Known vulnerabilities in Qlik Sense Enterprise for Windows

Software CPE: cpe:2.3:a:qlik:qlik_sense_enterprise_for_windows:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 3
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Qlik Sense Enterprise for Windows Qlik Sense Enterprise for Windows is affected by 8 known vulnerabilities: 6 high, 2 medium Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113173 - Use of Insufficiently Random Values
CVE-2025-7783
CWE-330 Medium
Available
No
May 2025 Patch 6, November 2024 Patch 18, May 2024 Patch 24 23.07.2025 SB2025072332
SB2025072333
SB2025081876
and 62 more
#VU111081 - Improper Access Control
CVE-2024-55580
CWE-284 High
No
No
August 2023 Patch 16, November 2024, May 2024 Patch 10, February 2024 Patch 14, February 2023 Patch 15, November 2023 Patch 16, May 2023 Patch 18 11.06.2025 SB2025061178
#VU111080 - Permissions, Privileges, and Access Controls
CVE-2024-55579
CWE-264 High
No
No
August 2023 Patch 16, November 2024, May 2024 Patch 10, February 2024 Patch 14, February 2023 Patch 15, November 2023 Patch 16, May 2023 Patch 18 11.06.2025 SB2025061178
#VU83603 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-48365
CWE-444 High
No
Exploited
August 2022 Patch 14, August 2023 Patch 2, May 2023 Patch 6, February 2023 Patch 10, November 2022 Patch 12, February 2022 Patch 15, May 2022 Patch 16, November 2021 Patch 17 30.11.2023 SB2023113053
#VU80323 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2023-26136
CWE-1321 High
No
No
May 2025 Patch 6, November 2024 Patch 18, May 2024 Patch 24 04.09.2023 SB2023090411
SB2023090423
SB2023090816
and 42 more
#VU80196 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-41266
CWE-22 High
Available
Exploited
August 2022 Patch 13, August 2023, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11 31.08.2023 SB2023083126
#VU80193 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-41265
CWE-444 High
Available
Exploited
August 2022 Patch 13, August 2023, May 2023 Patch 4, February 2023 Patch 8, November 2022 Patch 11 31.08.2023 SB2023083126
#VU60748 - Exposure of sensitive information to an unauthorized actor
CVE-2022-0564
CWE-200 Medium
No
No
14.44.0 22.02.2022 SB2022022204