Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 14.295 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 151 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 14.295

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Aimhubio Aim Server 3.19.3 - Arbitrary File OverwriteNetwork Scanner

Critical(9.8)

No
ThinkPHP 6.0.0-6.0.1 - Arbitrary File WriteNetwork Scanner

Critical

No
Cybersecurity Infrastructure Security Agency (CISA)PAN-OS Management Web Interface - Command InjectionNetwork Scanner

High(7.2)

No
mooSocial 3.1.8 - External Service InteractionNetwork Scanner

Medium(6.5)

No
Cybersecurity Infrastructure Security Agency (CISA)ServiceNow UI Macros - Template InjectionNetwork Scanner

High(9.8)

No
Netmaker - Hardcoded DNS Secret KeyNetwork Scanner

High(7.5)

No
Gradio 3.47 - 3.50.2 - Local File InclusionNetwork Scanner

High(7.5)

No
Base64 Encoder/Decoder <= 0.9.2 - Cross-Site ScriptingNetwork Scanner

Medium(6.5)

No
Popup Builder Plugin - SQL Injection and Cross-Site ScriptingNetwork Scanner

Critical(9.8)

No
CrateDB Database - Arbitrary File ReadNetwork Scanner

Medium(6.5)

No
Last.fm Rotation 1.0 - Path TraversalNetwork Scanner

Medium(5)

No
Cloudflare Rocket Loader - HTML InjectionNetwork Scanner

Low

No
GestSup - Account TakeoverNetwork Scanner

Critical(9.8)

No
Dahua DSS - SQL Injection (CNVD-2017-06001)Network Scanner

High

No
POS Codekop v2.0 - Broken AuthenticationNetwork Scanner

High(7.5)

No
nginxWebUI <= 3.5.0 - Remote Command ExecutionNetwork Scanner

Critical

No
Chuanhu Chat - Directory TraversalNetwork Scanner

Critical(9.8)

No
EyouCms v1.6.2 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Control iD iDSecure - Authentication BypassNetwork Scanner

Critical(9.8)

No
GestSup - Cross-Site ScriptingNetwork Scanner

High(8.6)

No
Gradio 3.47 - 3.50.2 - Server-Side Request ForgeryNetwork Scanner

High(7.5)

No
Next.js Cache PoisoningNetwork Scanner

High

No
Cybersecurity Infrastructure Security Agency (CISA)PaloAlto Networks Expedition - Remote Code ExecutionNetwork Scanner

Critical(9.9)

No
IBM WebSphere Application Server 7.x < 7.0.0.13 Multiple VulnerabilitiesNetwork Scanner
N/A
No
IBM WebSphere Application Server 7.x < 7.0.0.13 WS-Security Policy VulnerabilityNetwork Scanner
N/A
No