Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.962 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 190

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Hoverfly - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.590.99Yes
Cybersecurity Infrastructure Security Agency (CISA)Cisco ISE - Unauthenticated Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.370.98Yes
Blink Router (LB-LINK) - OS Command InjectionNetwork Scanner

Critical(9.8)

0.350.98Yes
Roxy-WI - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.740.99Yes
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - OS Command InjectionNetwork Scanner

Critical(9.8)

0.791Yes
Cybersecurity Infrastructure Security Agency (CISA)Hikvision IP camera/NVR - Remote Command ExecutionNetwork Scanner

Critical(9.8)

0.951Yes
Cybersecurity Infrastructure Security Agency (CISA)Aviatrix Controller - Remote Code ExecutionNetwork Scanner

Critical(10)

0.951Yes
Cybersecurity Infrastructure Security Agency (CISA)MeteoBridge <= 6.1 - Remote Code ExecutionNetwork Scanner

High(7.5)

0.440.98Yes
Cybersecurity Infrastructure Security Agency (CISA)HPE OneView - Remote Code ExecutionNetwork Scanner

Critical(10)

0.841Yes
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.81Yes
Cybersecurity Infrastructure Security Agency (CISA)Telnet inetutils - Authentication BypassNetwork Scanner

Critical(9.8)

0.881Yes
WordPress Post SMTP - Account TakeoverNetwork Scanner

Critical(9.8)

0.170.95Yes
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code Execution (React2Shell)Network Scanner

Critical(10)

0.851Yes
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiWeb - Authentication Bypass & Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.931Yes
WordPress Simple File List - Unauthenticated RCENetwork Scanner

Critical(9.8)

0.881Yes
Cybersecurity Infrastructure Security Agency (CISA)React Native Community CLI development server - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.190.96Yes
ASP.NET Core - Request SmugglingNetwork Scanner

Critical(9.9)

0.020.8Yes
Cybersecurity Infrastructure Security Agency (CISA)Oracle E-Business Suite - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.91Yes
Cybersecurity Infrastructure Security Agency (CISA)Magento & Adobe Commerce - Account TakeoverNetwork Scanner

Critical(9.1)

0.690.99Yes
Cybersecurity Infrastructure Security Agency (CISA)FreePBX - Authentication Bypass leading to SQL Injection & Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.770.99Yes
Fortinet FortiSIEM - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.450.98Yes
Cybersecurity Infrastructure Security Agency (CISA)Microsoft Sharepoint - Authentication Bypass & Remote Code ExecutionNetwork Scanner

High(8.8)

0.620.99Yes
SSH user enumerationNetwork Scanner

Medium(5.3)

0.911Yes
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Remote Code ExecutionNetwork Scanner

High(7.5)

0.921Yes
Wordpress TemplateInvaders - Arbitrary File UploadNetwork Scanner

Critical(10)

0.010.4Yes