Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Qualys/
  3. Qualys Patch Management

Qualys Patch Management

PatchAI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 19 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~46 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Automated patch deployment.

by Qualys · qualys.com · source ↗

Known CVEs (19)1 newAbout this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-70440 ↗MEDIUM 5.4new2026

    Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerabil…

  • CVE-2025-43079 ↗MEDIUM 6.32025

    The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and wi…

  • CVE-2024-48992 ↗HIGH 7.82024

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled R…

  • CVE-2024-48991 ↗HIGH 7.82024

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Pytho…

  • CVE-2024-48990 ↗HIGH 7.82024

    Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled…

  • CVE-2024-11003 ↗HIGH 7.82024

    Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which expects safe input. This could allow a local attacker to execute arbitrary shell …

  • CVE-2024-10224 ↗MEDIUM 5.32024

    Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe…

  • CVE-2023-6149 ↗MEDIUM 5.72024

    Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qua…

  • CVE-2023-6148 ↗MEDIUM 5.72024

    Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity …

  • CVE-2023-6147 ↗MEDIUM 5.72024

    Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity …

  • CVE-2023-6146 ↗MEDIUM 5.72023

    A Qualys web application was found to have a stored XSS vulnerability resulting from the absence of HTML encoding in the presentation of logging information to users. This vulnerability allowed a use…

  • CVE-2023-4777 ↗LOW 3.12023

    An incorrect permission check in Qualys Container Scanning Connector Plugin 1.6.2.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any …

  • CVE-2023-39154 ↗MEDIUM 6.52023

    Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using a…

  • CVE-2023-28143 ↗MEDIUM 6.72023

    Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) …

  • CVE-2023-28142 ↗MEDIUM 6.72023

    A Race Condition exists in the Qualys Cloud Agent for Windows platform in versions from 3.1.3.34 and before 4.5.3.1. This allows attackers to escalate privileges limited on the local machine during u…

  • CVE-2023-28141 ↗MEDIUM 6.72023

    An NTFS Junction condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.8.0.31. Attackers may write files to arbitrary locations via a local attack vector. This allows a…

  • CVE-2023-28140 ↗MEDIUM 6.72023

    An Executable Hijacking condition exists in the Qualys Cloud Agent for Windows platform in versions before 4.5.3.1. Attackers may load a malicious copy of a Dependency Link Library (DLL) via a local …

  • CVE-2022-29550 ↗MEDIUM 5.52022

    An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (fro…

  • CVE-2022-29549 ↗HIGH 7.32022

    An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full pathnames without first making ownership and permission checks (e.g., to help ensure that a program was ins…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Vulnerability Management products

see all →
  • A-LIGN Vulnerability Assessment Service · A-LIGN
  • AI EdgeLabs Vulnerability Detection · AI EdgeLabs
  • ASPIA Automated Vulnerability Management System · ASPIA Infotech Pvt. Ltd.
  • Absolute Resilience for Automation · Absolute
  • Action1 Free Initial Vulnerability Assessment · Action1
  • Action1 Patch Compliance Solutions · Action1
  • Action1 Vulnerability Management · Action1
  • Action1 Windows Patch Management · Action1