Vulnerability index

Browse CVEs

149 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xen HIGH 7.8
CVE-2026-23558

The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or PVH guest does a grant table …

Patch available
Fix from $1,950 2026-05-19
Xen MEDIUM 6.5
CVE-2026-23557

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored w…

Patch available
Fix from $1,600 2026-05-19
Xen HIGH 7.8
CVE-2026-23554

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modification…

Patch available
Fix from $1,950 2026-03-23
Xen HIGH 7.1
CVE-2026-23555

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error i…

Patch available
Fix from $1,950 2026-03-23
Xen HIGH 8.8
CVE-2025-58150

Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables are written to with guest co…

Patch available
Fix from $1,950 2026-01-28
Xen HIGH 7.5
CVE-2025-58148

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hyper…

Patch available
Fix from $1,950 2025-10-31
Xen HIGH 7.5
CVE-2025-58149

When passing through PCI devices, the detach logic in libxl won't remove access permissions to any 64bit memory BARs the device might have. As a res…

Patch available
Fix from $1,950 2025-10-31
Xen HIGH 7.5
CVE-2025-58147

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Some Viridian hyper…

Patch available
Fix from $1,950 2025-10-31
Xen CRITICAL 9.8
CVE-2025-58142

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple …

Fix: 4.17.0+
Fix from $2,300 2025-09-11
Xen CRITICAL 9.8
CVE-2025-58143

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple …

Fix: 4.17.0+
Fix from $2,300 2025-09-11
Xen HIGH 7.5
CVE-2025-58144

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issue…

Fix: 4.17.0+
Fix from $1,950 2025-09-11
Xen HIGH 7.5
CVE-2025-58145

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are two issue…

Fix: 4.17.0+
Fix from $1,950 2025-09-11
Xen CRITICAL 9.8
CVE-2025-27466

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] There are multiple …

Fix: 4.17.0+
Fix from $2,300 2025-09-11
Xen HIGH 7.5
CVE-2025-1713

When setting up interrupt remapping for legacy PCI(-X) devices, including PCI(-X) bridges, a lookup of the upstream bridge is required. This lookup, …

Patch available
Fix from $1,950 2025-07-17
Xen MEDIUM 6.5
CVE-2024-45818

The hypervisor contains code to accelerate VGA memory accesses for HVM guests, when the (virtual) VGA is in "standard" mode. Locking involved there …

Fix: 4.20.0+
Fix from $1,600 2024-12-19
Xen MEDIUM 5.5
CVE-2024-45819

PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied…

Patch available
Fix from $1,600 2024-12-19
Xen HIGH 7.5
CVE-2024-31145

Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or …

Patch available
Fix from $1,950 2024-09-25
Xen HIGH 7.5
CVE-2024-31146

When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests indi…

Patch available
Fix from $1,950 2024-09-25
Xen HIGH 7.3
CVE-2024-45817

In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can…

Patch available
Fix from $1,950 2024-09-25
Xen HIGH 7.5
CVE-2024-31143

An optional feature of PCI MSI called "Multiple Message" allows a device to use multiple consecutive interrupt vectors. Unlike for MSI-X, the settin…

Patch available
Fix from $1,950 2024-07-18
Xen MEDIUM 5.5
CVE-2023-46835

The current setup of the quarantine page tables assumes that the quarantine domain (dom_io) has been initialized with an address width of DEFAULT_DOM…

Patch available
Fix from $1,600 2024-01-05
Xen HIGH 7.8
CVE-2023-34322

For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. Since Xen itself needs to…

Fix: 4.15.0+
Fix from $1,950 2024-01-05
Xen HIGH 7.8
CVE-2023-34325

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] libfsimage contains…

Patch available
Fix from $1,950 2024-01-05
Xen HIGH 7.8
CVE-2023-34326

The caching invalidation guidelines from the AMD-Vi specification (48882—Rev 3.07-PUB—Oct 2022) is incorrect on some hardware, as devices will malfun…

Mitigation only
Fix from $1,950 2024-01-05
Xen MEDIUM 5.5
CVE-2023-34323

When a transaction is committed, C Xenstored will first check the quota is correct before attempting to commit any nodes. It would be possible that …

Fix: 4.17.0+
Fix from $1,600 2024-01-05
Xen MEDIUM 5.5
CVE-2023-34327

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~201…

Patch available
Fix from $1,600 2024-01-05
Xen MEDIUM 5.5
CVE-2023-34328

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] AMD CPUs since ~201…

Fix: 4.14.0+
Fix from $1,600 2024-01-05
Xen HIGH 7.5
CVE-2022-42330

Guests can cause Xenstore crash via soft reset When a guest issues a "Soft Reset" (e.g. for performing a kexec) the libxl based Xen toolstack will no…

Mitigation only
Fix from $1,950 2023-01-26
Xapi MEDIUM 5.3
CVE-2022-33749

XAPI open file limit DoS It is possible for an unauthenticated client on the network to cause XAPI to hit its file-descriptor limit. This causes XAPI…

Patch available
Fix from $1,600 2022-10-11
Xen HIGH 7.0
CVE-2021-28703

grant table v2 status pages may remain accessible after de-allocation (take two) Guest get permitted access to certain Xen-owned pages of memory. The…

Fix: 14.4+
Fix from $1,950 2021-12-07