Quest records
152 published records for vendor quest.
Researcher profile
- Entered KEV
- 2 · 1.3%
- Weaponized
- 4 · 2.6%
- Pre-auth RCE
- 33
- With a fix record
- 0%
- Median publish → KEV
- 847 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')52
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')38
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')22
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')6
- CWE-732 Incorrect Permission Assignment for Critical Resource4
- CWE-798 Use of Hard-coded Credentials3
The weakness classes this vendor ships most often: where to look.
CWEAll records
152 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2018-11138Weaponized | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users andquest · kace system management appliance · CWE-78 | Critical9.8 | KEV | 91.8% | May 31, 2018 |
71This week | CVE-2025-32975Weaponized | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 quest · kace systems management appliance · CWE-287 | Critical10.0 | KEV | 2.5% | Jun 24, 2025 |
61This week | CVE-2012-5896Weaponized | The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Adquest · intrust | Critical10.0 | — | 69.4% | Nov 17, 2012 |
59Plan | CVE-2018-1161No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13.quest · netvault backup · CWE-121 | Critical9.8 | — | 66.7% | Feb 8, 2018 |
53Plan | CVE-2017-17420No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 48.2% | Feb 8, 2018 |
52Plan | CVE-2017-6553Weaponized | Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policquest · privilege manager for unix · CWE-119 | Critical9.8 | — | 42.3% | Apr 29, 2017 |
50Plan | CVE-2018-11143No exploit | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).quest · disk backup · CWE-78 | Critical9.8 | — | 37.2% | Jun 1, 2018 |
48Plan | CVE-2018-11139No exploit | The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticatedquest · kace system management appliance · CWE-78 | High8.8 | — | 42.9% | May 31, 2018 |
44Plan | CVE-2018-1163No exploit | This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13.quest · netvault backup · CWE-287 | Critical9.8 | — | 16.0% | Feb 8, 2018 |
42Plan | CVE-2017-17417Proof of concept | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 9.8% | Feb 8, 2018 |
42Plan | CVE-2019-20504Proof of concept | service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code vquest · kace systems management · CWE-78 | Critical9.8 | — | 9.6% | Mar 8, 2020 |
42Plan | CVE-2020-8868No exploit | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0.quest · foglight evolve · CWE-798 | Critical9.8 | — | 9.5% | Mar 23, 2020 |
40Plan | CVE-2018-11132No exploit | In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue thaquest · kace system management appliance · CWE-78 | High8.8 | — | 18.3% | May 31, 2018 |
40Plan | CVE-2017-17422No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17421No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17414No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17419No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17413No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17659No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17656No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17655No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17418No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17657No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17658No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
40Plan | CVE-2017-17654No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.quest · netvault backup · CWE-89 | Critical9.8 | — | 3.9% | Feb 8, 2018 |
- CVE-2018-1113897Now
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and
CriticalCVSS 9.8KEVWeaponizedEPSS 92%quest · kace system management applianceMay 31, 2018
- CVE-2025-3297571This week
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341
CriticalCVSS 10.0KEVWeaponizedEPSS 2%quest · kace systems management applianceJun 24, 2025
- CVE-2012-589661This week
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Ad
CriticalCVSS 10.0WeaponizedEPSS 69%quest · intrustNov 17, 2012
- CVE-2018-116159Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13.
CriticalCVSS 9.8No exploitEPSS 67%quest · netvault backupFeb 8, 2018
- CVE-2017-1742053Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 48%quest · netvault backupFeb 8, 2018
- CVE-2017-655352Plan
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the polic
CriticalCVSS 9.8WeaponizedEPSS 42%quest · privilege manager for unixApr 29, 2017
- CVE-2018-1114350Plan
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).
CriticalCVSS 9.8No exploitEPSS 37%quest · disk backupJun 1, 2018
- CVE-2018-1113948Plan
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated
HighCVSS 8.8No exploitEPSS 43%quest · kace system management applianceMay 31, 2018
- CVE-2018-116344Plan
This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13.
CriticalCVSS 9.8No exploitEPSS 16%quest · netvault backupFeb 8, 2018
- CVE-2017-1741742Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8Proof of conceptEPSS 10%quest · netvault backupFeb 8, 2018
- CVE-2019-2050442Plan
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code v
CriticalCVSS 9.8Proof of conceptEPSS 10%quest · kace systems managementMar 8, 2020
- CVE-2020-886842Plan
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest Foglight Evolve 9.0.0.
CriticalCVSS 9.8No exploitEPSS 9%quest · foglight evolveMar 23, 2020
- CVE-2018-1113240Plan
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue tha
HighCVSS 8.8No exploitEPSS 18%quest · kace system management applianceMay 31, 2018
- CVE-2017-1742240Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1742140Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1741440Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1741940Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1741340Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1765940Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1765640Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1765540Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1741840Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1765740Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1765840Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018
- CVE-2017-1765440Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12.
CriticalCVSS 9.8No exploitEPSS 4%quest · netvault backupFeb 8, 2018