Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qualys, Inc.

First CVE: Aug 18, 2022Active for: 4 yearsTotal CVEs: 11
18.3
VTI Score
Low

Qualys, Inc. maintains a focused portfolio of cloud-based vulnerability management and compliance platforms, including cloud agents, policy compliance tools, and container scanning solutions that operate across enterprise infrastructure. Its vulnerability disclosures cluster around application-layer and trust-boundary weaknesses, including cross-site scripting, XML external entity injection, race conditions, link-following flaws, and integrity-check validation issues that are characteristic of web-facing and multi-tenant cloud services. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qualys, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2022
3 years ago
Most Recent CVE
Jan 9, 2024
927 days ago

Self-Reporting Analysis

Of all the CVEs published by Qualys, Inc. as a CNA, 90.0% affect products that Qualys, Inc. develops as a vendor.

90.0%
Self-reported: 9 (90.0%)
Third-party: 1 (10.0%)

Of all the CVEs published that affect products developed by Qualys, Inc., 81.8% are self-published by Qualys, Inc. as a CNA.

81.8%
18.2%
Self-published: 9 (81.8%)
Other CNAs: 2 (18.2%)

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-29549HIGH
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure th
Aug 18, 20227.324NONO
CVE-2023-28143HIGH
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (mac
Apr 18, 20237.022NONO
CVE-2023-28142HIGH
A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the lo
Apr 18, 20237.022NONO
CVE-2023-28140HIGH
An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious copy of a Dependency Link Librar
Apr 18, 20237.022NONO
CVE-2023-28141MEDIUM
An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack v
Apr 18, 20236.321NONO
CVE-2022-29550MEDIUM
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly wr
Aug 18, 20225.520NONO
CVE-2023-6147MEDIUM
Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor
Jan 9, 20246.519NONO
CVE-2023-6146MEDIUM
A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnera
Dec 8, 20235.419NONO
CVE-2023-6149MEDIUM
Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a conne
Jan 9, 20246.518NONO
CVE-2023-6148MEDIUM
Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while perfor
Jan 9, 20245.415NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
64%
36%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (54.5%)
Network5 (45.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (63.6%)
High4 (36.4%)
Unknown0 (0.0%)
User Interaction
None7 (63.6%)
Unknown0 (0.0%)
Required4 (36.4%)
Privileges Required
Low10 (90.9%)
High0 (0.0%)
None1 (9.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qualys, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qualys, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qualys, Inc.'s Products

View all 2 CNAs →

Top CWEs