Home/Product/yogeshojha rengine
Product

yogeshojha rengine

14 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-58287
all versions
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authen
8.8HIGH
CVE-2025-61319
<= 2.2.0
ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning
6.1MEDIUM
CVE-2025-24968
<= 2.2.0
reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attac
8.8HIGH
CVE-2025-24967
<= 2.2.0
reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in
5.4MEDIUM
CVE-2025-24966
<= 2.2.0
reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly valida
5.4MEDIUM
CVE-2025-24962
all versions
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nma
8.8HIGH
CVE-2025-24899
< 2.2.0
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where an insid
7.5HIGH
CVE-2024-43381
< 2.1.3
reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Si
5.0MEDIUM
CVE-2023-50094
<= 2.0.2
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in
8.8HIGH
CVE-2022-36566
all versions
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
9.8CRITICAL
CVE-2022-1813
< 1.2.0
OS Command Injection in GitHub repository yogeshojha/rengine prior to 1.2.0.
9.8CRITICAL
CVE-2022-28995
all versions
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
9.8CRITICAL
CVE-2021-39491
< 1.0.1
A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan Engine del
5.4MEDIUM
CVE-2021-38606
<= 0.5
reNgine through 0.5 relies on a predictable directory name.
9.8CRITICAL
threatengine.sh