerable vs. safe code snippets and taint patterns.
  • Gray/Black-box behavior: Observable indicators, error disclosures, and exploitation methodologies.
  • Remediation: Primary fixes, strict allowlisting, and common mitigation mistakes.

Who is this for?

Audience How They Use vex
Security Engineers Fast terminal reference during pentests, code reviews, and report writing.
Developers Learn root causes and immediately compare vulnerable code with the secure fix.
AI Agents & LLMs Consume structured datasets or autonomously generate new vulnerability entries.
Educators & Students Teach or learn standardized taxonomy, recognition signals, and threat modeling.

Quick Start

1. Installation

From PyPI

# Using pip
pip install vulnerability-explorer

# Or using uv (recommended)
uv pip install vulnerability-explorer

From Source (For Contributors)

git clone https://github.com/othonhugo/vulnerability-explorer.git
cd vulnerability-explorer

# Using pip
pip install -e .

# Using uv (recommended)
uv sync

2. Launch Interactive Mode

Simply type vex to launch the interactive arrow-key navigation menu:

vex

Features & CLI Usage

  • Interactive Terminal CLI (vex): Built-in arrow-key interactive menu for seamless browsing.
  • Rich Formatting & Pager: Read syntax-highlighted documentation right in your terminal (less-style scrolling).
  • Multi-dimensional Filtering: Slice the catalog by language, category, or analysis mode.
  • Full-Text Search: Instantly query across titles, tags, code snippets, and methodologies.
Task Command
Interactive Menu vex or vex interactive
View Catalog Hierarchy vex tree
Filter by Category vex list --category injection
Filter by Language & Mode vex list --language python --mode white-box
Read Specific Entry vex read injection.sql-injection
Search Catalog vex search "prepared statement"
Sync Remote Catalog vex sync <GITHUB_URL>

For full CLI options, flags, and advanced usage, see the CLI Commands Reference.

Developer & Contributor Tools

The catalog is logically organized under data/catalog/ and relies on a strict schema. We provide built-in tooling to ensure the knowledge base remains pristine.

# Run catalog integrity linter (validates YAML schema, internal links, and markdown structure)
vex-lint --root .

# Run Python code linters (Ruff & Mypy)
make lint-py

# Format Markdown/YAML (Prettier) and Python (Ruff)
make format

See CONTRIBUTING.md and our docs/contributing/ hierarchy for detailed entry guidelines.

Non-Goals

This repository does not contain weaponized exploits or automated scanning engines. Entries document recognition signals, root causes, and exploitation methodologies strictly necessary to understand, confirm, and fix vulnerabilities responsibly. See our ethical boundary guidelines for more details.

Metadata

Release files for vulnerability-explorer 1.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vulnerability-explorer 1.0.3
File Size Uploaded
vulnerability_explorer-1.0.3.tar.gz 22.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vulnerability-explorer 1.0.3
File Interpreter ABI Platform
vulnerability_explorer-1.0.3-py3-none-any.whl Python 3 none any Details

Total release size: 50.7 kB

Release files / vulnerability_explorer-1.0.3.tar.gz

Download URL vulnerability_explorer-1.0.3.tar.gz
Size 22.2 kB
Tags Source
SHA-256 checksum
How to use checksums
67de6957b527dff69e694450266af7bbd3c7733c0737fe081ff2e2003b072adc
BLAKE2b-256 checksum
How to use checksums
8154dcf8d8f17ab96acc8ed425b7f4b3245bc079dc03aa7397066e9b062c7ecb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 27, 2026.

Transparency log

Release files / vulnerability_explorer-1.0.3-py3-none-any.whl

Download URL vulnerability_explorer-1.0.3-py3-none-any.whl
Size 28.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e4352448452d861f8f76e91c4ef93bedd63cdca6637803c9593a637fd6beb2c9
BLAKE2b-256 checksum
How to use checksums
257202b062690e36fcd7ea6ca1a802d40de16f2bc3cff790a9ffb908bf7c4c1f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 27, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.3 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page