Vulnerability index

Browse CVEs

67 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32086

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in…

No fix yet
Fix from $2,300 2026-07-27
Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32088

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize …

No fix yet
Fix from $2,300 2026-07-27
Kace Systems Management Appliance HIGH 8.8
CVE-2021-32085

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL…

No fix yet
Fix from $1,950 2026-07-27
Kace Systems Management Appliance HIGH 8.8
CVE-2021-32087

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a…

Mitigation only
Fix from $1,950 2026-07-27
Kace Systems Management Appliance CRITICAL 9.8
CVE-2021-32084

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or…

No fix yet
Fix from $2,300 2026-07-27
Kace Systems Deployment Appliance MEDIUM 6.5
CVE-2023-33254

There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a high…

No fix yet
Fix from $1,600 2023-05-21
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35725

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35726

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35727

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications CRITICAL 9.8
CVE-2020-35205

Server Side Request Forgery (SSRF) in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to scan internal ports and …

No fix yet
Fix from $2,300 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.5
CVE-2020-35722

CSRF in Web Compliance Manager in Quest Policy Authority 8.1.2.200 allows remote attackers to force user modification/creation via a specially crafte…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35203

Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a …

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35204

Reflected XSS in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a specially crafted link to …

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35206

Reflected XSS in Web Compliance Manager in Quest Policy Authority version 8.1.2.200 allows attackers to inject malicious code into the browser via a …

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 6.1
CVE-2020-35719

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35720

Stored XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to store malicious code in multiple fields (first name, last name, and logon n…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35721

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35723

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Policy Authority For Unified Communications MEDIUM 5.4
CVE-2020-35724

Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to t…

No fix yet
Fix from $1,600 2021-01-11
Foglight Evolve CRITICAL 9.8
CVE-2020-8868EPSS 9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0. Authentication is not …

Mitigation only
Fix from $2,300 2020-03-23
Kace Systems Management Appliance MEDIUM 5.4
CVE-2019-13081

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the title field in the /common/ticket_associated_tickets.…

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance CRITICAL 9.8
CVE-2019-12918

Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and a…

Mitigation only
Fix from $2,300 2019-11-06
Kace Systems Management Appliance HIGH 8.8
CVE-2019-13076

Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr…

Mitigation only
Fix from $1,950 2019-11-06
Kace Systems Management Appliance HIGH 8.8
CVE-2019-13078

Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr…

Mitigation only
Fix from $1,950 2019-11-06
Kace Systems Management Appliance HIGH 8.8
CVE-2019-13079

Quest KACE Systems Management Appliance Server Center 9.1.317 is vulnerable to SQL injection. An authenticated user has the ability to execute arbitr…

Mitigation only
Fix from $1,950 2019-11-06
Kace Systems Management Appliance MEDIUM 6.1
CVE-2019-12917

A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php compo…

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance MEDIUM 6.1
CVE-2019-13077

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via the sam_detail_titled.php SAM_TYPE parameter) that allows…

Mitigation only
Fix from $1,600 2019-11-06
Kace Systems Management Appliance MEDIUM 5.4
CVE-2019-13080

Quest KACE Systems Management Appliance Server Center 9.1.317 has an XSS vulnerability (via an SVG image and HTML file) that allows an authenticated …

Mitigation only
Fix from $1,600 2019-11-06
Kace System Management Appliance CRITICAL 9.8
CVE-2018-11136

The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sani…

No fix yet
Fix from $2,300 2018-05-31
Kace System Management Appliance CRITICAL 9.8
CVE-2018-11138 KEVEPSS 92%

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be a…

Mitigation only
Fix from $2,300 2018-05-31