Quest Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Quest products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
4
In CISA KEV
2
Beyond CISA KEV
2
Sensor Observed
0
Virtual Patch Available
0
Quest KEVs Added by Year
4 Quest KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-32975
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch... |
KACE Systems Management Appliance | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-11138
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be... |
KACE System Management Appliance | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2023-27163
request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This... |
request-baskets | High | Not in CISA | 31 Mar 2023 |
|
CVE-2019-20504
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via... |
KACE K1000 Systems Management Appliance | High | Not in CISA | 09 Mar 2020 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-287 — Improper Authentication 1
- CWE-918 — Server-Side Request Forgery (SSRF) 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology