Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

xen — Vulnerabilities & Security Advisories 129

All 129 CVE vulnerabilities found in xen, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability records for Xen, the open-source type-1 hypervisor developed by Xen Project (formerly Citrix and NetScale). The collection focuses on security flaws affecting virtualization, memory management, and inter-domain communication, covering advisories published over the past decade. Readers can use this index to track the vendor’s advisory history, analyze recurring weakness classes, and review the complete vulnerability timeline for the Xen platform.

Vendor: Xen

CVE ID Title CVSS Severity Published
CVE-2025-58150 x86: buffer overrun with shadow paging + tracing 8.8AI High AI 2026-01-28
CVE-2025-58149 Incorrect removal of permissions on PCI device unplug 9.1 - 2025-10-31
CVE-2025-58147 x86: Incorrect input sanitisation in Viridian hypercalls 7.8 - 2025-10-31
CVE-2025-58148 x86: Incorrect input sanitisation in Viridian hypercalls 7.8 - 2025-10-31
CVE-2025-58145 Arm issues with page refcounting 7.1AI High AI 2025-09-11
CVE-2025-58144 Arm issues with page refcounting 7.1AI High AI 2025-09-11
CVE-2025-27466 Mutiple vulnerabilities in the Viridian interface 5.1AI Medium AI 2025-09-11
CVE-2025-58143 Mutiple vulnerabilities in the Viridian interface 5.1AI Medium AI 2025-09-11
CVE-2025-58142 Mutiple vulnerabilities in the Viridian interface 5.1AI Medium AI 2025-09-11
CVE-2025-1713 deadlock potential with VT-d and legacy PCI device pass-through 6.5AI Medium AI 2025-07-17
CVE-2025-27465 x86: Incorrect stubs exception handling for flags recovery 6.2AI Medium AI 2025-07-16
CVE-2024-31144 Xapi: Metadata injection attack against backup/restore functionality 7.1AI High AI 2025-02-14
CVE-2024-2201 CVE-2024-2201 6.2AI Medium AI 2024-12-19
CVE-2024-45819 libxl leaks data to PVH guests via ACPI tables 7.1 - 2024-12-19
CVE-2024-45818 Deadlock in x86 HVM standard VGA handling 6.5 - 2024-12-19
CVE-2024-45817 x86: Deadlock in vlapic_error() 5.5AI Medium AI 2024-09-25
CVE-2024-31146 PCI device pass-through with shared resources 8.1AI High AI 2024-09-25
CVE-2024-31145 error handling in x86 IOMMU identity mapping 7.1AI High AI 2024-09-25
CVE-2024-31143 double unlock in x86 guest IRQ handling 5.5AI Medium AI 2024-07-18
CVE-2024-31142 x86: Incorrect logic for BTC/SRSO mitigations 6.2 - 2024-05-16
CVE-2023-46842 x86 HVM hypercalls may trigger Xen bug check 7.5AI High AI 2024-05-16
CVE-2023-46841 x86: shadow stack vs exceptions from emulation stubs 7.8AI High AI 2024-03-20
CVE-2023-46840 VT-d: Failure to quarantine devices in !HVM builds 7.8AI High AI 2024-03-20
CVE-2023-46839 pci: phantom functions assigned to incorrect contexts 5.9 - 2024-03-20
CVE-2023-46837 arm32: The cache may not be properly cleaned/invalidated (take two) 6.1AI Medium AI 2024-01-05
CVE-2023-46836 x86: BTC/SRSO fixes not fully effective 9.1AI Critical AI 2024-01-05
CVE-2023-46835 x86/AMD: mismatch in IOMMU quarantine page table levels 8.4AI High AI 2024-01-05
CVE-2023-34328 x86/AMD: Debug Mask handling 5.5 - 2024-01-05
CVE-2023-34327 x86/AMD: Debug Mask handling 5.5 - 2024-01-05
CVE-2023-34325 Multiple vulnerabilities in libfsimage disk handling 8.2 - 2024-01-05

All 129 known CVE vulnerabilities affecting xen with full Chinese analysis, references, and POCs where available.