vciy

CVEs we hold for Xen

Records whose assigning authority named Xen as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-79603Unconditionally do TLB flushing ahead of page scrubbingXen
CVE-2026-79602x86: improper handling of HVM emulation return codesXen
CVE-2026-74239XenForo < 2.3.13 Path Traversal via Style Archive Importer on WindowsXenForo
CVE-2026-73321XenForo < 2.3.13 Uncontrolled Recursion DoS via BBCode ParserXenForo
CVE-2026-73320XenForo < 2.3.13 Unauthenticated Information Disclosure via Unfurl EndpointXenForo
CVE-2026-73319XenForo < 2.3.13 XSS via Dynamic Redirect HandlerXenForo
CVE-2026-73318XenForo < 2.3.13 Missing Authorization via force-agreement ControllerXenForo
CVE-2026-73317XenForo < 2.3.13 Missing Authorization via ACP Cache-Rebuild DispatcherXenForo
CVE-2026-73316XenForo < 2.3.13 Payment Replay via PayPal REST Payment ProviderXenForo
CVE-2026-73315XenForo < 2.3.13 SSRF via PayPal REST Webhook HandlerXenForo
CVE-2026-73314XenForo < 2.3.13 Signature Verification Bypass via PayPal REST WebhookXenForo
CVE-2026-73313XenForo < 2.3.13 MFA Bypass via Passkey TFA ProviderXenForo
CVE-2026-73312XenForo < 2.3.13 Refresh Token Replay via Expired Access TokenXenForo
CVE-2026-73311XenForo < 2.3.13 OAuth2 Authorization Code ReuseXenForo
CVE-2026-73310XenForo < 2.3.13 OAuth2 Authorization Code Token Theft via redirect_uri BypassXenForo
CVE-2026-73309XenForo < 2.3.13 Authentication Bypass via OAuth2 Token EndpointXenForo
CVE-2026-66473WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerabilityXendit Payment
CVE-2026-62437x86: DMs may cause mem leak by IRQ bindingXen
CVE-2026-62436grant-table: version change racing with other operationsXen
CVE-2026-62435grant-table: version change racing with other operationsXen
CVE-2026-62434PoD: Don't try to reclaim special pagesXen
CVE-2026-62433correct buffer checks for DM_OP hypercallsXen
CVE-2026-62432evtchn: Race between FIFO expand and resetXen
CVE-2026-62431Viridian STIMER division by zeroXen
CVE-2026-62430x86: Out-of-bounds read in vRTC emulationXen
CVE-2026-62429vNUMA domain cleanup may race other operationsXen
CVE-2026-62428grant-table: type confusion in grant-copyXen
CVE-2026-62427sysctl and platform-op locks open to abuseXen
CVE-2026-62426sysctl and platform-op locks open to abuseXen
CVE-2026-62425buffer overruns in libfsimage iso9660 handlingXen
CVE-2026-62424buffer overruns in libfsimage iso9660 handlingXen
CVE-2026-62423buffer overruns in libfsimage iso9660 handlingXen
CVE-2026-42495buffer overruns in libfsimage iso9660 handlingXen
CVE-2026-42494buffer overruns in libfsimage iso9660 handlingXen
CVE-2026-42493x86 shadow paging is deprecatedXen
CVE-2026-42492vIRQ event channel binding may break XenstoreXen
CVE-2026-42490domctl lock open to abuseXen
CVE-2026-42489domctl lock open to abuseXen
CVE-2026-42488x86: mismatched mapcache metadataXen
CVE-2026-42487x86 HVM I/O port list traversalXen
CVE-2026-42486Multiple RBAC issues in XAPIXen XAPI
CVE-2026-4075BWL Advanced FAQ Manager Lite <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sbox_id'…xenioushk BWL Advanced FAQ Manager Lite
CVE-2026-35174Chyrp Lite has a Path Traversal to Remote Code Executionxenocrat chyrp-lite
CVE-2026-35173Chyrp Lite has an IDOR via Mass Assignment in Post Modelxenocrat chyrp-lite
CVE-2026-35057XenForo Stored Cross-Site Scripting via Structured Text MentionsXenForo
CVE-2026-35056XenForo Remote Code Execution via Authenticated AdminXenForo
CVE-2026-35055XenForo Cross-Site Scripting via Lightbox in PostsXenForo
CVE-2026-35054XenForo Stored Cross-Site Scripting via BB Code RenderingXenForo
CVE-2026-23562Multiple RBAC issues in XAPIXen XAPI
CVE-2026-23561Multiple RBAC issues in XAPIXen XAPI
CVE-2026-23560Multiple RBAC issues in XAPIXen XAPI
CVE-2026-23559Multiple RBAC issues in XAPIXen XAPI
CVE-2026-23558grant table v2 race in status page mappingXen
CVE-2026-23557Xenstored DoS via XS_RESET_WATCHES commandXen
CVE-2026-23556oxenstored keeps quota related use counts across domain destructionXen oxenstored
CVE-2026-23555Xenstored DoS by unprivileged domainXen
CVE-2026-23554Use after free of paging structures in EPTXen
CVE-2026-23553x86: incomplete IBPB for vCPU isolationXen
CVE-2025-71282XenForo Path Disclosure via open_basedir ExceptionsXenForo
CVE-2025-71281XenForo Template Method Call Restriction BypassXenForo
CVE-2025-71280XenForo Local Account Page Caching Information DisclosureXenForo
CVE-2025-71279XenForo Passkey Security BypassXenForo
CVE-2025-71278XenForo OAuth2 Unauthorized Scope RequestXenForo
CVE-2025-68992WordPress BWL Knowledge Base Manager plugin <= 1.6.3 - Cross Site Scripting (XSS) vulnerabilityxenioushk BWL Knowledge Base Manager
CVE-2025-68991WordPress BWL Pro Voting Manager plugin <= 1.4.9 - Cross Site Scripting (XSS) vulnerabilityxenioushk BWL Pro Voting Manager
CVE-2025-68990WordPress BWL Pro Voting Manager plugin <= 1.4.9 - SQL Injection vulnerabilityxenioushk BWL Pro Voting Manager
CVE-2025-58151varstored: TOCTOU issues with mapped guest memoryXen varstored
CVE-2025-58150x86: buffer overrun with shadow paging + tracingXen
CVE-2025-58149Incorrect removal of permissions on PCI device unplugXen
CVE-2025-58148x86: Incorrect input sanitisation in Viridian hypercallsXen
CVE-2025-58147x86: Incorrect input sanitisation in Viridian hypercallsXen
CVE-2025-58146XAPI UTF-8 string handlingXen XAPI
CVE-2025-58145Arm issues with page refcountingXen
CVE-2025-58144Arm issues with page refcountingXen
CVE-2025-58143Mutiple vulnerabilities in the Viridian interfaceXen
CVE-2025-58142Mutiple vulnerabilities in the Viridian interfaceXen
CVE-2025-27466Mutiple vulnerabilities in the Viridian interfaceXen
CVE-2025-27465x86: Incorrect stubs exception handling for flags recoveryXen
CVE-2025-27464WinPVDrivers: Excessive permissions on user-exposed devicesXen Windows PV drivers
CVE-2025-27463WinPVDrivers: Excessive permissions on user-exposed devicesXen Windows PV drivers
CVE-2025-27462WinPVDrivers: Excessive permissions on user-exposed devicesXen Windows PV drivers
CVE-2025-1713deadlock potential with VT-d and legacy PCI device pass-throughXen
CVE-2024-58342XenForo Open Redirect via getDynamicRedirectXenForo
CVE-2024-45819libxl leaks data to PVH guests via ACPI tablesXen
CVE-2024-45818Deadlock in x86 HVM standard VGA handlingXen
CVE-2024-45817x86: Deadlock in vlapic_error()Xen
CVE-2024-32136WordPress BWL Advanced FAQ Manager plugin <= 2.0.3 - Auth. SQL Injection vulnerabilityXenioushk BWL Advanced FAQ Manager
CVE-2024-31146PCI device pass-through with shared resourcesXen
CVE-2024-31145error handling in x86 IOMMU identity mappingXen
CVE-2024-31144Xapi: Metadata injection attack against backup/restore functionalityXen
CVE-2024-31143double unlock in x86 guest IRQ handlingXen
CVE-2024-31142x86: Incorrect logic for BTC/SRSO mitigationsXen
CVE-2024-2201CVE-2024-2201Xen
CVE-2024-13801BWL Advanced FAQ Manager <= 2.1.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options…xenioushk BWL Advanced FAQ Manager
CVE-2023-53904Xenforo 2.2.13 Authenticated Stored Cross-Site Scripting via Smilie CategoriesXenforo
CVE-2023-46842x86 HVM hypercalls may trigger Xen bug checkXen
CVE-2023-46841x86: shadow stack vs exceptions from emulation stubsXen
CVE-2023-46840VT-d: Failure to quarantine devices in !HVM buildsXen
CVE-2023-46839pci: phantom functions assigned to incorrect contextsXen
CVE-2023-46837arm32: The cache may not be properly cleaned/invalidated (take two)Xen
CVE-2023-46836x86: BTC/SRSO fixes not fully effectiveXen
CVE-2023-46835x86/AMD: mismatch in IOMMU quarantine page table levelsXen
CVE-2023-34328x86/AMD: Debug Mask handlingXen
CVE-2023-34327x86/AMD: Debug Mask handlingXen
CVE-2023-34326x86/AMD: missing IOMMU TLB flushingXen
CVE-2023-34325Multiple vulnerabilities in libfsimage disk handlingXen
CVE-2023-34323xenstored: A transaction conflict can crash C XenstoredXen
CVE-2023-34322top-level shadow reference dropped too early for 64-bit PV guestsXen
CVE-2023-34321arm32: The cache may not be properly cleaned/invalidatedXen
CVE-2023-34320arm: Guests can trigger a deadlock on Cortex-A77Xen
CVE-2022-42336no title heldxen
CVE-2022-42335no title heldxen
CVE-2022-42334no title heldxen
CVE-2022-42333no title heldxen
CVE-2022-42332no title heldxen
CVE-2022-42331no title heldxen
CVE-2022-42330no title heldxen
CVE-2022-42327no title heldxen
CVE-2022-42326no title heldxen
CVE-2022-42325no title heldxen
CVE-2022-42324no title heldxen
CVE-2022-42323no title heldxen
CVE-2022-42322no title heldxen
CVE-2022-42321no title heldxen
CVE-2022-42320no title heldxen
CVE-2022-42319no title heldxen
CVE-2022-42318no title heldxen
CVE-2022-42317no title heldxen
CVE-2022-42316no title heldxen
CVE-2022-42315no title heldxen
CVE-2022-42314no title heldxen
CVE-2022-42313no title heldxen
CVE-2022-42312no title heldxen
CVE-2022-42311no title heldxen
CVE-2022-42310no title heldxen
CVE-2022-42309no title heldxen
CVE-2022-33748no title heldxen
CVE-2022-33747no title heldxen
CVE-2022-33746no title heldxen
CVE-2022-33745no title heldxen
CVE-2022-26364no title heldxen
CVE-2022-26363no title heldxen
CVE-2022-26362no title heldxen
CVE-2022-26361no title heldxen
CVE-2022-26360no title heldxen
CVE-2022-26359no title heldxen
CVE-2022-26358no title heldxen
CVE-2022-26357no title heldxen
CVE-2022-26356no title heldxen
CVE-2022-23035no title heldxen
CVE-2022-23034no title heldxen
CVE-2022-23033no title heldxen
CVE-2021-28710no title heldxen
CVE-2021-28709no title heldxen
CVE-2021-28708no title heldxen
CVE-2021-28707no title heldxen
CVE-2021-28706no title heldxen
CVE-2021-28705no title heldxen
CVE-2021-28704no title heldxen
CVE-2021-28703no title heldXen
CVE-2021-28702no title heldxen
CVE-2021-28701no title heldxen
CVE-2021-28700no title heldxen
CVE-2021-28699no title heldxen
CVE-2021-28698no title heldxen
CVE-2021-28697no title heldxen
CVE-2021-28696no title heldxen
CVE-2021-28695no title heldxen
CVE-2021-28694no title heldxen
CVE-2021-28693no title heldxen
CVE-2021-28692no title heldxen
CVE-2021-28690no title heldxen
CVE-2021-28689no title heldXen
CVE-2021-28687no title heldxen
CVE-2009-20003Xenorate <= 2.50 .xpl File Stack-Based Buffer OverflowXenorate

175 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.