Skip to main content

Vendor archive

yogeshojha CVEs

Beta · best-effort

12 CVEs tagged to vendor yogeshojha3 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2024-58287

Published Dec 11, 2025

reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands.…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-61319

Published Oct 10, 2025

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized pa…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24968

Published Feb 4, 2025

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_te…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24967

Published Feb 4, 2025

reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality.…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24966

Published Feb 4, 2025

reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24962

Published Feb 3, 2025

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed i…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24899

Published Feb 3, 2025

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Pen…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-43381

Published Aug 16, 2024

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability oc…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50094

Published Jan 1, 2024

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The comm…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-36566

Published Aug 31, 2022

Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28995

Published May 20, 2022

Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1