Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.299 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 166 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 742

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-859 Multiple Vulnerabilities (2019 - 2024)Network Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Remote Code ExecutionNetwork Scanner

High(7.5)

Yes
Cybersecurity Infrastructure Security Agency (CISA)QNAP Photo Station < 6.0.3 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft SMBv3 - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft .NET Framework - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft SharePoint - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Dahua IPC/VTH/VTO - Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link Network Attached Storage - Backdoor AccountNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)NUUO NVRmini - Remote Command ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Tenda AC15 AC1900 version 15.03.05.19 - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Roundcube Webmail - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-300 Multiple Vulnerabilities (2011 - 2024)Network Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-859 < 1.07b03_beta RCE Vulnerability (SAP10146)Network Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Nazgul Nostromo nhttpd < 1.9.7 Multiple Directory Traversal VulnerabilitiesNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-605 - Information DisclosureNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Craft CMS - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)ZKTeco BioTime v8.5.5 - Path TraversalNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)TP-Link Archer AX21 (AX1800) - Unauthenticated Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)PRTG Network Monitor - Local File InclusionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)ThinkPHP 5.0.23 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Wazuh - Unsafe Deserialization Remote Code ExecutionNetwork Scanner

Critical(9.9)

No
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code ExecutionNetwork Scanner

Medium(5.3)

No