Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xerox Corporation

First CVE: Oct 13, 1999Active for: 27 yearsTotal CVEs: 119
39.4
VTI Score
Medium

Xerox Corporation maintains a substantial portfolio of multifunction printers and enterprise imaging devices, the majority centered on its WorkCentre product line, which sees broad deployment across organizations worldwide. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the recurring weakness classes center on input-handling flaws such as cross-site scripting, path traversal, and classic buffer overflows, alongside placeholder categories that reflect the complexity of embedded firmware and web-based device management interfaces. The exposure pattern is characteristic of networked office equipment: these devices operate at the network edge, often with long support lifecycles and infrequent patching by end users, concentrating risk around authentication bypass, privilege escalation, and remote code execution on devices that have access to sensitive documents and network resources. Defenders should prioritize inventory and network segmentation of WorkCentre and related devices, particularly those exposed to untrusted networks, and treat firmware updates as security-critical rather than optional maintenance. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
119
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Xerox Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 13, 1999
26 years ago
Most Recent CVE
Feb 27, 2026
147 days ago

Self-Reporting Analysis

Of all the CVEs published by Xerox Corporation as a CNA, 76.2% affect products that Xerox Corporation develops as a vendor.

76.2%
23.8%
Self-reported: 16 (76.2%)
Third-party: 5 (23.8%)

Of all the CVEs published that affect products developed by Xerox Corporation, 13.4% are self-published by Xerox Corporation as a CNA.

13.4%
86.6%
Self-published: 16 (13.4%)
Other CNAs: 103 (86.6%)

Products(299 total)

Top CVEs

Signals from CVEs in this vendor scope (119 CVEs).

119 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3571HIGH
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.
Aug 10, 20087.850NOYES
CVE-2025-8356CRITICAL
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lead to Remote Code Execution (RCE
Aug 8, 20259.844NONO
CVE-2019-10880CRITICAL
Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vuln
Apr 12, 20199.835NONO
CVE-2026-2251CRITICAL
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal leading to RCE. This issue aff
Feb 27, 20269.834NONO
CVE-2019-13171CRITICAL
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by one or more stack-based buffer overflow vulnerabilities in the Google Cloud Print implementation that
Mar 13, 20209.832NONO
CVE-2012-0773HIGH
The NetStream class in Adobe Flash Player before 10.3.183.18 and 11.x before 11.2.202.228 on Windows, Mac OS X, and Linux; Flash Player before 10.3.183.18 and 11.x before 11.2.202.
Mar 28, 20129.332NONO
CVE-2021-28673CRITICAL
Xerox Phaser 6510 before 64.61.23 and 64.59.11 (Bridge), WorkCentre 6515 before 65.61.23 and 65.59.11 (Bridge), VersaLink B400 before 37.61.23 and 37.59.01 (Bridge), B405 before 38
Mar 29, 20219.831NONO
CVE-2019-13165CRITICAL
Some Xerox printers (such as the Phaser 3320 V53.006.16.000) were affected by a buffer overflow vulnerability in the request parser of the IPP service. This would allow an unauthen
Mar 13, 20209.831NONO
CVE-2021-37354CRITICAL
Xerox Phaser 4622 v35.013.01.000 was discovered to contain a buffer overflow in the function sub_3226AC via the TIMEZONE variable. This vulnerability allows attackers to cause a De
Feb 15, 20229.830NONO
CVE-2016-11061CRITICAL
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in
Apr 29, 20209.830NONO
View all 119 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products119 CVEs
41%
36%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network56 (47.1%)
Unknown63 (52.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (45.4%)
High2 (1.7%)
Unknown63 (52.9%)
User Interaction
None49 (41.2%)
Unknown63 (52.9%)
Required7 (5.9%)
Privileges Required
Low7 (5.9%)
High2 (1.7%)
None47 (39.5%)
Unknown63 (52.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (119 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
3.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xerox Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xerox Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xerox Corporation's Products

View all 6 CNAs →

Top CWEs