Xen
Xen · 490 CVEs
grant table v2 race in status page mapping
May 19, 2026
Xenstored DoS via XS_RESET_WATCHES command
May 19, 2026
Xenstored DoS by unprivileged domain
Mar 23, 2026
Use after free of paging structures in EPT
Mar 23, 2026
x86: incomplete IBPB for vCPU isolation
Jan 28, 2026
x86: buffer overrun with shadow paging + tracing
Jan 28, 2026
Incorrect removal of permissions on PCI device unplug
Oct 31, 2025
x86: Incorrect input sanitisation in Viridian hypercalls
Oct 31, 2025
x86: Incorrect input sanitisation in Viridian hypercalls
Oct 31, 2025
Arm issues with page refcounting
Sep 11, 2025
Arm issues with page refcounting
Sep 11, 2025
Mutiple vulnerabilities in the Viridian interface
Sep 11, 2025
Mutiple vulnerabilities in the Viridian interface
Sep 11, 2025
Mutiple vulnerabilities in the Viridian interface
Sep 11, 2025
deadlock potential with VT-d and legacy PCI device pass-through
Jul 17, 2025
x86: Incorrect stubs exception handling for flags recovery
Jul 16, 2025
CVE-2024-2201
Dec 19, 2024
libxl leaks data to PVH guests via ACPI tables
Dec 19, 2024
Deadlock in x86 HVM standard VGA handling
Dec 19, 2024
x86: Deadlock in vlapic_error()
Sep 25, 2024
PCI device pass-through with shared resources
Sep 25, 2024
error handling in x86 IOMMU identity mapping
Sep 25, 2024
double unlock in x86 guest IRQ handling
Jul 18, 2024
x86: Incorrect logic for BTC/SRSO mitigations
May 16, 2024
x86 HVM hypercalls may trigger Xen bug check
May 16, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-23558 | grant table v2 race in status page mapping | HIGH | 0.12% | May 19, 2026 |
| CVE-2026-23557 | Xenstored DoS via XS_RESET_WATCHES command | MEDIUM | 0.16% | May 19, 2026 |
| CVE-2026-23555 | Xenstored DoS by unprivileged domain | HIGH | 0.18% | Mar 23, 2026 |
| CVE-2026-23554 | Use after free of paging structures in EPT | HIGH | 0.13% | Mar 23, 2026 |
| CVE-2026-23553 | x86: incomplete IBPB for vCPU isolation | LOW | 0.14% | Jan 28, 2026 |
| CVE-2025-58150 | x86: buffer overrun with shadow paging + tracing | HIGH | 0.14% | Jan 28, 2026 |
| CVE-2025-58149 | Incorrect removal of permissions on PCI device unplug | HIGH | 0.43% | Oct 31, 2025 |
| CVE-2025-58148 | x86: Incorrect input sanitisation in Viridian hypercalls | HIGH | 0.38% | Oct 31, 2025 |
| CVE-2025-58147 | x86: Incorrect input sanitisation in Viridian hypercalls | HIGH | 0.38% | Oct 31, 2025 |
| CVE-2025-58145 | Arm issues with page refcounting | HIGH | 0.35% | Sep 11, 2025 |
| CVE-2025-58144 | Arm issues with page refcounting | HIGH | 0.45% | Sep 11, 2025 |
| CVE-2025-58143 | Mutiple vulnerabilities in the Viridian interface | CRITICAL | 0.37% | Sep 11, 2025 |
| CVE-2025-58142 | Mutiple vulnerabilities in the Viridian interface | CRITICAL | 0.47% | Sep 11, 2025 |
| CVE-2025-27466 | Mutiple vulnerabilities in the Viridian interface | CRITICAL | 0.47% | Sep 11, 2025 |
| CVE-2025-1713 | deadlock potential with VT-d and legacy PCI device pass-through | HIGH | 0.72% | Jul 17, 2025 |
| CVE-2025-27465 | x86: Incorrect stubs exception handling for flags recovery | MEDIUM | 0.66% | Jul 16, 2025 |
| CVE-2024-2201 | CVE-2024-2201 | MEDIUM | 8.79% | Dec 19, 2024 |
| CVE-2024-45819 | libxl leaks data to PVH guests via ACPI tables | MEDIUM | 0.30% | Dec 19, 2024 |
| CVE-2024-45818 | Deadlock in x86 HVM standard VGA handling | MEDIUM | 0.27% | Dec 19, 2024 |
| CVE-2024-45817 | x86: Deadlock in vlapic_error() | HIGH | 0.54% | Sep 25, 2024 |
| CVE-2024-31146 | PCI device pass-through with shared resources | HIGH | 0.24% | Sep 25, 2024 |
| CVE-2024-31145 | error handling in x86 IOMMU identity mapping | HIGH | 0.23% | Sep 25, 2024 |
| CVE-2024-31143 | double unlock in x86 guest IRQ handling | HIGH | 0.51% | Jul 18, 2024 |
| CVE-2024-31142 | x86: Incorrect logic for BTC/SRSO mitigations | HIGH | 17.44% | May 16, 2024 |
| CVE-2023-46842 | x86 HVM hypercalls may trigger Xen bug check | MEDIUM | 8.53% | May 16, 2024 |
Showing 1 to 25 of 490 CVEs