Записи qlik
13 опубликованных записей вендора qlik.
Профиль для исследователя
- Попали в KEV
- 3 · 23,1 %
- С эксплойтом
- 3 · 23,1 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 100 дн.
Повторяющиеся классы
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')2
- CWE-269 Improper Privilege Management1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2023-41265Готовый эксплойт | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 qlik · qlik sense · CWE-444 | Критическая9,9 | KEV | 88,2 % | 29 авг. 2023 г. |
83Срочно | CVE-2023-48365Готовый эксплойт | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.qlik · qlik sense · CWE-444 | Критическая9,9 | KEV | 47,5 % | 15 нояб. 2023 г. |
81Срочно | CVE-2023-41266Готовый эксплойт | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 aqlik · qlik sense · CWE-22 | Средняя6,5 | KEV | 84,8 % | 29 авг. 2023 г. |
35Наблюдать | CVE-2024-36077Эксплойта нет | Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation.CWE-269 | Высокая8,8 | — | 0,6 % | 22 мая 2024 г. |
31Наблюдать | CVE-2024-29863Proof of concept | A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may CWE-362 | Высокая7,8 | — | 0,4 % | 5 апр. 2024 г. |
31Наблюдать | CVE-2021-41988Эксплойта нет | Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.qlik · nprinting designer · CWE-668 | Высокая7,8 | — | 0,3 % | 26 янв. 2023 г. |
31Наблюдать | CVE-2021-41989Эксплойта нет | Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.qlik · qlikview · CWE-668 | Высокая7,8 | — | 0,3 % | 26 янв. 2023 г. |
30Наблюдать | CVE-2015-3623Proof of concept | XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgerqlik · qlikview | Средняя6,4 | — | 15,8 % | 16 сент. 2015 г. |
30Наблюдать | CVE-2025-61138Эксплойта нет | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.qlik · qlik sense · CWE-538 | Высокая7,5 | — | 0,3 % | 20 нояб. 2025 г. |
26Наблюдать | CVE-2019-11628Эксплойта нет | An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; andqlik · qlikview server · CWE-917 | Средняя6,5 | — | 1,0 % | 30 апр. 2019 г. |
21Наблюдать | CVE-2022-0564Эксплойта нет | Qlik Sense Enterprise Domain User enumerationqlik · qlik sense · CWE-204 | Средняя5,3 | — | 1,4 % | 21 февр. 2022 г. |
21Наблюдать | CVE-2021-36761Эксплойта нет | The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.qlik · qlik sense · CWE-918 | Средняя5,3 | — | 1,2 % | 21 июн. 2022 г. |
21Наблюдать | CVE-2022-42248Proof of concept | QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.qlik · qlikview · CWE-79 | Средняя5,4 | — | 0,4 % | 6 мар. 2023 г. |
- CVE-2023-4126595Срочно
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 88 %qlik · qlik sense29 авг. 2023 г.
- CVE-2023-4836583Срочно
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 47 %qlik · qlik sense15 нояб. 2023 г.
- CVE-2023-4126681Срочно
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 a
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 85 %qlik · qlik sense29 авг. 2023 г.
- CVE-2024-3607735Наблюдать
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %22 мая 2024 г.
- CVE-2024-2986331Наблюдать
A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may
ВысокаяCVSS 7,8Proof of conceptEPSS 0 %5 апр. 2024 г.
- CVE-2021-4198831Наблюдать
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %qlik · nprinting designer26 янв. 2023 г.
- CVE-2021-4198931Наблюдать
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %qlik · qlikview26 янв. 2023 г.
- CVE-2015-362330Наблюдать
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forger
СредняяCVSS 6,4Proof of conceptEPSS 16 %qlik · qlikview16 сент. 2015 г.
- CVE-2025-6113830Наблюдать
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %qlik · qlik sense20 нояб. 2025 г.
- CVE-2019-1162826Наблюдать
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and
СредняяCVSS 6,5Эксплойта нетEPSS 1 %qlik · qlikview server30 апр. 2019 г.
- CVE-2022-056421Наблюдать
Qlik Sense Enterprise Domain User enumeration
СредняяCVSS 5,3Эксплойта нетEPSS 1 %qlik · qlik sense21 февр. 2022 г.
- CVE-2021-3676121Наблюдать
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %qlik · qlik sense21 июн. 2022 г.
- CVE-2022-4224821Наблюдать
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
СредняяCVSS 5,4Proof of conceptEPSS 0 %qlik · qlikview6 мар. 2023 г.