Yogeshojha
Yogeshojha Rengine: vulnerabilidades y CVE
Yogeshojha Rengine tiene 13 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses3
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-105487 | Baja (2.1) | 1.1% | — | 6 oct 2026 | A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of… |
| CVE-2024-58287 | Alta (8.7) | 3.4% | — | 11 dic 2025 | reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd… |
| CVE-2025-61319 | Media (6.1) | 0.29% | — | 10 oct 2025 | ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI,… |
| CVE-2025-24968 | Alta (8.8) | 0.63% | — | 4 feb 2025 | reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to delete all… |
| CVE-2025-24967 | Alta (7.4) | 0.28% | — | 4 feb 2025 | reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exploit this issue by… |
| CVE-2025-24966 | Media (5.3) | 0.27% | — | 4 feb 2025 | reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject arbitrary HTML code. In this… |
| CVE-2025-24962 | Alta (8.7) | 0.74% | — | 3 feb 2025 | reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in… |
| CVE-2025-24899 | Alta (7.1) | 0.54% | — | 3 feb 2025 | reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester, or Sys Admin) **can… |
| CVE-2024-43381 | Media (5.4) | 0.44% | — | 16 ago 2024 | reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a domain, and if the… |
| CVE-2023-50094 | Alta (8.8) | 14% | — | 1 ene 2024 | reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via… |
| CVE-2022-36566 | Crítica (9.8) | 2.1% | — | 31 ago 2022 | Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function. |
| CVE-2022-28995 | Crítica (9.8) | 2.3% | — | 20 may 2022 | Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function. |
| CVE-2021-38606 | Crítica (9.8) | 1.2% | — | 12 ago 2021 | reNgine through 0.5 relies on a predictable directory name. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.