Qlik Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Qlik products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
3
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Qlik KEVs Added by Year
3 Qlik KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-41265
An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7... |
Qlik Sense Enterprise for Windows | Confirmed | In CISA | 07 Dec 2023 |
|
CVE-2023-41266
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and... |
Qlik Sense Enterprise for Windows | Confirmed | In CISA | 07 Dec 2023 |
|
CVE-2023-48365
Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation... |
Sense Enterprise for Windows | Confirmed | In CISA | 13 Jan 2025 |
Common Vulnerability Classes (CWE)
- CWE-444 — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') 2
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology