Vulnerability Explorer (vex)
A git-native, interactive terminal reference and structured knowledge base for software vulnerabilities.
Imagine man pages built specifically for application security. Vulnerability Explorer is a curated, structured knowledge base of software vulnerabilities combined with a versatile command-line tool (vex).
❯ vex list
Catalog Entries
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━┳━━━━━━━━━━━━━━━━━━━━━━━━┳━━━━━━━━┓
┃ ID ┃ Type ┃ Title ┃ Langs ┃
┡━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━╇━━━━━━━━━━━━━━━━━━━━━━━━╇━━━━━━━━┩
│ injection.sql-injection │ concept │ SQL Injection │ - │
│ injection.sql.inband.go-database... │ manifestation │ Classic In-Band SQLi...│ go │
│ injection.sql.inband.java-jdbc... │ manifestation │ Classic In-Band SQLi...│ java │
│ injection.sql.inband.php-mysqli... │ manifestation │ Classic In-Band SQLi...│ php │
│ injection.sql.inband.python-psyc... │ manifestation │ Classic In-Band SQLi...│ python │
└─────────────────────────────────────┴───────────────┴────────────────────────┴────────┘
Why Vulnerability Explorer?
Traditional vulnerability databases (like CVEs or the NVD) focus on tracking patches for specific software versions. Vulnerability Explorer focuses on the code.
Every entry in our catalog is an atomic Markdown file enriched with strict YAML frontmatter. We document concrete vulnerability mechanisms (manifestations) across specific languages, frameworks, and architectures:
- White-box identification: Side-by-side vulnerable vs. safe code snippets and taint patterns.
- Gray/Black-box behavior: Observable indicators, error disclosures, and exploitation methodologies.
- Remediation: Primary fixes, strict allowlisting, and common mitigation mistakes.
Who is this for?
| Audience | How They Use vex |
|---|---|
| Security Engineers | Fast terminal reference during pentests, code reviews, and report writing. |
| Developers | Learn root causes and immediately compare vulnerable code with the secure fix. |
| AI Agents & LLMs | Consume structured datasets or autonomously generate new vulnerability entries. |
| Educators & Students | Teach or learn standardized taxonomy, recognition signals, and threat modeling. |
Quick Start
1. Installation
From PyPI
# Using pip
pip install vulnerability-explorer
# Or using uv (recommended)
uv pip install vulnerability-explorer
From Source (For Contributors)
git clone https://github.com/othonhugo/vulnerability-explorer.git
cd vulnerability-explorer
# Using pip
pip install -e .
# Using uv (recommended)
uv sync
2. Launch Interactive Mode
Simply type vex to launch the interactive arrow-key navigation menu:
vex
Features & CLI Usage
- Interactive Terminal CLI (
vex): Built-in arrow-key interactive menu for seamless browsing. - Rich Formatting & Pager: Read syntax-highlighted documentation right in your terminal (
less-style scrolling). - Multi-dimensional Filtering: Slice the catalog by language, category, or analysis mode.
- Full-Text Search: Instantly query across titles, tags, code snippets, and methodologies.
| Task | Command |
|---|---|
| Interactive Menu | vex or vex interactive |
| View Catalog Hierarchy | vex tree |
| Filter by Category | vex list --category injection |
| Filter by Language & Mode | vex list --language python --mode white-box |
| Read Specific Entry | vex read injection.sql-injection |
| Search Catalog | vex search "prepared statement" |
| Sync Remote Catalog | vex sync <GITHUB_URL> |
For full CLI options, flags, and advanced usage, see the CLI Commands Reference.
Developer & Contributor Tools
The catalog is logically organized under data/catalog/ and relies on a strict schema. We provide built-in tooling to ensure the knowledge base remains pristine.
# Run catalog integrity linter (validates YAML schema, internal links, and markdown structure)
vex-lint --root .
# Run Python code linters (Ruff & Mypy)
make lint-py
# Format Markdown/YAML (Prettier) and Python (Ruff)
make format
See CONTRIBUTING.md and our docs/contributing/ hierarchy for detailed entry guidelines.
Non-Goals
This repository does not contain weaponized exploits or automated scanning engines. Entries document recognition signals, root causes, and exploitation methodologies strictly necessary to understand, confirm, and fix vulnerabilities responsibly. See our ethical boundary guidelines for more details.
Metadata
Release files for vulnerability-explorer 1.0.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vulnerability_explorer-1.0.3.tar.gz | 22.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vulnerability_explorer-1.0.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 50.7 kB
Release files / vulnerability_explorer-1.0.3.tar.gz
| Download URL | vulnerability_explorer-1.0.3.tar.gz |
|---|---|
| Size | 22.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
67de6957b527dff69e694450266af7bbd3c7733c0737fe081ff2e2003b072adc
|
|
BLAKE2b-256 checksum How to use checksums |
8154dcf8d8f17ab96acc8ed425b7f4b3245bc079dc03aa7397066e9b062c7ecb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 27, 2026.
Transparency logRelease files / vulnerability_explorer-1.0.3-py3-none-any.whl
| Download URL | vulnerability_explorer-1.0.3-py3-none-any.whl |
|---|---|
| Size | 28.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e4352448452d861f8f76e91c4ef93bedd63cdca6637803c9593a637fd6beb2c9
|
|
BLAKE2b-256 checksum How to use checksums |
257202b062690e36fcd7ea6ca1a802d40de16f2bc3cff790a9ffb908bf7c4c1f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 27, 2026.
Transparency log