Recommended Free Tools
To diff two Vulnerability Exploitability eXchange (VEX) documents claim by claim, match each assertion by vulnerability and exact product scope, then compare status, rationale or action, and timing. A line-based diff can show what text moved; an auditable VEX diff must show whether the issuer changed which product versions are affected and why.
What counts as a VEX claim?
OpenVEX describes its central unit as a statement: an assertion about a vulnerability in a product, with a status and supporting context. Treat a claim as the combination of vulnerability, product identity, version or component scope where specified, status, rationale or action, and time. Two records are counterparts only when their vulnerability and product scopes correspond closely enough to compare.
A VEX status is the issuer’s assertion, not independent proof that an exploit is or is not possible. In particular, retain an issuer’s explanation for a not-affected conclusion, and do not interpret under-investigation as either affected or not affected. OpenVEX Specification
Prepare both documents before matching claims
First establish what each file is. A .json extension does not identify a VEX format: OpenVEX serializes a JSON-LD structure, while CSAF VEX is a profile within the CSAF advisory model. Record the declared format and specification version, document identifier, issuer, document version, and issue or update timestamps. Parse each file against its own declared format and version; do not apply a CSAF 2.1 parser to a 2.0 document without validating compatibility. OpenVEX Specification; CSAF 2.1
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Intuitive interface of a conventional FTP client
- Easy and Reliable FTP Site Maintenance.
- FTP Automation and Synchronization
Build a stable claim key
Use a key that captures identity, not merely display text. Start with the vulnerability identifier and a stable product identifier. Add version or version range, platform or release, and component or subcomponent when present. OpenVEX recommends product identifiers that can be correlated with software bill of materials entries and commonly uses CVE-style vulnerability identifiers. CSAF references products in a product tree and attaches vulnerability statuses to product IDs. A familiar product name alone can match the wrong edition or release. OpenVEX Specification; CSAF 2.0 VEX profile
Compare product and version scope first
Before reading the status change, compare which products the assertion covers. Check product identity, platform and release, component scope, and the version representation. Scope can be expressed as enumerated versions or ranges; a shift from one release to a broad range is material even if the status is unchanged. Record additions, removals, expansions, and contractions explicitly rather than burying them in a text-field diff. CISA VEX Use Cases
Product matching may require issuer-specific detail. Cisco’s CVR lookup, for example, asks customers to match CVE and product, platform, and release. When identifiers do not map cleanly, keep the records unmatched or mark the match uncertain instead of silently equating them. Cisco CVR/VEX FAQ
Compare status, explanation, and action together
Statuses are controlled values, but their labels differ by format. Preserve the original labels in the output; if a downstream report normalizes them, show the mapping separately so readers can distinguish source wording from your categorization.
| Format | Source-native status labels | Context to compare |
|---|---|---|
| OpenVEX | not_affected, affected, fixed, under_investigation |
not_affected requires a justification or impact statement; affected requires an action statement. |
| CSAF VEX | known_not_affected, known_affected, fixed, under_investigation |
known_not_affected needs impact information; known_affected needs product-specific remediation information. |
Compare old and new status alongside the associated justification, impact explanation, status notes, and action or remediation. Do not infer that two free-text explanations are equivalent just because their wording resembles each other. OpenVEX notes that free-form impact text is not machine-readable and recommends machine-readable justifications for automation. OpenVEX Specification; CSAF 2.1
Keep fixed tied to the versions that contain the fix; the label alone does not establish the boundaries of affected or fixed scope. Likewise, an under_investigation claim is unresolved, not a midpoint between affected and not affected.
Rank #2
- Apply effects and transitions, adjust video speed and more
- One of the fastest video stream processors on the market
- Drag and drop video clips for easy video editing
- Capture video from a DV camcorder, VHS, webcam, or import most video file formats
- Create videos for DVD, HD, YouTube and more
Compare timestamps and revision metadata
Show document issue time, statement timestamp where available, last-updated time, and document version. Keep assertion time distinct from the time you retrieved the file. A newer file may change only metadata, or it may change claim content; report those cases separately.
OpenVEX describes statements as evolving: later statements can override or enrich earlier information, and the document version must increase when content changes, including statements. Do not assume every VEX format uses the same supersession rules; apply the declared format’s timestamp inheritance and revision semantics. OpenVEX Specification
Produce an auditable diff
Use one row per matched claim, then separate lists for claims found only in the old or new document and for uncertain matches. A useful report makes the literal field changes visible and keeps semantic interpretation distinct from them.
| Field | What to record |
|---|---|
| Match key | Vulnerability ID; stable product identity; version, platform, release, and component scope where applicable. |
| Scope | Previous and current product/version scope, with additions, removals, expansion, or narrowing called out. |
| Status | Previous and current source-native labels; any normalization shown separately. |
| Rationale | Previous and current justification, impact statement, or status notes. |
| Action | Previous and current action or remediation information. |
| Time and revision | Statement and document timestamps, document version, and retrieval time where relevant. |
| Classification and review | Change class, literal field differences, interpretation, and any reason for human review. |
Useful change classes include:
- Vulnerability/product claim added or removed.
- Product or version scope expanded, narrowed, or otherwise changed.
- Status changed, including a move into or out of investigation.
- Justification, impact explanation, or action/remediation added, removed, or changed.
- Document or statement timing/version changed without a claim-content change.
- Match is uncertain and needs issuer or human review.
Where automation helps—and where review remains necessary
Security tools consume VEX statuses, so parsing and field-level comparison can make revisions easier to process. Microsoft Security Response Center announced on September 8, 2026, that it was publishing VEX statements for all Microsoft-assigned CVEs, describing the goal as more machine-readable information for security tooling. That is a dated supplier announcement, not a promise about every VEX issuer or every downstream integration. MSRC announcement, September 8, 2026
Automation cannot safely resolve every identity or meaning question. Route a diff for human review when product identifiers fail to match, version boundaries are unclear, a mapping is unsupported, the format or schema is uncertain, or the apparent status change depends on ambiguous prose. A machine-readable diff exposes the evidence; it does not independently validate the issuer’s exploitability assessment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




