Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yogeshojha

First CVE: Aug 12, 2021Active for: 5 yearsTotal CVEs: 12
51.5
VTI Score
TOP TARGET

Yogeshojha maintains rengine, a reconnaissance and vulnerability-scanning platform widely adopted in security testing and bug-bounty workflows, where its vulnerability footprint centers on web-application attack surface issues. The vendor's disclosures skew toward serious outcomes and show a moderate tendency toward public exploit availability, with recurring weaknesses in input validation (cross-site scripting), OS command injection, access control, and sensitive-information exposure that are characteristic of tools bridging user-supplied reconnaissance data and system command execution. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yogeshojha over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 12, 2021
4 years ago
Most Recent CVE
Dec 11, 2025
226 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-50094HIGH
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The comma
Jan 1, 20248.841NOYES
CVE-2022-36566CRITICAL
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
Aug 31, 20229.832NONO
CVE-2022-28995CRITICAL
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
May 20, 20229.831NONO
CVE-2021-38606CRITICAL
reNgine through 0.5 relies on a predictable directory name.
Aug 12, 20219.831NONO
CVE-2024-58287HIGH
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. A
Dec 11, 20258.829NONO
CVE-2025-24968HIGH
reNgine is an automated reconnaissance framework for web applications. An unrestricted project deletion vulnerability allows attackers with specific roles, such as `penetration_tes
Feb 4, 20258.825NONO
CVE-2025-24962HIGH
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in
Feb 3, 20258.825NONO
CVE-2025-61319MEDIUM
ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. When scanning a target with an XSS payload, the unsanitized pay
Oct 10, 20256.122NONO
CVE-2025-24899HIGH
reNgine is an automated reconnaissance framework for web applications. A vulnerability was discovered in reNgine, where **an insider attacker with any role** (such as Auditor, Pene
Feb 3, 20257.521NONO
CVE-2025-24967MEDIUM
reNgine is an automated reconnaissance framework for web applications. A stored cross-site scripting (XSS) vulnerability exists in the admin panel's user management functionality.
Feb 4, 20255.417NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
33%
42%
25%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (66.7%)
Unknown0 (0.0%)
Required4 (33.3%)
Privileges Required
Low7 (58.3%)
High0 (0.0%)
None5 (41.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yogeshojha.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yogeshojha — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yogeshojha's Products

View all 3 CNAs →

Top CWEs