Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xen Project

First CVE: Mar 20, 2007Active for: 19 yearsTotal CVEs: 497
34.9
VTI Score
Medium

Xen Project is a specialized hypervisor and virtualization platform that, despite a narrow product line, is deeply embedded in cloud infrastructure, data centers, and enterprise virtualization deployments, making it among the most prominent open-source hypervisors in the landscape. The vendor's vulnerability profile centers on its core Xen hypervisor, QEMU integration layer, and associated management tooling, with recurring weakness classes reflecting the complexity of privileged code execution, guest-host isolation, and concurrent resource management inherent to hypervisor design—including improper input validation, memory-buffer boundary issues, race conditions, and sensitive-information exposure. The narrow product scope and structural role as a foundational isolation boundary mean that individual vulnerabilities can have wide deployment impact, warranting close monitoring despite modest disclosure volume. Defenders should treat Xen advisories as requiring prompt assessment across virtualized infrastructure; current severity, exploitation activity, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
497
Total CVEs
More Total CVEs than 100% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xen Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2007
19 years ago
Most Recent CVE
May 19, 2026
66 days ago

Self-Reporting Analysis

Of all the CVEs published by Xen Project as a CNA, 83.4% affect products that Xen Project develops as a vendor.

83.4%
16.6%
Self-reported: 121 (83.4%)
Third-party: 24 (16.6%)

Of all the CVEs published that affect products developed by Xen Project, 24.3% are self-published by Xen Project as a CNA.

24.3%
75.7%
Self-published: 121 (24.3%)
Other CNAs: 376 (75.7%)

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (497 CVEs).

497 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-0217HIGH
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos befor
Jun 12, 20127.265NOYES
CVE-2018-8897HIGH
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-sys
May 8, 20187.856NOYES
CVE-2015-3456HIGH
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or p
May 13, 20157.742NOYES
CVE-2017-15595HIGH
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly
Oct 18, 20178.838NOYES
CVE-2017-7228HIGH
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM
Apr 4, 20178.237NOYES
CVE-2025-27466CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling
Sep 11, 20259.834NONO
CVE-2025-58143CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling
Sep 11, 20259.832NONO
CVE-2025-58142CRITICAL
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple issues related to the handling
Sep 11, 20259.832NONO
CVE-2024-31142HIGH
Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) us
May 16, 20247.532NONO
CVE-2017-10918CRITICAL
Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
Jul 5, 201710.032NONO
View all 497 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products497 CVEs
10%
54%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local264 (53.1%)
Network52 (10.5%)
Unknown171 (34.4%)
Physical9 (1.8%)
Adjacent Network1 (0.2%)
Attack Complexity
Low269 (54.1%)
High57 (11.5%)
Unknown171 (34.4%)
User Interaction
None326 (65.6%)
Unknown171 (34.4%)
Required0 (0.0%)
Privileges Required
Low247 (49.7%)
High34 (6.8%)
None45 (9.1%)
Unknown171 (34.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (497 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
0.6% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
1.2% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xen Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xen Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xen Project's Products

View all 9 CNAs →

Top CWEs