Xerox Corporation
First CVE: Oct 7, 2024Active for: 2 years
21
CVEs Published
More CVEs Published than 41% of tracked CNAs
7.0
Avg CVEs / Year
More Avg CVEs / Year than 42% of tracked CNAs
7.9
Avg CVSS Score
Higher Avg CVSS Score than 84% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Xerox Corporation as a CNA, 76.2% affect products that Xerox Corporation develops as a vendor.
76.2%
23.8%
Self-reported: 16Third-party: 5
Of all the CVEs published that affect products developed by Xerox Corporation, 13.4% are self-published by Xerox Corporation as a CNA.
13.4%
86.6%
Self-published: 16Published by other CNAs: 103
Trends Over Time
The number and severity of CVEs published by Xerox Corporation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2024
21 months ago
Most Recent CVE
Feb 27, 2026
147 days ago
Top CVEs
All CVEs published by Xerox Corporation as a CNA, regardless of affected vendor or product.
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8356CRITICAL In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE | Aug 8, 2025 | 9.8 | 44 | NO | NO |
CVE-2026-2251CRITICAL Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE.
This issue aff | Feb 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2024-47557CRITICAL Pre-Auth RCE via Path Traversal | Oct 7, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-47556CRITICAL Pre-Auth RCE via Path Traversal | Oct 7, 2024 | 9.8 | 27 | NO | NO |
CVE-2026-2252HIGH An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references | Feb 27, 2026 | 7.5 | 26 | NO | NO |
CVE-2024-55930CRITICAL Xerox Workplace Suite has weak default folder permissions that allow unauthorized users to access, modify, or delete files | Jan 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2024-55926CRITICAL A vulnerability found in Xerox Workplace Suite allows arbitrary file read, upload, and deletion on the server through crafted header manipulation. By exploiting improper validation | Jan 23, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-8355HIGH In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML containing references to internal UR | Aug 8, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-12511HIGH With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access. | Feb 3, 2025 | 7.6 | 25 | NO | NO |
CVE-2024-6333HIGH Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. | Oct 17, 2024 | 7.2 | 25 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA21 CVEs
24%
48%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.8%)
Network19 (90.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.8%)
Attack Complexity
Low20 (95.2%)
High1 (4.8%)
Unknown0 (0.0%)
User Interaction
None20 (95.2%)
Unknown0 (0.0%)
Required1 (4.8%)
Privileges Required
Low6 (28.6%)
High2 (9.5%)
None13 (61.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Xerox Corporation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Xerox Corporation as a CNA — matched by CVE ID, not by organization name.