Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 12.132 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 150 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 12.132

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Angular-Base64-Upload - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Ivanti Avalanche SmartDeviceServer - XML External EntityNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)PAN-OS Management Web Interface - Authentication BypassNetwork Scanner

Critical(9.8)

No
Wavlink WL-WN530HG4 M30HG4.V5030.201217 - Information DisclosureNetwork Scanner

High(7.5)

No
Wavlink WL-WN533A8 M33A8.V5030.190716 - Information DisclosureNetwork Scanner

High(7.5)

No
WAVLINK Quantum D4G (WL-WN531G3) - Information DisclosureNetwork Scanner

High(7.5)

No
Safe Editor Plugin < 1.2 - CSS/JS-injectionNetwork Scanner

Medium(6.1)

No
D-Link NAS - Command Injection via Group ParameterNetwork Scanner

Critical(9.8)

No
Z-Downloads < 1.11.7 - Cross-Site ScriptingNetwork Scanner

Low(3.5)

No
Timesheet Plugin < 0.1.5 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
D-Link NAS - Command Injection via Name ParameterNetwork Scanner

Critical(9.8)

No
Visual CSS Style Editor < 7.5.4 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
CodeChecker <= 6.24.1 - Authentication BypassNetwork Scanner

Critical(10)

No
Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File ReadNetwork Scanner

High(8.6)

No
Symfony Profiler - Remote Access via Injected ArgumentsNetwork Scanner

High(7.3)

No
OpenAPI Generator <= 7.5.0 - Arbitrary File Read/DeleteNetwork Scanner

High(8.3)

No
GitHub Enterprise - SAML Authentication BypassNetwork Scanner

Critical(9.1)

No
Atom.CMS 2.0 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Lantronix SecureLinx Spider (SLS) 2.2+ - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
DedeCMS v5.7.111 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
ResourceSpace - Metadata ExportNetwork Scanner

Medium(6.5)

No
WAVLINK AC1200 - Information DisclosureNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Cloud Services Appliance - Path TraversalNetwork Scanner

Critical(9.1)

No
Twisted - Open Redirect & XSSNetwork Scanner

Medium(6.1)

No
WordPress Core <6.5.2 - Cross-Site ScriptingNetwork Scanner

High(7.2)

No