Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.922 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 172 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.922

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Bentoml - Server Side Request ForgeryNetwork Scanner

High

N/A
N/A
No
MapTiler Tileserver-php v2.0 - Unauthenticated File ReadNetwork Scanner

High(7.5)

0.010.29No
MapTiler Tileserver-php v2.0 - Unauthenticated XSSNetwork Scanner

Medium(6.1)

0.010.48No
Cybersecurity Infrastructure Security Agency (CISA)Oracle WebLogic Server - Remote Code Execution (Insecure Deserialization)Network Scanner

Critical(9.8)

0.941No
Arcserve Unified Data Protection - Authentication BypassNetwork Scanner

Critical(9.8)

0.270.97No
UniFi - NFC CredentialsNetwork Scanner

High

N/A
N/A
No
Reflected XSSNetwork Scanner

Low

N/A
N/A
No
UniFi - Unauthenticated Creation Access For UsersNetwork Scanner

High

N/A
N/A
No
Arcserve Unified Data Protection - Unauthenticated DoS in ASNative.dllNetwork Scanner

High(7.5)

0.650.99No
UniFi Access - Broken Access ControlNetwork Scanner

Critical(10)

0.060.9No
Mailgun TakeoverNetwork Scanner

High

N/A
N/A
No
ChurchCRM - Default LoginNetwork Scanner

High

N/A
N/A
No
ChurchCRM - Setup ExposureNetwork Scanner

High

N/A
N/A
No
ArgoCD Project API Token Repository Credentials ExposureNetwork Scanner

Critical(9.9)

0.060.9No
Python DoS Vulnerability (Oct 2025) - WindowsNetwork Scanner
N/A
0.010.03No
ChurchCRM - SQL InjectionNetwork Scanner

Critical(9.8)

0.010.72No
Discourse Cache Poisoning Vulnerability (GHSA-jp9x-wwv6-cv3j)Network Scanner
N/A
0.010.17No
FOGProject <= 1.5.10.1673 - Authentication BypassNetwork Scanner

Critical(9.1)

0.090.93No
JSONPath Plus < 10.3.0 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.871No
Cybersecurity Infrastructure Security Agency (CISA)Oracle E-Business Suite - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.841Yes
XWiki Platform - SQL InjectionNetwork Scanner

Critical(9.8)

0.160.95No
Letta Letta 0.7.12 - Remote Code ExecutionNetwork Scanner

High(8.8)

0.10.93No
Code-Projects School Fees Payment System 1.0 - SQL InjectionNetwork Scanner

Critical(9.8)

0.030.85No
Generic PHP Backup Information DisclosureNetwork Scanner

Medium

N/A
N/A
No
QVIS NVR/DVR - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.720.99No