- What is the Qualys CNA?
- Qualys is a CVE Numbering Authority (CNA) — an organization authorized to assign CVE IDs to vulnerabilities in its scope. It has published 10 CVE records since 2023.
- How many CVEs has Qualys published?
- Qualys has published 10 CVE records, including 1 in the last two years.
- What is Qualys's CVE data quality grade?
- RadicalNotion.AI grades Qualys's CVE data quality as A, with an overall completeness score of 100%. This reflects how consistently its CVE records include vendor (100%), product (100%), CVSS (100%), and CWE (100%) information.
- What products does Qualys publish CVEs for?
- Qualys most frequently publishes CVEs for Cloud Agent, com.qualys.plugins:qualys-pc, Policy Compliance Connector Jenkins Plugin, policy compliance, Container Scanning Connector Jenkins Plugin.
- Which vendors does Qualys cover?
- Qualys publishes CVEs across 4 distinct vendors, most often Qualys,Inc., Jenkins, apple.
- Is Qualys actively publishing CVEs?
- Qualys is currently active, based on 1 CVEs in the last two years.
- What is the average severity of Qualys's CVEs?
- The average CVSS base score across Qualys's scored CVEs is 5.9.
- Are any of Qualys's CVEs in CISA's Known Exploited Vulnerabilities catalog?
- No. None of Qualys's CVEs are currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
- What are the most common weakness types in Qualys's CVEs?
- Qualys's CVEs most often map to these CWE weakness types: CWE-611 (Improper Restriction of XML External Entity Reference), CWE-426 (Untrusted Search Path), CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-732 (Incorrect Permission Assignment for Critical Resource).
- How does Qualys rank among CNAs?
- By total CVE volume, Qualys ranks #305 of 370 CNAs, and it reports more complete CVE records than 60% of all CNAs.