Vulnerability index

Browse CVEs

67 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-32086 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in… Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2021-32088 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize … Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 HIGH 8.8 CVE-2021-32085 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL… Kace Systems Management Appliance No fix yet Fix from $1,9502026-07-27 HIGH 8.8 CVE-2021-32087 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a… Kace Systems Management Appliance Mitigation only Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2021-32084 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or… Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 MEDIUM 6.5 CVE-2023-33254 There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a high… Kace Systems Deployment Appliance No fix yet Fix from $1,6002023-05-21 MEDIUM 6.1 CVE-2020-35725 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 6.1 CVE-2020-35726 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 5.4 CVE-2020-35727 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 CRITICAL 9.8 CVE-2020-35205 Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and … Policy Authority For Unified Communications No fix yet Fix from $2,3002021-01-11 MEDIUM 6.5 CVE-2020-35722 CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafte… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 6.1 CVE-2020-35203 Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a … Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 6.1 CVE-2020-35204 Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to … Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 6.1 CVE-2020-35206 Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a … Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 6.1 CVE-2020-35719 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 5.4 CVE-2020-35720 Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon n… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 5.4 CVE-2020-35721 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 5.4 CVE-2020-35723 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 MEDIUM 5.4 CVE-2020-35724 Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t… Policy Authority For Unified Communications No fix yet Fix from $1,6002021-01-11 CRITICAL 9.8 CVE-2020-8868EPSS 9% This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not … Foglight Evolve Mitigation only Fix from $2,3002020-03-23 MEDIUM 5.4 CVE-2019-13081 Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.… Kace Systems Management Appliance Mitigation only Fix from $1,6002019-11-06 CRITICAL 9.8 CVE-2019-12918 Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and a… Kace Systems Management Appliance Mitigation only Fix from $2,3002019-11-06 HIGH 8.8 CVE-2019-13076 Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr… Kace Systems Management Appliance Mitigation only Fix from $1,9502019-11-06 HIGH 8.8 CVE-2019-13078 Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr… Kace Systems Management Appliance Mitigation only Fix from $1,9502019-11-06 HIGH 8.8 CVE-2019-13079 Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr… Kace Systems Management Appliance Mitigation only Fix from $1,9502019-11-06 MEDIUM 6.1 CVE-2019-12917 A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php compo… Kace Systems Management Appliance Mitigation only Fix from $1,6002019-11-06 MEDIUM 6.1 CVE-2019-13077 Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows… Kace Systems Management Appliance Mitigation only Fix from $1,6002019-11-06 MEDIUM 5.4 CVE-2019-13080 Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated … Kace Systems Management Appliance Mitigation only Fix from $1,6002019-11-06 CRITICAL 9.8 CVE-2018-11136 The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sani… Kace System Management Appliance No fix yet Fix from $2,3002018-05-31 CRITICAL 9.8 CVE-2018-11138 KEVEPSS 92% The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be a… Kace System Management Appliance Mitigation only Fix from $2,3002018-05-31