Xen Project is a specialized hypervisor and virtualization platform that, despite a narrow product line, is deeply embedded in cloud infrastructure, data centers, and enterprise virtualization deployments, making it among the most prominent open-source hypervisors in the landscape. The vendor's vulnerability profile centers on its core Xen hypervisor, QEMU integration layer, and associated management tooling, with recurring weakness classes reflecting the complexity of privileged code execution, guest-host isolation, and concurrent resource management inherent to hypervisor design—including improper input validation, memory-buffer boundary issues, race conditions, and sensitive-information exposure. The narrow product scope and structural role as a foundational isolation boundary mean that individual vulnerabilities can have wide deployment impact, warranting close monitoring despite modest disclosure volume. Defenders should treat Xen advisories as requiring prompt assessment across virtualized infrastructure; current severity, exploitation activity, and vulnerability counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xen Project over time
Of all the CVEs published by Xen Project as a CNA, 83.4% affect products that Xen Project develops as a vendor.
Of all the CVEs published that affect products developed by Xen Project, 24.3% are self-published by Xen Project as a CNA.
Signals from CVEs in this vendor scope (497 CVEs).
497 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-0217HIGH The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos befor | Jun 12, 2012 | 7.2 | 65 | NO | YES |
CVE-2018-8897HIGH A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sys | May 8, 2018 | 7.8 | 56 | NO | YES |
CVE-2015-3456HIGH The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p | May 13, 2015 | 7.7 | 42 | NO | YES |
CVE-2017-15595HIGH An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly | Oct 18, 2017 | 8.8 | 38 | NO | YES |
CVE-2017-7228HIGH An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM | Apr 4, 2017 | 8.2 | 37 | NO | YES |
CVE-2025-27466CRITICAL [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are multiple issues related to the handling | Sep 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-58143CRITICAL [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are multiple issues related to the handling | Sep 11, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-58142CRITICAL [This CNA information record relates to multiple CVEs; the
text explains which aspects/vulnerabilities correspond to which CVE.]
There are multiple issues related to the handling | Sep 11, 2025 | 9.8 | 32 | NO | NO |
CVE-2024-31142HIGH Because of a logical error in XSA-407 (Branch Type Confusion), the
mitigation is not applied properly when it is intended to be used.
XSA-434 (Speculative Return Stack Overflow) us | May 16, 2024 | 7.5 | 32 | NO | NO |
CVE-2017-10918CRITICAL Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222. | Jul 5, 2017 | 10.0 | 32 | NO | NO |
Signals from CVEs in this vendor scope (497 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xen Project.
Media articles that mention a CVE ID that affects a product developed by Xen Project — matched by CVE ID, not by vendor name.