25 Total CVEs
25 AI Analyzed
0 CISA KEV
14 Critical

Profile

0% ended up actively exploited 0 of 25 added to CISA KEV
56% rated critical (CVSS 9.0+) 14 critical, 11 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

19 CVEs in the last 12 months

Products

  • XAPI6
  • Windows PV drivers3
  • Xen2
  • oxenstored1
  • EPT paging1
  • varstored1

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-25 of 25 CVEs
CVE-2026-62427
Analyzed
8.8
Xen Xen

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2026-08-17
CVE-2026-62426
Analyzed
8.8
Xen Xen

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2026-08-17
CVE-2026-42486
Analyzed
9.4
Xen XAPI

Xen XAPI improperly restricts access to the VM.platform:hvm_serial parameter, allowing vm-admin users to write arbitrary files to the dom0 host system...

2026-07-10
CVE-2026-23562
Analyzed
9.4
Xen XAPI

Xen XAPI fails to perform necessary authorization checks for PCI passthrough configuration, allowing lower-privileged administrators to access uninten...

2026-07-10
CVE-2026-23561
Analyzed
9.4
Xen XAPI

A vulnerability in Xen XAPI allows a vm-admin to manipulate storage domain configurations, potentially causing host storage connections to be erroneou...

2026-07-10
CVE-2026-23560
Analyzed
9.4
Xen XAPI

A vulnerability in Xen XAPI allows a vm-admin to mark a VM as a system domain, which can cause the domain to be hidden from management tooling and per...

2026-07-10
CVE-2026-23559
Analyzed
9.4
Xen XAPI

A privilege escalation vulnerability in Xen XAPI allows a vm-admin to manipulate arbitrary files in dom0 by misconfiguring VBD settings, leading to un...

2026-07-10
CVE-2026-23558
Analyzed
7.8
Xen Multiple Products

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table v...

2026-05-20
CVE-2026-23556
Analyzed
9.4
Xen oxenstored

A resource leak in Xen oxenstored allows for improper node usage tracking during domain teardown, resulting in potential denial-of-service conditions...

2026-07-10
CVE-2026-23554
Analyzed
7.8
Xen EPT paging

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications...

2026-03-24
CVE-2025-58151
Analyzed
9.4
Xen varstored

Xen's varstored component contains a TOCTOU race condition due to insufficient compiler barriers, potentially allowing an attacker to manipulate inter...

2026-07-10
CVE-2025-58150
Analyzed
8.8
Xen Multiple Products

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing

2026-01-29
CVE-2025-58149
Analyzed
7.5
Xen Multiple Products

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have

2025-10-31
CVE-2025-58148
Analyzed
7.5
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2025-10-31
CVE-2025-58147
Analyzed
7.5
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2025-10-31
CVE-2025-58146
Analyzed
9.4
Xen XAPI

Xen XAPI contains multiple vulnerabilities related to improper input validation, leading to potential database corruption, event thread termination, a...

2026-07-10
CVE-2025-58145
Analyzed
7.5
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2025-09-12
CVE-2025-58144
Analyzed
7.5
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE

2025-09-12
CVE-2025-58143
Analyzed
9.8
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple i...

2025-09-12
CVE-2025-58142
Analyzed
9.8
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple i...

2025-09-12
CVE-2025-27466
Analyzed
9.8
Xen Multiple Products

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple i...

2025-09-12
CVE-2025-27464
Analyzed
9.4
Xen Windows PV drivers

The Xen Windows PV drivers fail to implement security descriptors on various facilities, allowing unprivileged users to access sensitive interfaces.

2026-07-10
CVE-2025-27463
Analyzed
9.4
Xen Windows PV drivers

The Xen Windows PV drivers for the XenIface facility lack proper security descriptors, allowing unprivileged users to access the interface and potenti...

2026-07-10
CVE-2025-27462
Analyzed
9.4
Xen Windows PV drivers

The Xen Windows PV drivers for the XenCons facility lack proper security descriptors, allowing unprivileged users to access the interface and potentia...

2026-07-10
CVE-2025-1713
Analyzed
7.5
Xen Multiple Products

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required

2025-07-17