CVE-2026-105487
- EPSS 1.09%
- Veröffentlicht 06.10.2026 01:45:12
- Zuletzt bearbeitet 06.10.2026 13:16:45
A vulnerability was found in yogeshojha reNgine up to 2.2.0. Affected by this vulnerability is the function subdomain_discovery of the file web/reNgine/tasks.py of the component listTargets Endpoint. The manipulation of the argument Name results in o...
CVE-2026-92570
- EPSS 0.34%
- Veröffentlicht 16.09.2026 14:40:49
- Zuletzt bearbeitet 23.09.2026 17:17:49
reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can access files co...
CVE-2024-58287
- EPSS 3.47%
- Veröffentlicht 11.12.2025 21:33:35
- Zuletzt bearbeitet 20.01.2026 18:43:16
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encod...
CVE-2025-61319
- EPSS 0.27%
- Veröffentlicht 10.10.2025 00:00:00
- Zuletzt bearbeitet 16.01.2026 20:57:05
ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized payload is rendered in the ReNgine web UI, resulting in arbitrary JavaScr...
CVE-2025-24966
- EPSS 0.27%
- Veröffentlicht 04.02.2025 20:15:50
- Zuletzt bearbeitet 13.05.2025 18:46:23
reNgine is an automated reconnaissance framework for web applications. HTML Injection occurs when an application improperly validates or sanitizes user inputs, allowing attackers to inject arbitrary HTML code. In this scenario, the vulnerability exis...
CVE-2025-24967
- EPSS 0.28%
- Veröffentlicht 04.02.2025 20:15:50
- Zuletzt bearbeitet 13.05.2025 18:43:01
reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality. An attacker can exploit this issue by injecting malicious payloads int...
CVE-2025-24968
- EPSS 0.61%
- Veröffentlicht 04.02.2025 20:15:50
- Zuletzt bearbeitet 13.05.2025 18:39:25
reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tester` or `auditor` to delete all projects in the system. This can lead ...
CVE-2025-24962
- EPSS 0.72%
- Veröffentlicht 03.02.2025 21:15:16
- Zuletzt bearbeitet 13.05.2025 19:21:43
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in the next versioned release. User...
CVE-2025-24899
- EPSS 0.53%
- Veröffentlicht 03.02.2025 21:15:15
- Zuletzt bearbeitet 13.05.2025 19:23:48
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Penetration Tester, or Sys Admin) **can extract sensitive information from...
CVE-2024-43381
- EPSS 0.44%
- Veröffentlicht 16.08.2024 15:15:29
- Zuletzt bearbeitet 11.09.2024 13:02:26
reNgine is an automated reconnaissance framework for web applications. Versions 2.1.2 and prior are susceptible to Stored Cross-Site Scripting (XSS) attacks. This vulnerability occurs when scanning a domain, and if the target domain's DNS record cont...