Qualys, Inc. maintains a focused portfolio of cloud-based vulnerability management and compliance platforms, including cloud agents, policy compliance tools, and container scanning solutions that operate across enterprise infrastructure. Its vulnerability disclosures cluster around application-layer and trust-boundary weaknesses, including cross-site scripting, XML external entity injection, race conditions, link-following flaws, and integrity-check validation issues that are characteristic of web-facing and multi-tenant cloud services. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qualys, Inc. over time
Of all the CVEs published by Qualys, Inc. as a CNA, 90.0% affect products that Qualys, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Qualys, Inc., 81.8% are self-published by Qualys, Inc. as a CNA.
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29549HIGH An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure th | Aug 18, 2022 | 7.3 | 24 | NO | NO |
CVE-2023-28143HIGH
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7)
installer allows a local escalation of privilege bounded only to the time of
installation and only on older macOSX (mac | Apr 18, 2023 | 7.0 | 22 | NO | NO |
CVE-2023-28142HIGH
A Race Condition exists in the Qualys Cloud Agent for Windows
platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to
escalate privileges limited on the lo | Apr 18, 2023 | 7.0 | 22 | NO | NO |
CVE-2023-28140HIGH
An Executable Hijacking condition exists in the
Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers
may load a malicious copy of a Dependency Link Librar | Apr 18, 2023 | 7.0 | 22 | NO | NO |
CVE-2023-28141MEDIUM
An NTFS Junction condition exists in the Qualys Cloud Agent
for Windows platform in versions before 4.8.0.31. Attackers may write files to
arbitrary locations via a local attack v | Apr 18, 2023 | 6.3 | 21 | NO | NO |
CVE-2022-29550MEDIUM An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly wr | Aug 18, 2022 | 5.5 | 20 | NO | NO |
CVE-2023-6147MEDIUM Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor | Jan 9, 2024 | 6.5 | 19 | NO | NO |
CVE-2023-6146MEDIUM
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnera | Dec 8, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-6149MEDIUM
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a conne | Jan 9, 2024 | 6.5 | 18 | NO | NO |
CVE-2023-6148MEDIUM Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor | Jan 9, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qualys, Inc..
Media articles that mention a CVE ID that affects a product developed by Qualys, Inc. — matched by CVE ID, not by vendor name.