Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

XEROX — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting XEROX. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Xerox Corporation operates primarily as a provider of document management technologies, including multifunction printers and enterprise software solutions. With twenty-three recorded Common Vulnerabilities and Exposures (CVEs), the company’s historical attack surface has frequently involved remote code execution, cross-site scripting, and privilege escalation flaws within its web-based management interfaces and embedded firmware. These vulnerabilities often stem from insufficient input validation and weak authentication mechanisms in legacy systems. While no catastrophic data breaches have defined its public security history, the persistent presence of critical flaws in network-connected devices highlights ongoing challenges in securing embedded Linux environments. Security researchers continue to identify risks in Xerox’s document workflow software, emphasizing the need for rigorous patch management and network segmentation to mitigate potential exploitation by threat actors targeting enterprise infrastructure.

Found 9 results / 23 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-2252 XML External Entity (XXE) vulnerability resulting in Server-Side Request Forgery (SSRF) — FreeFlow Core CWE-611 7.5 High 2026-02-27
CVE-2026-2251 Path Traversal leading to Remote Code Execution (RCE) — FreeFlow Core CWE-22 9.8 Critical 2026-02-27
CVE-2025-8356 Path Traversal leading to RCE — FreeFlow Core CWE-22 9.8 Critical 2025-08-08
CVE-2025-8355 XXE leading to SSRF — FreeFlow Core CWE-611 7.5 High 2025-08-08
CVE-2024-47559 Authenticated RCE via Path Traversal — FreeFlow Core CWE-22 7.6 High 2024-10-07
CVE-2024-47558 Authenticated RCE via Path Traversal — FreeFlow Core CWE-22 7.6 High 2024-10-07
CVE-2024-47557 Pre-Auth RCE via Path Traversal — FreeFlow Core CWE-22 8.3 High 2024-10-07
CVE-2024-47556 Pre-Auth RCE via Path Traversal — FreeFlow Core CWE-22 8.3 High 2024-10-07
CVE-2024-47555 Missing Authentication - User & System Configuration — FreeFlow Core CWE-306 8.3 High 2024-10-07

This page lists every published CVE security advisory associated with XEROX. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.