github.com/CycloneDX/sbom-utility@v0.16.0/examples/cyclonedx/VEX/Use-Cases/Case-5/README.md (about) 1 # VEX Use Case 5 2 3 | Single Product | Multiple Versions (Range) | Single Vulnerability | Affected & Not Affected | 4 | --- | --- | --- | --- | 5 6 A VEX states that CVE-2020-25649 is not exploitable in the current version (e.g. 7.0.0) and higher of a software product, 7 nor is it exploitable prior to v1.5.0. But is exploitable between v1.5.0 up to (but excluding) v7.0.0.