Vulnerability index

Browse CVEs

148 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Policy Authority For Unified Communications MEDIUM 6.5
CVE-2020-35722

CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafte…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35203

Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a …

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35204

Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to …

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35206

Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a …

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35719

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35720

Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon n…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35721

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35723

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35724

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Foglight Evolve CRITICAL 9.8
CVE-2020-8868EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not …

Mitigation only
Fix from $2,300 2020-03-23
Kace Systems Management CRITICAL 9.8
CVE-2019-20504EPSS 10%

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell …

Fix: 6.4.120822+
Fix from $2,300 2020-03-09
Kace Systems Management Appliance MEDIUM 5.4
CVE-2019-13081

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.…

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance CRITICAL 9.8
CVE-2019-12918

Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and a…

Mitigation only
Fix from $2,300 2019-11-06
Kace Systems Management Appliance HIGH 8.8
CVE-2019-13076

Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr…

Mitigation only
Fix from $1,950 2019-11-06
Kace Systems Management Appliance HIGH 8.8
CVE-2019-13078

Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr…

Mitigation only
Fix from $1,950 2019-11-06
Kace Systems Management Appliance HIGH 8.8
CVE-2019-13079

Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr…

Mitigation only
Fix from $1,950 2019-11-06
Kace Systems Management Appliance MEDIUM 6.1
CVE-2019-12917

A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php compo…

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance MEDIUM 6.1
CVE-2019-13077

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows…

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance MEDIUM 5.4
CVE-2019-13080

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated …

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance HIGH 7.2
CVE-2019-10973

Quest KACE, all versions prior to version 8.0.x, 8.1.x, and 9.0.x, allows unintentional access to the appliance leveraging functions of the troublesh…

Fix: after 9.0.270
Fix from $1,950 2019-07-08
Kace Systems Management Appliance Firmware HIGH 8.8
CVE-2018-5406EPSS 12%

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS)…

Fix: 9.0.270+
Fix from $1,950 2019-06-03
Kace Systems Management Appliance Firmware MEDIUM 6.5
CVE-2018-5404

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) …

Fix: 9.0.270+
Fix from $1,600 2019-06-03
Kace Systems Management Appliance Firmware MEDIUM 5.4
CVE-2018-5405

The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated least privileged user with 'User Console Only' rights to potential…

Fix: 9.0.270+
Fix from $1,600 2019-06-03
Kace Systems Management Appliance MEDIUM 6.1
CVE-2019-11604

An issue was discovered in Quest KACE Systems Management Appliance before 9.1. The script at /service/kbot_service_notsoap.php is vulnerable to unaut…

Fix: 9.1+
Fix from $1,600 2019-05-24
Disk Backup HIGH 8.8
CVE-2018-11175

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11176

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 34 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11177

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 35 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11178

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 36 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11179

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 37 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02
Disk Backup HIGH 8.8
CVE-2018-11180

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 38 of 46).

Fix: 4.0.3.1+
Fix from $1,950 2018-06-02