CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “xen”

339 vulnerabilities found for “xen”

Page 1 of 17

CVE-2021-47809
HIGH7.8

Disk Sorter Enterprise 13.6.12 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Sorter Enterprise\bin\disksrs.exe' to inject malicious executables and escalate privileges.

flexense / disk_sorter
Local
Published Jan 16, 2026
Page 1 of 17
CVE-2022-23142
MEDIUM5.3

ZXEN CG200 has a DoS vulnerability. An attacker could construct and send a large number of HTTP GET requests in a short time, which can make the product management websites not accessible.

zte / zxen_cg200_firmware
Network
Published Jul 18, 2022
CVE-2021-44519
HIGH8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to remote code execution.

citrix / xenmobile_server+8
Network
Published Apr 19, 2022
CVE-2021-44520
HIGH8.8

In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.

citrix / xenmobile_server+8
Network
Published Apr 13, 2022
CVE-2022-26151
HIGH7.2

Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.

citrix / xenmobile_server+10
Network
Published Apr 13, 2022
CVE-2021-22928
HIGH7.8

A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Windows VDA that has either Citrix Profile Management or Citrix Profile Management WMI Plugin installed to escalate their privilege level on that Windows VDA to SYSTEM.

citrix / virtual_apps_and_desktops+8
Local
Published Aug 5, 2021
CVE-2020-8283
HIGH8.8

An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.

citrix / virtual_apps_and_desktops+13
Network
Published Dec 14, 2020
CVE-2020-29659
CRITICAL9.8

A buffer overflow in the web server of Flexense DupScout Enterprise 10.0.18 allows a remote anonymous attacker to execute code as SYSTEM by overflowing the sid parameter via a GET /settings&sid= attack.

flexense / dupscout
Network
Published Dec 9, 2020
CVE-2020-8269
HIGH8.8

An unprivileged Windows user on the VDA can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9

citrix / virtual_apps_and_desktops+13
Network
Published Nov 16, 2020
CVE-2020-8253
HIGH7.5

Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 leads to the ability to access sensitive files.

citrix / xenmobile_server+17
Network
Published Sep 18, 2020
CVE-2020-8210
HIGH7.5

Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 discloses credentials of a service account.

citrix / xenmobile_server+20
Network
Published Aug 17, 2020
CVE-2020-8212
CRITICAL9.8

Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows access to privileged functionality.

citrix / xenmobile_server+15
Network
Published Aug 17, 2020
CVE-2020-8211
CRITICAL9.8

Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.

citrix / xenmobile_server+20
Network
Published Aug 17, 2020
CVE-2020-8208
MEDIUM6.1

Improper input validation in Citrix XenMobile Server 10.12 before RP1, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.11 before RP6 and Citrix XenMobile Server before 10.9 RP5 allows Cross-Site Scripting (XSS).

citrix / xenmobile_server+17
Network
Published Aug 17, 2020
CVE-2020-8209
HIGH7.5

Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and leads to the ability to read arbitrary files.

citrix / xenmobile_server+17
Network
Published Aug 17, 2020
CVE-2018-10649
MEDIUM6.1

There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

citrix / xenmobile_server+2
Network
Published May 23, 2018
CVE-2018-10648
CRITICAL9.8

There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Network
Published May 23, 2018
CVE-2018-10650
HIGH7.8

There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

citrix / xenmobile_server+4
Local
Published May 23, 2018
CVE-2018-10566
MEDIUM6.1

XSS exists in Flexense DupScout Enterprise from v10.0.18 to v10.7.

flexense / dupscout
Network
Published May 2, 2018
CVE-2017-13696
CRITICAL9.8

A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.

flexense / dupscout+3
Network
Published Jan 24, 2018