Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.489 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.489

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Prometheus Blackbox Exporter - Server-Side Request Forgery (SSRF)Network Scanner

Medium(5.8)

0.040.88No
LiquidFiles < 4.2 - User Enumeration via Password ResetNetwork Scanner

High(7.3)

0.050.89No
osTicket - Arbitrary File ReadNetwork Scanner

High

0.050.89No
Oracle iPlanet Web Server 7.0.x - Image InjectionNetwork Scanner

Medium(4.8)

0.420.98No
OneDev < 4.0.3 - User Access Token LeakNetwork Scanner

High(8.6)

0.310.97No
Astro - Unauthorized Third-Party Image AccessNetwork Scanner

Medium(6.4)

0.010.37No
Umbraco CMS - Directory Listing ExposureNetwork Scanner

Medium

N/A
N/A
No
Perforce Repository DisclosureNetwork Scanner

Low

N/A
N/A
No
Sendmail .forward File - ExposureNetwork Scanner

Medium

N/A
N/A
No
OpenNMS Dashboard - ExposureNetwork Scanner

Medium

N/A
N/A
No
OpenLiteSpeed WebAdmin - Default LoginNetwork Scanner

High

N/A
N/A
No
WordPress Header Footer Elementor - Full Path DisclosureNetwork Scanner

Low

N/A
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Gogs <= 0.13.3 - Remote Code ExecutionNetwork Scanner

High(8.8)

0.250.96No
SQLite History - ExposureNetwork Scanner

Medium

N/A
N/A
No
Spring Boot `X-Application-Context` Header ExposureNetwork Scanner

Low

N/A
N/A
No
Adobe Experience Manager Forms - Insecure DeserializationNetwork Scanner

Critical(9.8)

0.40.98No
WordPress Easy WP SMTP - Log ExposureNetwork Scanner

High

N/A
N/A
No
ServiceStack Request Logs - Unauthenticated AccessNetwork Scanner

High

N/A
N/A
No
info.cgi Environment Variable - DisclosureNetwork Scanner

Medium

N/A
N/A
No
Symfony Lock File - ExposureNetwork Scanner

Low

N/A
N/A
No
Apache Tika - XML External Entity InjectionNetwork Scanner

Critical(9.8)

0.040.88No
Fastly Backend Server Information DisclosureNetwork Scanner

Medium

N/A
N/A
No
Rancher - Incomplete Setup ExposureNetwork Scanner

Low

N/A
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Grandstream UCM6200 - SQL InjectionNetwork Scanner

Critical(9.8)

0.941No
Advantech WISE-IoTSuite/SaaS - SQL InjectionNetwork Scanner

Critical(10)

0.090.93No