Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.078 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.936

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
UniFi OS Server - Command InjectionNetwork Scanner

Critical(10)

0.010.28No
Dozzle - Server Side Request ForgeryNetwork Scanner

High(8.6)

0.010.08No
changedetection.io <= 0.52.9 - Unauthenticated Path TraversalNetwork Scanner

Medium(5.3)

0.020.82No
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL InjectionNetwork Scanner

High(7.5)

0.010.25No
dotCMS Core Publish Audit API - Unauthenticated SQL InjectionNetwork Scanner

Critical

0.010.65No
Milvus - Unauthenticated Metrics API AccessNetwork Scanner

Critical(9.8)

0.160.95No
PrestaShop lgcookieslaw - SQL InjectionNetwork Scanner

Critical(9.8)

0.210.96No
phpBB - Authentication bypassNetwork Scanner

Critical(9.4)

N/A
N/A
No
MLflow < 3.10.0 - Authentication Bypass on FastAPI RoutesNetwork Scanner

High(8.6)

0.020.81No
Starlette - Improper Validation of Unsafe Equivalence in InputNetwork Scanner

Medium(6.5)

0.010.58No
Open WebUI 'LDAP Empty Password' - Authentication BypassNetwork Scanner

Critical(9.1)

0.030.87No
Label Studio < 1.18.0 - Reflected XSSNetwork Scanner

Medium(6.1)

0.010.77No
Scramble Laravel - Remote Code ExecutionNetwork Scanner

Critical(9.4)

0.090.93No
Bitrix Site Management 2.x - Open RedirectNetwork Scanner

Medium(6.1)

0.020.8No
DataEase < 2.10.10 - JWT Authentication BypassNetwork Scanner

Critical(9.8)

0.080.92No
Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path TraversalNetwork Scanner

Critical(10)

0.240.97No
E-Learning System 1.0 - SQL InjectionNetwork Scanner

Critical(9.8)

0.630.99No
BrightSign Digital Signage 8.2.26 - Server-Side Request ForgeryNetwork Scanner

Medium

0.050.9No
Cybersecurity Infrastructure Security Agency (CISA)LiteLLM - Command InjectionNetwork Scanner

Critical(9.8)

0.610.99No
Open WebUI < 0.9.5 - Information DisclosureNetwork Scanner

Medium(5.3)

0.020.79No
YesWiki - Cross-Site ScriptingNetwork Scanner

High

N/A
N/A
No
WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.090.93No
Cybersecurity Infrastructure Security Agency (CISA)Palo Alto Networks PAN-OS - Authentication BypassNetwork Scanner

Critical(9.1)

0.590.99No
JoomSport <= 5.7.7 - SQL InjectionNetwork Scanner

Critical(9.3)

N/A
N/A
No
WordPress FluentCRM <= 2.9.87 - Unauthenticated Blind SSRFNetwork Scanner

Medium(5.4)

0.010.76No