Vulnerabilities
175 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-32084 | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2026-9787 | Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault Backup. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of NVBULogDaemon JSON-RPC messages. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27625. NVD description · AI analysis pending | 8.8 | 5% |
| — | ||
| CVE-2025-60865 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service wi Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2025-67813 | Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2025-56689 | One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass One Identity by Quest Safeguard for Privileged Passwords Appliance 7.5.1.20903 is vulnerable to One Time Password (OTP)/Multifactor Authentication (MFA) bypass using response manipulation. An attacker who intercepts or captures a valid OTP response can bypass the OTP verification step by replaying the same response. NOTE: this is disputed by the Supplier because, by design, the product successfully authenticates a client that possesses a cookie whose validity time interval includes the current time, and thus authentication after any type of "interception" is not a violation of the security model. (The cookie has the HttpOnly attribute.) NVD description · AI analysis pending | 4.6 | 1% | PoC |
| — | |
| CVE-2025-32975 | Authentication Bypass in Quest KACE Systems Management Appliance (SSO) Quest KACE Systems Management Appliance (SMA) versions in the 13.0.x through 14.1.x branches, prior to the fixed builds, contain an improper authentication flaw (CWE-287) in the SSO authentication handling mechanism. Because the bypass requires no valid credentials, privileges, or user interaction and is reachable over the network, an attacker who can reach the appliance can impersonate legitimate users and achieve complete administrative takeover. Any organization running an affected SMA build is exposed, particularly where the appliance's web interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-04-20, and press reporting describes attackers hijacking unpatched SMA systems, with compromises at roughly 60 organizations cited; ransomware use is not yet confirmed. Do: Upgrade affected SMA deployments to the fixed build for their branch — 13.0.385, 13.1.81, 13.2.183, 14.0.341 (Patch 5), or 14.1.101 (Patch 4) or later — prioritizing internet-facing appliances. Since the flaw is actively exploited and grants full admin takeover, review appliance logs and administrator accounts for signs of compromise (unexpected SSO sessions, new or altered accounts) and restrict access to the SMA web interface to trusted networks per Quest's guidance. U.S. federal agencies must apply the required mitigations or discontinue use under BOD 22-01 by the KEV deadline. | 10.0 | 2% | KEV |
| largetens of thousands of deployed SMA appliances worldwide, with likely only a low-thousands subset internet-exposed | |
| CVE-2024-13492 | The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cro The Guten Free Options WordPress plugin through 0.9.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-48118 | SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc W SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to execute arbitrary code via a crafted request to the Common.svc WSDL page. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2024-21625 | SideQuest is a place to get virtual reality applications for Oculus Quest. SideQuest is a place to get virtual reality applications for Oculus Quest. The SideQuest desktop application uses deep links with a custom protocol (`sidequest://`) to trigger actions in the application from its web contents. Because, prior to version 0.10.35, the deep link URLs were not sanitized properly in all cases, a one-click remote code execution can be achieved in cases when a device is connected, the user is presented with a malicious link and clicks it from within the application. As of version 0.10.35, the custom protocol links within the electron application are now being parsed and sanitized properly. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2020-26708 | requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafte requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2023-33254 | There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. There is an LDAP bind credentials exposure on KACE Systems Deployment and Remote Site appliances 9.0.146. The captured credentials may provide a higher privilege level on the Active Directory domain. To exploit this, an authenticated attacker edits the user-authentication settings to specify an attacker-controlled LDAP server, clicks the Test Settings button, and captures the cleartext credentials. NVD description · AI analysis pending | 6.5 | 3% | PoC |
| — | |
| CVE-2022-30350 | Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2023-1666 | A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. A vulnerability has been found in SourceCodester Automatic Question Paper Generator System 1.0 and classified as critical. This vulnerability affects unknown code of the file users/classes/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-224104. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-1592 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file admin/courses/view_class.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The identifier of this vulnerability is VDB-223660. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2023-1474 | A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223336. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-28155 | The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP t The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2022-38220 | An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML. An XSS vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.1 that may allow remote injection of arbitrary web script or HTML. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-29807 | A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_age A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through 12.0 that can allow for remote code execution via download_agent_installer.php. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2022-31555 | The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. NVD description · AI analysis pending | 9.3 | 1% | PoC |
| — | |
| CVE-2022-26631 | Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. Automatic Question Paper Generator v1.0 contains a Time-Based Blind SQL injection vulnerability via the id GET parameter. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2022-1073 +1 in the same advisory: …1076 | A vulnerability was found in Automatic Question Paper Generator 1.0. A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2022-0654 | Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0. Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2021-44031 | An issue was discovered in Quest KACE Desktop Authority before 11.2. An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a .ASP file to reside at /images/{GUID}/{filename}. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2021-31597 | The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected. NVD description · AI analysis pending | 9.4 | 2% | PoC |
| — | |
| CVE-2020-35308 | CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code. CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2020-28502 | This affects the package xmlhttprequest before 1.7.0; This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run. NVD description · AI analysis pending | 8.1 | 5% | PoC ×4 |
| — | |
| CVE-2020-35727 | Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDi Reflected XSS in Quest Policy Authority 8.1.2.200 allows remote attackers to inject malicious code into the browser via a specially crafted link to the BrowseDirs.do file via the title parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer NVD description · AI analysis pending | 5.4 | 1% | PoC ×2 |
| — |