Vulnerability index

Browse CVEs

148 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32086

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in…

No fix yet
Fix from $2,300 2026-07-27
Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32088

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize …

No fix yet
Fix from $2,300 2026-07-27
Kace Systems Management Appliance HIGH 8.8
CVE-2021-32085

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL…

No fix yet
Fix from $1,950 2026-07-27
Kace Systems Management Appliance HIGH 8.8
CVE-2021-32087

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a…

Mitigation only
Fix from $1,950 2026-07-27
Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32084

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or…

No fix yet
Fix from $2,300 2026-07-27
Netvault Backup HIGH 8.8
CVE-2026-9780

Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authe…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9781

Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9782

Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9783

Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arb…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9784

Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9785

Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitr…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9786

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-9787

Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-7569

Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authe…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Netvault Backup HIGH 8.8
CVE-2026-7570

Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 14.0.2+
Fix from $1,950 2026-06-25
Kace Desktop Authority MEDIUM 5.3
CVE-2025-67813

Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication

Fix: 11.3.2+
Fix from $1,600 2026-01-12
Kace Systems Management Appliance CRITICAL 10.0
CVE-2025-32975 KEV

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5)…

Fix: 13.0.385 / 13.1.81+
Fix from $2,300 2025-06-24
Kace Systems Deployment Appliance MEDIUM 6.5
CVE-2023-33254

There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a high…

No fix yet
Fix from $1,600 2023-05-21
Kace Systems Management Appliance MEDIUM 6.1
CVE-2022-38220

An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script…

Fix: after 12.1
Fix from $1,600 2023-03-01
Kace Systems Management Appliance CRITICAL 9.8
CVE-2022-29807

A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via d…

Fix: 12.1.168+
Fix from $2,300 2022-08-02
Kace Systems Management Appliance CRITICAL 9.8
CVE-2022-30285

In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible during authentication. This may allow authentication with…

Fix: 12.1.168+
Fix from $2,300 2022-08-02
Kace Systems Management Appliance HIGH 7.5
CVE-2022-29808

In Quest KACE Systems Management Appliance (SMA) through 12.0, predictable token generation occurs when appliance linking is enabled.

Fix: 12.1.168+
Fix from $1,950 2022-08-02
Kace Desktop Authority CRITICAL 9.8
CVE-2021-44029

An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserializa…

Fix: 11.2+
Fix from $2,300 2021-12-22
Kace Desktop Authority CRITICAL 9.8
CVE-2021-44031

An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a…

Fix: 11.2+
Fix from $2,300 2021-12-22
Kace Desktop Authority MEDIUM 6.1
CVE-2021-44030

Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuer…

Fix: 11.2+
Fix from $1,600 2021-12-22
Kace Desktop Authority MEDIUM 5.5
CVE-2021-44028

XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue …

Fix: 11.2+
Fix from $1,600 2021-12-22
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35725

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35726

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35727

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications CRITICAL 9.8
CVE-2020-35205

Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and …

No fix yet
Fix from $2,300 2021-01-11