qlik records
13 published records for vendor qlik.
Researcher profile
- Entered KEV
- 3 · 23.1%
- Weaponized
- 3 · 23.1%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- 100 days
Recurring classes
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')2
- CWE-269 Improper Privilege Management1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-538 Insertion of Sensitive Information into Externally-Accessible File or Directory1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
95Now | CVE-2023-41265Weaponized | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 qlik · qlik sense · CWE-444 | Critical9.9 | KEV | 88.2% | Aug 29, 2023 |
83Now | CVE-2023-48365Weaponized | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.qlik · qlik sense · CWE-444 | Critical9.9 | KEV | 47.5% | Nov 15, 2023 |
81Now | CVE-2023-41266Weaponized | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 aqlik · qlik sense · CWE-22 | Medium6.5 | KEV | 84.8% | Aug 29, 2023 |
35Monitor | CVE-2024-36077No exploit | Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation.CWE-269 | High8.8 | — | 0.6% | May 22, 2024 |
31Monitor | CVE-2024-29863Proof of concept | A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may CWE-362 | High7.8 | — | 0.4% | Apr 5, 2024 |
31Monitor | CVE-2021-41988No exploit | Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.qlik · nprinting designer · CWE-668 | High7.8 | — | 0.3% | Jan 26, 2023 |
31Monitor | CVE-2021-41989No exploit | Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.qlik · qlikview · CWE-668 | High7.8 | — | 0.3% | Jan 26, 2023 |
30Monitor | CVE-2015-3623Proof of concept | XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forgerqlik · qlikview | Medium6.4 | — | 15.8% | Sep 16, 2015 |
30Monitor | CVE-2025-61138No exploit | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.qlik · qlik sense · CWE-538 | High7.5 | — | 0.3% | Nov 20, 2025 |
26Monitor | CVE-2019-11628No exploit | An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; andqlik · qlikview server · CWE-917 | Medium6.5 | — | 1.0% | Apr 30, 2019 |
21Monitor | CVE-2022-0564No exploit | Qlik Sense Enterprise Domain User enumerationqlik · qlik sense · CWE-204 | Medium5.3 | — | 1.4% | Feb 21, 2022 |
21Monitor | CVE-2021-36761No exploit | The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.qlik · qlik sense · CWE-918 | Medium5.3 | — | 1.2% | Jun 21, 2022 |
21Monitor | CVE-2022-42248Proof of concept | QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.qlik · qlikview · CWE-79 | Medium5.4 | — | 0.4% | Mar 6, 2023 |
- CVE-2023-4126595Now
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023
CriticalCVSS 9.9KEVWeaponizedEPSS 88%qlik · qlik senseAug 29, 2023
- CVE-2023-4836583Now
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683.
CriticalCVSS 9.9KEVWeaponizedEPSS 47%qlik · qlik senseNov 15, 2023
- CVE-2023-4126681Now
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 a
MediumCVSS 6.5KEVWeaponizedEPSS 85%qlik · qlik senseAug 29, 2023
- CVE-2024-3607735Monitor
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation.
HighCVSS 8.8No exploitEPSS 1%May 22, 2024
- CVE-2024-2986331Monitor
A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may
HighCVSS 7.8Proof of conceptEPSS 0%Apr 5, 2024
- CVE-2021-4198831Monitor
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
HighCVSS 7.8No exploitEPSS 0%qlik · nprinting designerJan 26, 2023
- CVE-2021-4198931Monitor
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
HighCVSS 7.8No exploitEPSS 0%qlik · qlikviewJan 26, 2023
- CVE-2015-362330Monitor
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server-side request forger
MediumCVSS 6.4Proof of conceptEPSS 16%qlik · qlikviewSep 16, 2015
- CVE-2025-6113830Monitor
Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
HighCVSS 7.5No exploitEPSS 0%qlik · qlik senseNov 20, 2025
- CVE-2019-1162826Monitor
An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and
MediumCVSS 6.5No exploitEPSS 1%qlik · qlikview serverApr 30, 2019
- CVE-2022-056421Monitor
Qlik Sense Enterprise Domain User enumeration
MediumCVSS 5.3No exploitEPSS 1%qlik · qlik senseFeb 21, 2022
- CVE-2021-3676121Monitor
The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF.
MediumCVSS 5.3No exploitEPSS 1%qlik · qlik senseJun 21, 2022
- CVE-2022-4224821Monitor
QlikView 12.60.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the QvsViewClient functionality.
MediumCVSS 5.4Proof of conceptEPSS 0%qlik · qlikviewMar 6, 2023