Qualys, Inc.
First CVE: Apr 18, 2023Active for: 3 years
10
CVEs Published
More CVEs Published than 27% of tracked CNAs
3.3
Avg CVEs / Year
More Avg CVEs / Year than 24% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 13% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Qualys, Inc. as a CNA, 90.0% affect products that Qualys, Inc. develops as a vendor.
90.0%
Self-reported: 9Third-party: 1
Of all the CVEs published that affect products developed by Qualys, Inc., 81.8% are self-published by Qualys, Inc. as a CNA.
81.8%
18.2%
Self-published: 9Published by other CNAs: 2
Trends Over Time
The number and severity of CVEs published by Qualys, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2023
3 years ago
Most Recent CVE
Nov 10, 2025
256 days ago
Top CVEs
All CVEs published by Qualys, Inc. as a CNA, regardless of affected vendor or product.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-43079MEDIUM The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using a | Nov 10, 2025 | 6.3 | 22 | NO | NO |
CVE-2023-28143HIGH
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7)
installer allows a local escalation of privilege bounded only to the time of
installation and only on older macOSX (mac | Apr 18, 2023 | 7.0 | 22 | NO | NO |
CVE-2023-28142HIGH
A Race Condition exists in the Qualys Cloud Agent for Windows
platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to
escalate privileges limited on the lo | Apr 18, 2023 | 7.0 | 22 | NO | NO |
CVE-2023-28140HIGH
An Executable Hijacking condition exists in the
Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers
may load a malicious copy of a Dependency Link Librar | Apr 18, 2023 | 7.0 | 22 | NO | NO |
CVE-2023-28141MEDIUM
An NTFS Junction condition exists in the Qualys Cloud Agent
for Windows platform in versions before 4.8.0.31. Attackers may write files to
arbitrary locations via a local attack v | Apr 18, 2023 | 6.3 | 21 | NO | NO |
CVE-2023-6147MEDIUM Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor | Jan 9, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-6146MEDIUM
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnera | Dec 8, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-6149MEDIUM
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a conne | Jan 9, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-6148MEDIUM Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor | Jan 9, 2024 | 5.4 | 15 | NO | NO |
CVE-2023-4777MEDIUM
An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configur | Sep 8, 2023 | 4.3 | 14 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA10 CVEs
70%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (50.0%)
Network5 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High5 (50.0%)
Unknown0 (0.0%)
User Interaction
None6 (60.0%)
Unknown0 (0.0%)
Required4 (40.0%)
Privileges Required
Low8 (80.0%)
High1 (10.0%)
None1 (10.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Qualys, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Qualys, Inc. as a CNA — matched by CVE ID, not by organization name.