Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.4
CVE-2020-12256EPSS 96%
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbi…
Rconfig
No fix yet
CRITICAL 9.1
CVE-2020-12258
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPS…
Rconfig
Mitigation only
HIGH 8.8
CVE-2020-12257
rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker…
Rconfig
No fix yet
MEDIUM 5.4
CVE-2020-12259EPSS 96%
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability b…
Rconfig
Mitigation only
CRITICAL 9.8
CVE-2020-10879EPSS 84%
rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed direc…
Rconfig
3.9.5+
HIGH 7.5
CVE-2020-9425EPSS 19%
An issue was discovered in includes/head.inc.php in rConfig before 3.9.4. An unauthenticated attacker can retrieve saved cleartext credentials via a …
Rconfig
3.9.4+
HIGH 8.8
CVE-2020-10221 KEVEPSS 37%
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the…
Rconfig
after 3.9.4
CRITICAL 9.8
CVE-2020-10220EPSS 100%
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter.
Rconfig
after 3.9.4
HIGH 8.8
CVE-2019-19509EPSS 72%
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFil…
Rconfig
No fix yet
HIGH 7.8
CVE-2019-19585EPSS 6%
An issue was discovered in rConfig 3.9.3. The install script updates the /etc/sudoers file for rconfig specific tasks. After an "rConfig specific Apa…
Rconfig
No fix yet
HIGH 7.5
CVE-2019-19372
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potent…
Rconfig
after 3.9.3
HIGH 8.8
CVE-2019-19207EPSS 23%
rConfig 3.9.2 allows devices.php?searchColumn= SQL injection.
Rconfig
No fix yet
CRITICAL 9.8
CVE-2019-16662EPSS 98%
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php beca…
Rconfig
No fix yet
HIGH 8.8
CVE-2019-16663EPSS 85%
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the ca…
Rconfig
No fix yet