Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rengine HIGH 8.8
CVE-2024-58287

reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers t…

No fix yet
Fix from $1,950 2025-12-11
Rengine MEDIUM 6.1
CVE-2025-61319

ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an X…

Fix: after 2.2.0
Fix from $1,600 2025-10-10
Rengine HIGH 8.8
CVE-2025-24968

reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific …

Fix: after 2.2.0
Fix from $1,950 2025-02-04
Rengine MEDIUM 5.4
CVE-2025-24966

reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes us…

Fix: after 2.2.0
Fix from $1,600 2025-02-04
Rengine MEDIUM 5.4
CVE-2025-24967

reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's …

Fix: after 2.2.0
Fix from $1,600 2025-02-04
Rengine HIGH 8.8
CVE-2025-24962

reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. T…

Patch available
Fix from $1,950 2025-02-03
Rengine HIGH 7.5
CVE-2025-24899

reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with an…

Fix: 2.2.0+
Fix from $1,950 2025-02-03
Rengine MEDIUM 5.4
CVE-2024-43381

reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) …

Fix: 2.1.3+
Fix from $1,600 2024-08-16
Rengine HIGH 8.8
CVE-2023-50094EPSS 14%

reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_d…

Fix: after 2.0.2
Fix from $1,950 2024-01-01
Rengine CRITICAL 9.8
CVE-2022-36566

Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.

No fix yet
Fix from $2,300 2022-08-31
Rengine CRITICAL 9.8
CVE-2022-28995

Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.

No fix yet
Fix from $2,300 2022-05-20
Rengine CRITICAL 9.8
CVE-2021-38606

reNgine through 0.5 relies on a predictable directory name.

Fix: after 0.5
Fix from $2,300 2021-08-12