Kubescape: The 1st Open Source project to support VEX Generation Introduction Vulnerability Exploitability eXchange (VEX) is a vulnerability document designed to complement a Software Bill of Materials (SBOM). It informs users of a software product about the applicability of one or more vulnerability findings. Security scanners will detect and flag components in software that have been identified as being vulnerable.