Xerox Corporation

First CVE: Oct 7, 2024Active for: 2 years
21
CVEs Published
More CVEs Published than 41% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Xerox Corporation as a CNA, 76.2% affect products that Xerox Corporation develops as a vendor.

76.2%
23.8%
Self-reported: 16Third-party: 5

Of all the CVEs published that affect products developed by Xerox Corporation, 13.4% are self-published by Xerox Corporation as a CNA.

13.4%
86.6%
Self-published: 16Published by other CNAs: 103

Trends Over Time

The number and severity of CVEs published by Xerox Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2024
21 months ago
Most Recent CVE
Feb 27, 2026
147 days ago

Top CVEs

All CVEs published by Xerox Corporation as a CNA, regardless of affected vendor or product.

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE
Aug 8, 20259.844NONO
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue aff
Feb 27, 20269.834NONO
Pre-Auth RCE via Path Traversal
Oct 7, 20249.828NONO
Pre-Auth RCE via Path Traversal
Oct 7, 20249.827NONO
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references
Feb 27, 20267.526NONO
Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files
Jan 23, 20259.826NONO
A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation
Jan 23, 20259.826NONO
In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal UR
Aug 8, 20257.525NONO
With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access.
Feb 3, 20257.625NONO
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
Oct 17, 20247.225NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA21 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (4.8%)
Network19 (90.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.8%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low6 (28.6%)
High2 (9.5%)
None13 (61.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Xerox Corporation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Xerox Corporation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs