Qualys, Inc.

First CVE: Apr 18, 2023Active for: 3 years
10
CVEs Published
More CVEs Published than 27% of tracked CNAs
3.3
Avg CVEs / Year
More Avg CVEs / Year than 24% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Qualys, Inc. as a CNA, 90.0% affect products that Qualys, Inc. develops as a vendor.

90.0%
Self-reported: 9Third-party: 1

Of all the CVEs published that affect products developed by Qualys, Inc., 81.8% are self-published by Qualys, Inc. as a CNA.

81.8%
18.2%
Self-published: 9Published by other CNAs: 2

Trends Over Time

The number and severity of CVEs published by Qualys, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2023
3 years ago
Most Recent CVE
Nov 10, 2025
256 days ago

Top CVEs

All CVEs published by Qualys, Inc. as a CNA, regardless of affected vendor or product.

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using a
Nov 10, 20256.322NONO
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (mac
Apr 18, 20237.022NONO
A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the lo
Apr 18, 20237.022NONO
An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious copy of a Dependency Link Librar
Apr 18, 20237.022NONO
An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack v
Apr 18, 20236.321NONO
Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor
Jan 9, 20246.519NONO
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnera
Dec 8, 20235.419NONO
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a conne
Jan 9, 20246.518NONO
Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor
Jan 9, 20245.415NONO
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configur
Sep 8, 20234.314NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA10 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHigh
Attack Vector
Local5 (50.0%)
Network5 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High5 (50.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low8 (80.0%)
High1 (10.0%)
None1 (10.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Qualys, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Qualys, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs