Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.049 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 161 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 14.907

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
NTFY Web - ExposureNetwork Scanner

Medium

No
elFinder 2.1.58 - Remote Code ExecutionNetwork Scanner

Critical

No
Firebase database detectedNetwork Scanner

Low

No
DWR detect test pageNetwork Scanner

Low

No
Elasticsearch - SQL ClientNetwork Scanner

Low

No
Cybersecurity Infrastructure Security Agency (CISA)Gladinet CentreStack < 16.4.10315.56368 Use of Hard-coded Key Leads to Unauthenticated RCENetwork Scanner

Critical(9.8)

No
LDAP Anonymous LoginNetwork Scanner

Medium

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized Mirror AnnotationsNetwork Scanner

High(8.8)

No
cPanel Configuration - File DisclosureNetwork Scanner

Medium

No
GeoVision GV-SNVR0811 - Directory TraversalNetwork Scanner

High

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-tls-match-cn` AnnotationNetwork Scanner

High(8.8)

No
Uncanny Automator <= 6.3.0.2 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationNetwork Scanner

High(8.8)

No
Sante PACS Server.exe - Path Traversal Information DisclosureNetwork Scanner

High(7.5)

No
DSL-124 Wireless N300 ADSL2+ - Backup File DisclosureNetwork Scanner

High

No
MinIO - Incomplete Signature Validation for Unsigned-Trailer UploadsNetwork Scanner

High

No
Ingress-Nginx Controller - Configuration Injection via Unsanitized `auth-url` AnnotationNetwork Scanner

High(8.8)

No
UNA CMS 14.0.0-RC - PHP Object InjectionNetwork Scanner

Critical

No
Langflow AI - Unauthenticated Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Vite Development Server - Path TraversalNetwork Scanner

Medium(5.3)

No
WordPress Download Manager - File Password ExposureNetwork Scanner

Medium(5.3)

No
Delmia Apriso - Pre-Authentication Unsafe .NET Object DeserializationNetwork Scanner

Critical(9)

No
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege EscalationNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet Authentication BypassNetwork Scanner

Critical(9.8)

No
Vipshop Saturn Console <= 3.5.1 - SQL Injection via ClusterKey ComponentNetwork Scanner

Critical(9.8)

No
WordPress Download Manager < 3.2.44 - Authenticated Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No