Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities that can be detected with Pentest-Tools.com and the exploits that are currently available in the platform.

We detect more than 11.185 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 133 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 11.185

Pentest-Tools.com Vulnerabilities
Name
CVE
Detectable
with
Detection added
Severity
CVSSv3
score
Exploitable
with Sniper
Hotel Booking Lite < 4.8.5 - Arbitrary File Download & DeletionNetwork Scanner

High

9.8No
Embedded JavaScript(EJS) 3.1.6 - Template InjectionNetwork Scanner

High

9.8No
Gradio Applications - Local File ReadNetwork Scanner

High

7.5No
NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information DisclosureNetwork Scanner

Medium

5.3No
XWiki - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
mooSocial v.3.1.8 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
qdPM 9.2 - Directory TraversalNetwork Scanner

High

7.5No
Roxy Wi - Remote Code ExecutionNetwork Scanner

High

9.8Yes
Cybersecurity Infrastructure Security Agency (CISA)TeamCity - Authentication BypassNetwork Scanner

High

9.8Yes
Hoteldruid v3.0.5 - SQL InjectionNetwork Scanner

High

9.8No
Github Enterprise Authenticated Remote Code ExecutionNetwork Scanner

High

9.8No
Change Detection - Server Side Template InjectionNetwork Scanner

High

10No
User Meta WP Plugin < 3.1 - Sensitive Information ExposureNetwork Scanner

Medium

5.3No
CData API Server < 23.4.8844 - Path TraversalNetwork Scanner

High

9.8No
SOPlanning 1.52.00 Cross Site ScriptingNetwork Scanner

Medium

---No
Shield Security WP Plugin <= 18.5.9 - Local File InclusionNetwork Scanner

High

9.8No
Combo Blocks < 2.2.76 - Improper Access ControlNetwork Scanner

Medium

---No
CData Arc < 23.4.8839 - Path TraversalNetwork Scanner

High

8.6No
CData Sync < 23.4.8843 - Path TraversalNetwork Scanner

High

8.6No
Mura/Masa CMS - SQL InjectionNetwork Scanner

High

---No
mooSocial v.3.1.8 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCENetwork Scanner

High

9.8No
eyoucms v.1.6.5 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
WordPress Toolbar <= 2.2.6 - Open RedirectNetwork Scanner

Medium

6.1No
Avada < 7.11.7 - Information DisclosureNetwork Scanner

Medium

5.3No