Qlik
Qlik Sense: vulnerabilidades y CVE
Qlik Sense tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses1
Críticas2
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-48365 | Crítica (9.9) | 47% | ⚠ Explotación activa | 15 nov 2023 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege… |
| CVE-2023-41265 | Crítica (9.9) | 88% | ⚠ Explotación activa | 29 ago 2023 | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch… |
| CVE-2023-41266 | Media (6.5) | 85% | ⚠ Explotación activa | 29 ago 2023 | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-61138 | Alta (7.5) | 0.29% | — | 20 nov 2025 | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory. |
| CVE-2023-48365 | Crítica (9.9) | 47% | ⚠ Explotación activa | 15 nov 2023 | Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege… |
| CVE-2023-41266 | Media (6.5) | 85% | ⚠ Explotación activa | 29 ago 2023 | A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and… |
| CVE-2023-41265 | Crítica (9.9) | 88% | ⚠ Explotación activa | 29 ago 2023 | An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch… |
| CVE-2021-36761 | Media (5.3) | 1.2% | — | 21 jun 2022 | The GeoAnalytics feature in Qlik Sense April 2020 patch 4 allows SSRF. |
| CVE-2022-0564 | Media (5.3) | 1.4% | — | 21 feb 2022 | A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate domain user accounts. An attacker could exploit this vulnerability by sending authentication requests to an affected… |
| CVE-2019-11628 | Media (6.5) | 0.97% | — | 1 may 2019 | An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.