Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.061 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 176 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.919

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Munin Monitoring Dashboard - ExposureNetwork Scanner

Medium

N/A
N/A
No
ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)Network Scanner

Critical(9.8)

0.010.74No
ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.010.46No
WordPress <= 5.2.4 - Unauthenticated View Private/Draft PostsNetwork Scanner

Medium(5.3)

0.760.99No
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code ExecutionNetwork Scanner

Critical(10)

0.140.95No
Microsoft SharePoint - List API DisclosureNetwork Scanner

Low

N/A
N/A
No
HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege EscalationNetwork Scanner

Critical(9.8)

0.620.99No
Post Grid <= 2.2.50 - Information Exposure via REST APINetwork Scanner

High(7.5)

0.530.98No
WP Google Maps < 9.0.48 - Cross-Site ScriptingNetwork Scanner

High(8.8)

0.140.95No
OpenWRT Privilege Escalation Vulnerability (Mar 2025)Network Scanner

High(8)

0.010.06No
freeFTPD < 1.0.12 PASS Command Buffer Overflow VulnerabilityNetwork Scanner

Critical(9.8)

0.630.99No
RegistrationMagic <= 5.0.1.7 - Authentication BypassNetwork Scanner

Critical(9.8)

0.720.99No
Apache Struts DoS Vulnerability (S2-068)Network Scanner

High(7.5)

0.010.27No
Caldera Forms < 1.9.7 - Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.030.84No
elFinder < 2.1.58 - Remote Code ExecutionNetwork Scanner

High(8.1)

0.710.99No
Synology DiskStation Manager (DSM) File Write Vulnerability (Synology-SA-24:20) - Remote Known Vulnerable Versions CheckNetwork Scanner

Medium(4.3)

0.010.17No
WP Live Chat Support <= 8.0.27 — Stored Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.060.91No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiWeb - Authentication Bypass & Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.881Yes
ShortCode Addons - Unauthenticated Options UpdateNetwork Scanner

Critical(9.8)

0.490.98No
PrestaShop - Information DisclosureNetwork Scanner

Medium(3.7)

0.020.78No
Apache2 - Transfer-Encoding Chunked XSSNetwork Scanner

Medium(6.1)

0.130.94No
News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File InclusionNetwork Scanner

High(8.1)

0.460.98No
SolarWinds Serv-U FTP - Remote Code ExecutionNetwork Scanner

Critical

N/A
N/A
No
WP Popups - Information DisclosureNetwork Scanner

Medium(5.3)

0.090.93No
Prestashop Blockwishlist 2.1.0 SQL InjectionNetwork Scanner

High(8.1)

0.550.98No