Xen Orchestra is a management and orchestration platform for Xen hypervisor infrastructure, with a focused product footprint centered on its server and web components. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xen Orchestra over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36383MEDIUM Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacke | Jul 12, 2021 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xen Orchestra.
Media articles that mention a CVE ID that affects a product developed by Xen Orchestra — matched by CVE ID, not by vendor name.