Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 1.1% | — | Yogeshojha RengineAI | 6/10/2026 | 6/10/2026 | A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in os command injection. The attack can be launched remotely. The exploit… | |
| Aplazada | Alta (7.1) | 0.44% | — | Reengine RengineAI | 16/9/2026 | 23/9/2026 | reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files containing third-party API keys for services like SecurityTrails,… | |
| Analizada | Alta (8.7) | 3.4% | — | Yogeshojha Rengine | 11/12/2025 | 17/6/2026 | reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine… | |
| Analizada | Media (6.1) | 0.29% | — | Yogeshojha Rengine | 10/10/2025 | 17/6/2026 | ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScript execution in the victim's browser. This can be abused to steal… | |
| Aplazada | Crítica (9.3) | 3.6% | — | BuilderengineAIElfinderAIJquery File UploadAI | 10/7/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php… | |
| Analizada | Alta (8.8) | 0.63% | — | Yogeshojha Rengine | 4/2/2025 | 17/6/2026 | reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to delete all projects in the system. This can lead to a complete system takeover by redirecting the attacker to the… | |
| Analizada | Alta (7.4) | 0.28% | — | Yogeshojha Rengine | 4/2/2025 | 17/6/2026 | reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exploit this issue by injecting malicious payloads into the username field during user creation. This vulnerability allows… | |
| Analizada | Media (5.3) | 0.27% | — | Yogeshojha Rengine | 4/2/2025 | 17/6/2026 | reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject arbitrary HTML code. In this scenario, the vulnerability exists in the "Add Target" functionality of the application, where the… | |
| Analizada | Alta (8.7) | 0.74% | — | Yogeshojha Rengine | 3/2/2025 | 17/6/2026 | reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in the next versioned release. Users are advised to filter user input and monitor the project for a new… | |
| Analizada | Alta (7.1) | 0.54% | — | Yogeshojha Rengine | 3/2/2025 | 17/6/2026 | reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester, or Sys Admin) **can extract sensitive information from other reNgine users.** After running a scan and obtaining… | |
| Analizada | Alta (8.4) | 0.35% | — | Inspur Clusterengine | 6/1/2025 | 17/6/2026 | An issue was discovered in Inspur ClusterEngine v4.0 that allows attackers to gain escalated Local privileges and execute arbitrary commands via /opt/tsce4/torque6/bin/getJobsByShell. | |
| Analizada | Media (5.4) | 0.44% | — | Yogeshojha Rengine | 16/8/2024 | 17/6/2026 | reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a domain, and if the target domain's DNS record contains an XSS payload, it leads to the execution of malicious scripts… | |
| Modificada | Alta (8.8) | 14% | — | Yogeshojha Rengine | 1/1/2024 | 17/6/2026 | reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output. | |
| Modificada | Crítica (9.8) | 2.1% | — | Yogeshojha Rengine | 31/8/2022 | 17/6/2026 | Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function. | |
| Modificada | Crítica (9.8) | 2.7% | — | Rengine Project Rengine | 22/5/2022 | 17/6/2026 | OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0. | |
| Modificada | Crítica (9.8) | 2.3% | — | Yogeshojha Rengine | 20/5/2022 | 17/6/2026 | Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function. | |
| Modificada | Media (5.4) | 0.49% | — | Rengine Project Rengine | 24/3/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine deletion confirmation modal box . . | |
| Modificada | Crítica (9.8) | 1.9% | — | Razorengine Project Razorengine | 6/3/2022 | 17/6/2026 | In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Crítica (9.8) | 1.2% | — | Yogeshojha Rengine | 12/8/2021 | 17/6/2026 | reNgine through 0.5 relies on a predictable directory name. | |
| Modificada | Crítica (9.8) | 39% | — | Inspur Clusterengine | 22/2/2021 | 17/6/2026 | A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server |