Vulnerabilities > Yogeshojha > Rengine

DATE CVE VULNERABILITY TITLE RISK
2024-01-01 CVE-2023-50094 OS Command Injection vulnerability in Yogeshojha Rengine
reNgine through 2.0.2 allows OS Command Injection if an adversary has a valid session ID.
network
low complexity
yogeshojha CWE-78
8.8
2022-08-31 CVE-2022-36566 OS Command Injection vulnerability in Yogeshojha Rengine 1.3.0
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
network
low complexity
yogeshojha CWE-78
critical
9.8
2022-05-20 CVE-2022-28995 Unspecified vulnerability in Yogeshojha Rengine 1.0.2
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
network
low complexity
yogeshojha
critical
9.8
2021-08-12 CVE-2021-38606 Use of Insufficiently Random Values vulnerability in Yogeshojha Rengine
reNgine through 0.5 relies on a predictable directory name.
network
low complexity
yogeshojha CWE-330
critical
9.8