Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities that can be detected with Pentest-Tools.com and the exploits that are currently available in the platform.

We detect more than 11.408 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 141 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 11.408

Pentest-Tools.com Vulnerabilities
Name
CVE
Detectable
with
Detection added
Severity
CVSSv3
score
Exploitable
with Sniper
EfroTech Timetrax v8.3 - Sql InjectionNetwork Scanner
---
---No
Dolibarr ERP CMS `list.php` - SQL InjectionNetwork Scanner

Critical

9.1No
FOG Project < 1.5.10.34 - Remote Command ExecutionNetwork Scanner

Critical

9.8No
RWS WorldServer - Authentication BypassNetwork Scanner

Critical

9.8No
TurboMeeting - Boolean-based SQL InjectionNetwork Scanner
---
---No
LiteLLM - Server-Side Request ForgeryNetwork Scanner
---
---No
Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via HashNetwork Scanner

Critical

9.8No
Craft CMS <=v3.7.31 - SQL InjectionNetwork Scanner

Critical

9.8No
Polyfill Supply Chain Attack Malicious Code ExecutionNetwork Scanner

High

7.2No
Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal - Remote Code ExecutionNetwork Scanner

Critical

9.8No
wpForo Forum <= 2.1.8 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
Temenos Transact - Cross-Site ScriptingNetwork Scanner
---
---No
Bazarr < 1.4.3 - Arbitrary File ReadNetwork Scanner
---
---No
LiveGBS user/save - Logical Flaw (CNVD-2023-72138)Network Scanner
---
---No
ShokoServer System - Local File Inclusion (LFI)Network Scanner

High

8.6No
H3C ER8300G2-X - Password DisclosureNetwork Scanner

Critical

9.8No
TOTOLINK EX1800T TOTOLINK EX1800T - Command InjectionNetwork Scanner
---
---No
EasySpider 0.6.2 - Arbitrary File ReadNetwork Scanner

Medium

4.3No
Netgear-WN604 downloadFile.php - Information DisclosureNetwork Scanner

Medium

5.3No
Next.js - Server Side Request Forgery (SSRF)Network Scanner

High

7.5No
Magento - XML External Entity InjectionNetwork Scanner

Critical

9.8Yes
BlueNet Technology Clinical Browsing System 1.2.1 - Sql InjectionNetwork Scanner

Medium

6.3No
WPS Hide Login < 1.9.16.4 - Hidden Login Page DisclosureNetwork Scanner

Medium

6.1No
XWiki - Open RedirectNetwork Scanner

Medium

6.1No
WWBN AVideo 11.6 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No