Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 7 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

rConfig < 8.2.13 Path Traversal File Read via FileDownloadController

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../ sequences to escape the exports base directory and access sensitive files readable by the web server process, including application environment files containing encryption keys, database credentials, and mail configuration

CWE-22Aug 12, 2026
CVSS7.1v4.0EPSS0.373%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig rConfig Improper Privilege Management

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

CWE-269CWE-287Nov 13, 20201 related artifact
CVSS9.8v3.1EPSS76.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CWE-89Jun 4, 20201 related artifact
CVSS9.8v3.1EPSS87.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CWE-89Jun 4, 20201 related artifact
CVSS9.8v3.1EPSS37.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

rConfig OS Command Injection Vulnerability

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

CWE-78Mar 8, 2020
CVSS8.8v3.1EPSS36.8%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.

CWE-78Jan 6, 2020
CVSS8.8v3.1EPSS71.6%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

CWE-78Oct 28, 20191 related artifact
CVSS9.8v3.1EPSS97.7%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX