Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Quest

First CVE: May 1, 2012Active for: 14 yearsTotal CVEs: 145
76.5
VTI Score
TOP TARGET

Quest develops a portfolio of systems-management and backup appliances widely deployed in enterprise environments, including disk-backup, NetVault Backup, and KACE systems-management platforms that handle privileged administrative functions and sensitive data. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value, often internet-exposed nature of administrative and backup infrastructure. The recurring weakness classes—including OS command injection, SQL injection, cross-site scripting, improper permission assignment, and input-validation flaws—are characteristic of appliance-oriented software where administrative interfaces and data-handling pipelines present broad attack surfaces. Defenders should treat Quest advisories as high-priority, inventory affected appliances carefully, and apply patches promptly to administrative and backup tiers; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
145
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
1.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Quest over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 1, 2012
14 years ago
Most Recent CVE
Jun 25, 2026
30 days ago

Products(17 total)

Top CVEs

Signals from CVEs in this vendor scope (145 CVEs).

145 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11138CRITICAL
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary comm
May 31, 20189.899YESYES
CVE-2012-5896HIGH
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not properly implement the Add method, which allows remote attackers
Nov 17, 201210.082NOYES
CVE-2025-32975CRITICAL
Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (P
Jun 24, 202510.075YESNO
CVE-2017-6553CRITICAL
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request
Apr 29, 20179.872NOYES
CVE-2018-1161CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.2.0.13. Authentication is not required to exploit this
Feb 8, 20189.865NONO
CVE-2017-17420CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this
Feb 8, 20189.853NONO
CVE-2018-11139HIGH
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any authenticated user and can be abused to execute arbit
May 31, 20188.849NONO
CVE-2018-11143CRITICAL
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).
Jun 2, 20189.848NONO
CVE-2017-17417CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this
Feb 8, 20189.846NOYES
CVE-2018-5406HIGH
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated,
Jun 3, 20198.843NOYES
View all 145 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products145 CVEs
20%
52%
28%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (2.8%)
Network138 (95.2%)
Unknown3 (2.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low142 (97.9%)
High0 (0.0%)
Unknown3 (2.1%)
User Interaction
None116 (80.0%)
Unknown3 (2.1%)
Required26 (17.9%)
Privileges Required
Low78 (53.8%)
High5 (3.4%)
None59 (40.7%)
Unknown3 (2.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (145 CVEs).

CISA KEV
2 CVEs
1.4% of CVEs· 99th percentile
Metasploit
3 CVEs
2.1% of CVEs· 97th percentile
Nuclei
3 CVEs
2.1% of CVEs· 95th percentile
ExploitDB
9 CVEs
6.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Quest.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Quest — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Quest's Products

View all 4 CNAs →

Top CWEs