Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.052 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.052

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
librechat - Config ExposureNetwork Scanner

Low

N/A
N/A
No
Laravel Sanctum - Stateful Domain CSRF MisconfigurationNetwork Scanner

Medium

N/A
N/A
No
Laravel Clockwork - Sensitive Information ExposureNetwork Scanner

Medium

N/A
N/A
No
Laravel Nova - Unauthenticated Admin Panel AccessNetwork Scanner

High

N/A
N/A
No
Laravel Passport - OAuth2 Keys ExposedNetwork Scanner

High

N/A
N/A
No
PuppetDB Dashboard - Unauthenticated AccessNetwork Scanner

High

N/A
N/A
No
Laravel Pulse - Unauthenticated Dashboard AccessNetwork Scanner

Medium

N/A
N/A
No
FlipperCode Custom CSS, JS & PHP <= 2.0.7 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.010.78No
Laravel Debugbar - Sensitive Information ExposureNetwork Scanner

Medium

N/A
N/A
No
WordPress Burst Statistics 3.4.0-3.4.1.1 - Authentication BypassNetwork Scanner

Critical(9.8)

0.040.88No
YesWiki < 4.6.4 - Unauthenticated SQL InjectionNetwork Scanner

Critical(9.8)

N/A
N/A
No
Frappe Framework < 16.15.0 - Arbitrary File Read via render_include Path TraversalNetwork Scanner

Medium(6.5)

0.040.87No
cPanel Mailman - Cross-Site ScriptingNetwork Scanner

Medium

N/A
N/A
No
WatchGuard Fireware AD Helper Component - Credentials DisclosureNetwork Scanner

Critical(10)

0.170.95No
Laravel Ignition - Log Viewer Information DisclosureNetwork Scanner

Medium

N/A
N/A
No
TYPO3 ceselector Extension - Insecure DeserializationNetwork Scanner

Critical(9.8)

0.040.88No
Longjing Technology BEMS API 1.21 - Unauthenticated Arbitrary File DownloadNetwork Scanner

High(7.5)

0.020.84No
Frappe Framework - Default Login CredentialsNetwork Scanner

High

N/A
N/A
No
WordPress AudioIgniter <= 2.0.2 - Unauthenticated IDORNetwork Scanner

High(7.5)

0.280.97No
Web-Check < 2.0.1 Screenshot API - OS Command InjectionNetwork Scanner

Critical(9.8)

0.450.98No
Hazelcast Management Center - Configuration ExposureNetwork Scanner

Medium

N/A
N/A
No
Flowise 1.4.3 - Arbitrary File ReadNetwork Scanner

High(7.5)

0.580.99No
Ozeki 10 SMS Gateway 10.3.208 - Arbitrary File ReadNetwork Scanner

High

0.180.96No
Polyaxon - Unauthenticated Directory TraversalNetwork Scanner

High(7.5)

0.250.97No
Uptime-Kuma < v1.23.0 - Improper Access ControlNetwork Scanner

Medium(5.3)

0.010.75No