« Volver al listado

Yogeshojha

Yogeshojha Rengine: vulnerabilidades y CVE

Yogeshojha Rengine tiene 13 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses3
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-105487Baja (2.1)1.1%—6 oct 2026
A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of…
CVE-2024-58287Alta (8.7)3.4%—11 dic 2025
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd…
CVE-2025-61319Media (6.1)0.29%—10 oct 2025
ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI,…
CVE-2025-24968Alta (8.8)0.63%—4 feb 2025
reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to delete all…
CVE-2025-24967Alta (7.4)0.28%—4 feb 2025
reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exploit this issue by…
CVE-2025-24966Media (5.3)0.27%—4 feb 2025
reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject arbitrary HTML code. In this…
CVE-2025-24962Alta (8.7)0.74%—3 feb 2025
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in…
CVE-2025-24899Alta (7.1)0.54%—3 feb 2025
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester, or Sys Admin) **can…
CVE-2024-43381Media (5.4)0.44%—16 ago 2024
reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a domain, and if the…
CVE-2023-50094Alta (8.8)14%—1 ene 2024
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via…
CVE-2022-36566Crítica (9.8)2.1%—31 ago 2022
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
CVE-2022-28995Crítica (9.8)2.3%—20 may 2022
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
CVE-2021-38606Crítica (9.8)1.2%—12 ago 2021
reNgine through 0.5 relies on a predictable directory name.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1059 Command and Scripting Interpreter3
  3. T1005 Data from Local System1
  4. T1059.007 JavaScript1
  5. T1190 Exploit Public-Facing Application1
  6. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.