Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.562 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 169 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.420

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Protect WP Admin < 4.0 - Unauthenticated Protection BypassNetwork Scanner

Medium(6.1)

0.010.27No
User Profile Picture < 2.5.0 - Sensitive Information DisclosureNetwork Scanner

High(7.5)

0.010.68No
WPEngine WPGraphQL 0.2.3 - Unauthenticated Comment PostingNetwork Scanner

Medium(5.3)

0.220.96No
WordPress InstaWP Connect <= 0.1.0.38 - Unauthenticated User CreationNetwork Scanner

Critical(9.8)

0.50.98No
WordPress Loginizer < 1.6.4 – Unauthenticated SQL Injection via `log` ParameterNetwork Scanner

Critical(9.8)

0.610.99No
MCP Inspector < 0.14.0 UnauthenticatedRemote Code ExecutionNetwork Scanner

Critical

0.010.54No
Flowise Installation Wizard - ExposureNetwork Scanner

High

N/A
N/A
No
Images to WebP < 1.9 - Authenticated Local File InclusionNetwork Scanner

High(7.5)

0.010.75No
XXL-JOB v2.2.0 — Stored Cross Site ScriptingNetwork Scanner

Medium(6.1)

0.010.62No
WordPress Popup Builder <= 4.2.3 - Unauthenticated Stored XSSNetwork Scanner

Medium(6.1)

0.110.93No
Rank Math SEO <= 1.0.40.2 - Redirect Creation via Unprotected REST API EndpointNetwork Scanner

Medium(6.1)

0.010.63No
WordPress Sexy Contact Form (<= 0.9.7) - Arbitrary File UploadNetwork Scanner

Critical(9.8)

0.791No
WordPress 10Web Map Builder < 1.0.73 - Unauthenticated SQL InjectionNetwork Scanner

Critical(9.8)

0.010.68No
Flowise <= 3.0.5 - Account TakeoverNetwork Scanner

Critical(9.8)

0.010.2No
Cybersecurity Infrastructure Security Agency (CISA)Acronis Cyber Infrastructure - Default PasswordNetwork Scanner

Critical(9.8)

0.770.99No
WordPress FluentForms <= 5.1.16 - Broken Access ControlNetwork Scanner

High(7.5)

0.010.69No
Registrations for The Events Calendar < 2.7.5 - Authenticated Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.010.44No
Rank Math SEO <= 1.0.40.2 - Privilege Escalation via Unprotected REST API EndpointNetwork Scanner

Critical(9.8)

0.050.89No
Microsoft FrontPage Configuration - ExposureNetwork Scanner

Low

N/A
N/A
No
GiveWP Donation Plugin <= 3.16.1 - Unauthenticated PHP Object InjectionNetwork Scanner

Critical(10)

0.690.99No
OpenMetadata - Admin User EnumerationNetwork Scanner

Medium

N/A
N/A
No
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 - Privilege EscalationNetwork Scanner

Critical(9.8)

0.330.97No
Phoenix Contact CHARX SEC-3XXX AC Controller < 1.7.3 - Multiple VulnerabilitiesNetwork Scanner

Critical

N/A
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet SSL-VPN - Heap-Based Buffer OverflowNetwork Scanner

Critical(9.8)

0.951No
Memos 0.13.2 - Server-Side Request ForgeryNetwork Scanner

Medium(6.1)

0.080.92No