Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 8 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

rConfig < 8.2.13 Path Traversal File Read via FileDownloadController

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../ sequences to escape the exports base directory and access sensitive files readable by the web server process, including application environment files containing encryption keys, database credentials, and mail configuration

CWE-22Aug 12, 2026
CVSS7.1v4.0EPSS0.373%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig Core < 8.2.8 Privilege Escalation via Users API role field

rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the missing allowlist validation and absent admin-level authorization check in StoreUserRequest to mass-assign the Admin role directly to the User model, granting access to privileged features. rConfig Pro and Enterprise are not a

CWE-915Jul 20, 2026
CVSS5.3v4.0EPSS0.246%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig rConfig Improper Privilege Management

lib/crud/userprocess.php in rConfig 3.9.x before 3.9.7 has an authentication bypass, leading to administrator account creation. This issue has been fixed in 3.9.7.

CWE-269CWE-287Nov 13, 20201 related artifact
CVSS9.8v3.1EPSS76.6%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

rConfig 3.9.4 and previous versions has unauthenticated compliancepolicies.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CWE-89Jun 4, 20201 related artifact
CVSS9.8v3.1EPSS87.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

rConfig 3.9.4 and previous versions has unauthenticated devices.inc.php SQL injection. Because, by default, nodes' passwords are stored in cleartext, this vulnerability leads to lateral movement, granting an attacker access to monitored network devices.

CWE-89Jun 4, 20201 related artifact
CVSS9.8v3.1EPSS37.3%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

rConfig OS Command Injection Vulnerability

lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.

CWE-78Mar 8, 2020
CVSS8.8v3.1EPSS36.8%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function without filtering, which can lead to command execution.

CWE-78Jan 6, 2020
CVSS8.8v3.1EPSS71.6%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

rConfig rConfig Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filtering, which can lead to command execution.

CWE-78Oct 28, 20191 related artifact
CVSS9.8v3.1EPSS97.7%PoCs4SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX