VYPR
Vendor

Qlik

Products
21
CVEs
36
Across products
52
Status
Private

Products

21

Recent CVEs

36
View all 36 CVEs →
  • CVE-2023-41265CriKEVAug 29, 2023
    risk 0.87cvss 9.6epss 0.84

    An HTTP Request Tunneling vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows a remote attacker to elevate their…

  • CVE-2023-48365CriKEVNov 15, 2023
    risk 0.82cvss 9.6epss 0.25

    Qlik Sense Enterprise for Windows before August 2023 Patch 2 allows unauthenticated remote code execution, aka QB-21683. Due to improper validation of HTTP headers, a remote attacker is able to elevate their privilege by tunneling HTTP requests, allowing them to execute HTTP…

  • CVE-2023-41266HigKEVAug 29, 2023
    risk 0.78cvss 8.2epss 0.82

    A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate…

  • CVE-2026-6264CriApr 14, 2026
    risk 0.64cvss 9.8epss 0.01

    A critical vulnerability in the Talend JobServer and Talend Runtime allows unauthenticated remote code execution via the JMX monitoring port. The attack vector is the JMX monitoring port of the Talend JobServer. The vulnerability can be mitigated for the Talend JobServer by…

  • CVE-2021-42837CriNov 5, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Talend Data Catalog before 7.3-20210930. After setting up SAML/OAuth, authentication is not correctly enforced on the native login page. Any valid user from the SAML/OAuth provider can be used as the username with an arbitrary password, and login will…

  • CVE-2014-2228CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbitrary code via unsafe deserialization of XML messages.

  • CVE-2021-40684CriSep 22, 2021
    risk 0.59cvss 9.1epss 0.01

    Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container…

  • CVE-2024-55579HigDec 9, 2024
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. An unprivileged user with network access may be able to create connection objects that trigger execution of arbitrary EXE files. This is fixed in November 2024 IR, May 2024 Patch 10, February…

  • CVE-2024-36077HigMay 22, 2024
    risk 0.57cvss 8.8epss 0.01

    Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their privilege due to improper validation. The attacker can elevate their privilege to the internal system role, which allows them to execute commands on the server. This affects February 2024…

  • CVE-2026-9057HigMay 20, 2026
    risk 0.53cvss 8.2epss 0.00

    A broken access control issue has been identified in the Talend Administration Center, that allows a user with “View” permission to modify the Talend Studio update URL. This issue was resolved in a patch, which is already available.

  • CVE-2019-11628HigMay 1, 2019
    risk 0.53cvss 8.2epss 0.01

    An issue was discovered in QlikView Server before 11.20 SR19, 12.00 and 12.10 before 12.10 SR11, 12.20 before SR9, and 12.30 before SR2; and Qlik Sense Enterprise and Qlik Analytics Platform installations that lack these patch levels: February 2018 Patch 4, April 2018 Patch 3,…

  • CVE-2024-29863HigApr 5, 2024
    risk 0.51cvss 7.8epss 0.00

    A race condition in the installer executable in Qlik Qlikview before versions May 2022 SR3 (12.70.20300) and May 2023 SR2 (12,80.20200) may allow an existing lower privileged user to cause code to be executed in the context of a Windows Administrator.

  • CVE-2022-45588HigFeb 3, 2023
    risk 0.51cvss 7.8epss 0.00

    All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previous version. Talend Remote Engine Gen 1 and Talend Cloud…

  • CVE-2021-41989HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2021-41988HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.

  • CVE-2025-61138HigNov 20, 2025
    risk 0.49cvss 7.5epss 0.00

    Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.

  • CVE-2024-55580HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality risks. This is fixed in…

  • CVE-2023-36301HigJun 26, 2023
    risk 0.49cvss 7.5epss 0.01

    Talend Data Catalog before 8.0-20230221 contain a directory traversal vulnerability in HeaderImageServlet.

  • CVE-2023-33247HigMay 26, 2023
    risk 0.49cvss 7.5epss 0.00

    Talend Data Catalog remote harvesting server before 8.0-20230413 contains a /upgrade endpoint that allows an unauthenticated WAR file to be deployed on the server. (A mitigation is that the remote harvesting server should be behind a firewall that only allows access to the…

  • CVE-2023-31444HigApr 28, 2023
    risk 0.49cvss 7.5epss 0.01

    In Talend Studio before 7.3.1-R2022-10 and 8.x before 8.0.1-R2022-09, microservices allow unauthenticated access to the Jolokia endpoint of the microservice. This allows for remote access to the JVM via the Jolokia JMX-HTTP bridge.