Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
Quest CVEs
15 high and critical vulnerabilities covered by CVE Brief since 2025-07-05, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
14 CVEs in the last 12 months
Products
- NetVault Backup10
- KACE Systems Deployment Appliance (SMA)3
- KACE Systems Management Appliance (SMA)1
- KACE Systems Management Appliance1
4 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability
Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability - Active in CISA KEV catalog.
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed...
Quest KACE Systems Deployment Appliance uses a hardcoded symmetric encryption key to protect secrets in MySQL databases, allowing unauthorized decrypt...
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL...
Quest KACE SMA 11.0.273 fails to enforce IP-based access restrictions on API endpoints, allowing bypass of console security.