CVE-2025-67813
- EPSS 0.01%
- Veröffentlicht 12.01.2026 00:00:00
- Zuletzt bearbeitet 20.01.2026 18:33:24
Quest KACE Desktop Authority through 11.3.1 has Insecure Permissions on the Named Pipes used for inter-process communication
CVE-2021-44029
- EPSS 0.88%
- Veröffentlicht 22.12.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:14
An issue was discovered in Quest KACE Desktop Authority before 11.2. This vulnerability allows attackers to execute remote code through a deserialization exploitation in the RadAsyncUpload function of ASP.NET AJAX. An attacker can leverage this vulne...
CVE-2021-44030
- EPSS 0.37%
- Veröffentlicht 22.12.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:15
Quest KACE Desktop Authority before 11.2 allows XSS because it does not prevent untrusted HTML from reaching the jQuery.htmlPrefilter method of jQuery.
CVE-2021-44031
- EPSS 2.87%
- Veröffentlicht 22.12.2021 06:15:07
- Zuletzt bearbeitet 21.11.2024 06:30:15
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles/profileitems/outlooksettings/Insertimage.aspx contains a vulnerability that could allow pre-authentication remote code execution. An attacker could upload a ...
CVE-2021-44028
- EPSS 0.19%
- Veröffentlicht 22.12.2021 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:30:14
XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue to CVE-2018-1285.