Quest Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Quest products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

4

In CISA KEV

2

Beyond CISA KEV

2

Sensor Observed

0

Virtual Patch Available

0

Quest KEVs Added by Year

Loading...

4 Quest KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-32975

Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch...

Confirmed In CISA 01 Jun 2026
CVE-2018-11138

The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be...

Confirmed In CISA 25 Mar 2022
CVE-2023-27163

request-baskets up to v1.2.1 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /api/baskets/{name}. This...

High Not in CISA 31 Mar 2023
CVE-2019-20504

service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via...

High Not in CISA 09 Mar 2020

Common Vulnerability Classes (CWE)

  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-287 — Improper Authentication 1
  • CWE-918 — Server-Side Request Forgery (SSRF) 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology