Fresh scan results for your toolkit
Copy link to “Fresh scan results for your toolkit”The scan results facelift continues! We’ve recently rolled out visual updates for:
Port Scanner
Subdomain Finder
Domain Finder
URL Fuzzer
Virtual Hosts Finder

These are the latest updates we've made to our platform. If you have any questions about any of the updates you see below, please feel free to contact us!
The scan results facelift continues! We’ve recently rolled out visual updates for:
Port Scanner
Subdomain Finder
Domain Finder
URL Fuzzer
Virtual Hosts Finder

Our proprietary Website Vulnerability Scanner just got more powerful with these November updates:
Validate with SQLi Exploiter button: Found an SQL Injection vulnerability? Validate it instantly in one click! Our SQLi Exploiter auto-fills details like HTTP methods, POST data, and test parameters.

Insecure deserialization detection for Python-based applications in the scanner’s Active module. (‘Nough said!)
Subdomain whitelisting for broader scan coverage. By default, we’re whitelisting "api", but you can customize your subdomain scanning under the Custom scan settings for even more control.

You now have access to scheduled scans so it’s even easier to maintain regular monitoring routines.
Here’s how it works:
Set your preferred scans to run automatically on a weekly or monthly basis.
Set up scan diff email alerts to know when something changes.
![[New in free] Monitor your targets for new vulnerabilities with Pentest-Tools.com](/_vercel/image?url=https:%2F%2Fcontent.pentest-tools.com%2Fassets%2Fcontent%2Fmonitor---free.png&w=1536&q=100)
Chaining our tools for more and better findings is our ultimate goal.
That’s why when the Network Vulnerability Scanner detects a login interface, you’ll now see a Scan with Password Auditor button.
Click it and the scanner automatically fills in fields like target, ports, and service for faster weak credentials detection.

Not one month passes without adding new proof of exploitation to our proprietary offensive tool — Sniper: Auto-Exploiter.
The tool can now exploit Authentication Bypass and Remote Code Execution vulnerabilities in Palo Alto Networks Expedition:
CVE-2024-0012 and CVE-2024-9474 (CVSSv3 9.8) - allow a remote attacker to bypass the authentication mechanism and compromise your internal network.
Prove exploitation easily and integrate this update into your offensive workflows.
You asked, we listened! The Joomla Scanner is now part of our API, ready to use directly from your scripts.
The "How to reproduce" section in the Cloud Scanner findings now includes the AWS command so you can easily validate your results.
First we introduced the scan diff notification, so you can easily track changes in your targets’ security posture.
Now, we’ve made it even easier for you to set a complete monitoring flow for our Network & Website Vulnerability Scanners, Port Scanner, and Subdomain Finder.
You just select your target(s) and follow the Monitor setup process. It’s that simple!
You’ll automatically get email alerts whenever there’s an update.

There’s a new cloud integration in your Pentest-Tools.com toolkit!
Now you can easily import AWS targets to your account with a fast setup.

Our Network Scanner is constantly expanding its reach so you get the most from your precision network scans.
Detect these freshly added high-impact RCEs:
CVE-2024-47177 (CVSSv3 9) — RCE in CUPS, a standards-based, open-source printing system.
CVE-2024-28986 (CVSSv3 9.8) — RCE in SolarWinds Web Help Desk that allows an attacker to run commands on the host machine

misconfigured DNS (because it's always DNS!) SPF, DNS DMARC, and DNS DKIM records
a DNS Zone Transfer vulnerability
Also, know what step your scan is at with real-time updates in the Network Scanner’s scan logs.
Our team also updated the Website Scanner's capabilities this past month so you have a more comprehensive view of your targets.
You can:
detect insecure deserialization in PHP applications with the scanner’s Active module
automatically detect GraphQL as we’ve integrated our API Vulnerability Scanner’s test methods for this language

The Website Scanner now:
creates a new finding with all the API endpoints it detects during crawling
fuzzes for Open API specifications, creates a new finding with any identified results, and even adds it into the Specification Spider
adds exposures and exposed-panels Nuclei templates to the Interesting files finding so you detect even more publicly accessible pages that should’ve been hidden.

Our proprietary offensive tool, Sniper: Auto Exploiter, has a wide range of available exploits — but we want to make it even more up to date.
Use Sniper to extract the proof of exploitation for a critical Palo Alto Networks Expedition RCE (CVE-2024-9463, CVSSv3 9.8) that can allow an unauthenticated attacker to inject an OS Command using special characters and fully compromise your server.
With the Cloud Vulnerability Scanner, you can assess targets across multi-cloud environments like AWS, GCP, or Azure from both within and the outside.
There’s a fresh finding for it, too!
Use our Cloud Scanner to detect the risk of data leaks because of a misconfiguration in your AWS bucket that gives a potential attacker public access to list your multipart uploads.
Our Subdomain Finder also has a new update to make your scan results more accurate.
The tool now translates key entries from the Enumeration wordlist for languages from the top level domain (TLD) through the FindSubdomains alteration test.
There’s a fresh, new Reports section in Pentest-Tools.com for you to manage and download scan results, findings, and custom reports — all in one place.
.png&w=1536&q=50)
Asynchronous report generation, so you don’t have to worry about getting stuck on the same screen while waiting for your files. Not even for larger ones. You’ll get an in-app alert as soon as the report is ready.
30 days storage for all your reports. No need to regenerate or search for a specific report, we make sure they’re all in their right place.
See how you can leverage the power of automation to streamline your client reports in this hands-on demo:

There’s a new module in the active capabilities of our proprietary Website Scanner: detection for insecure deserialization in .Net applications.
To make XSS and SQLi findings easier to navigate, we’ve also added a highlight directly in the request/response line containing the payload used in that detection.
We’ve made Findings management even smoother so you don’t waste time on menial tasks. Now you can clone Findings in bulk with just a press of the button! Quick and easy.
.png&w=1536&q=50)
Detect these 2 high-risk CVEs with our powerful Network Vulnerability Scanner:
CVE-2024-5932 (CVSSv3 10) - this GiveWP Donation Plugin RCE can allow unauthenticated attackers to inject a PHP Object, gain full access, and compromise your server.
CVE-2023-43770 (CVSSv3 6.1) - this RoundCube Cross-Site Scripting vulnerability can lead to data theft, session hijacking, or defacement of the affected application.
Get proof of exploitation for these 5 critical CVEs with our proprietary offensive tool, Sniper - Auto-Exploiter:
CVE-2024-29973 (CVSSv3 9.8) - RCE in Zyxel. Validate that an unauthenticated attacker can execute arbitrary commands on the device by exploiting improperly sanitized inputs in the "setCookie" endpoint.
CVE-2024-38856 (CVSSv3 9.8) - RCE in Apache OFBiz. Validate this RCE through an especially crafted HTTP POST request that allows an attacker to fully compromise your server.
CVE-2024-4358 (CVSSv3 9.8) - Prove how an attacker can fully compromise your server with this RCE in Progress Telerik Report Server through an insecure XML deserialization.
CVE-2022-20705 (CVSSv3 9.8) and CVE-2022-20707 - Validate these Cisco Small Business RV Series RCE and Authentication Bypass vulnerabilities.
CVE-2024-5932 (CVSSv3 9.8) - assess the business risk of this GiveWP Donation Plugin RCE.
Scan diff for your scan results is finally here! We know you’ve been asking for it, so we’ve listened and delivered.
Available for port scanning, vulnerabilities, and subdomains, scan diff highlights new and updated findings compared to your previous scan on the same target within a set workspace.
Use it for continuous monitoring of all targets in your workspace
Get automatic notifications when anything changes, on your preferred channel (email, Slack, Teams, Discord, etc.)
Create an automatic scan baseline and use scheduled scans for easier tracking

We've increased the URL crawling speed by 30%, making the Website Scanner more efficient from start to finish.
Our proprietary web app scanner now uses parallelization when detecting cloud hosted URLs. Expect faster discovery, quicker scan completion, and more timely results.
We’ve also improved the tool’s passive detection method with:
Disclosure of OS paths in the HTTP response
Detection for session tokens in the request URLs