Xen Project
First CVE: Apr 6, 2021Active for: 5 years
145
CVEs Published
More CVEs Published than 75% of tracked CNAs
24.2
Avg CVEs / Year
More Avg CVEs / Year than 72% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Xen Project as a CNA, 83.4% affect products that Xen Project develops as a vendor.
83.4%
16.6%
Self-reported: 121Third-party: 24
Of all the CVEs published that affect products developed by Xen Project, 24.3% are self-published by Xen Project as a CNA.
24.3%
75.7%
Self-published: 121Published by other CNAs: 376
Trends Over Time
The number and severity of CVEs published by Xen Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2021
5 years ago
Most Recent CVE
Jul 9, 2026
16 days ago
Top CVEs
All CVEs published by Xen Project as a CNA, regardless of affected vendor or product.
145 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23560CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different r | Jul 9, 2026 | 9.4 | 39 | NO | NO |
CVE-2026-23556CRITICAL When oxenstored is tearing a domain down, the node data is cleaned up
but the usage counts are leaked.
When the domain ID is eventually reused, the new domain can create fewer
nod | Jul 9, 2026 | 9.4 | 39 | NO | NO |
CVE-2026-42486CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different r | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2026-23562CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different r | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2026-23561CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different r | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2026-23559CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.]
XAPI can configure different users with different | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2025-58151CRITICAL varstored is a component of the Xapi toolstack handling UEFI Variables
for a VM. It has a communication path with OVMF inside the VM involving
mapping a buffer prepared by OVMF.
| Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2025-58146CRITICAL There are multiple issues.
1. Updates to the XAPI database sanitise input strings, but try
generating the notification using the unsanitised input. This
causes the datab | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2025-27464CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE-2025-27463CRITICAL [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to | Jul 9, 2026 | 9.4 | 38 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA145 CVEs
44%
42%
10%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local116 (80.0%)
Network24 (16.6%)
Unknown0 (0.0%)
Physical5 (3.4%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (82.1%)
High26 (17.9%)
Unknown0 (0.0%)
User Interaction
None145 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low101 (69.7%)
High9 (6.2%)
None35 (24.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (145 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Xen Project as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Xen Project as a CNA — matched by CVE ID, not by organization name.