Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.117 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 930

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCENetwork Scanner

Critical(9.8)

0.91No
Cybersecurity Infrastructure Security Agency (CISA)Check Point IKEv1 Remote-Access VPN - Certificate Authentication BypassNetwork Scanner

Critical(10)

0.721No
Cybersecurity Infrastructure Security Agency (CISA)Splunk Enterprise & Cloud Platform - Unrestricted File UploadNetwork Scanner

Critical(9.8)

0.931No
Cybersecurity Infrastructure Security Agency (CISA)Joomla! JCE extension < 2.9.99.5 unauthenticated RCENetwork Scanner

Critical(10)

0.811No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Sentry - OS Command InjectionNetwork Scanner

Critical(10)

0.991No
Cybersecurity Infrastructure Security Agency (CISA)LiteLLM - Command InjectionNetwork Scanner

Critical(9.8)

0.751No
Cybersecurity Infrastructure Security Agency (CISA)Palo Alto Networks PAN-OS - Authentication BypassNetwork Scanner

Critical(9.1)

0.871No
Cybersecurity Infrastructure Security Agency (CISA)LiteLLM - SQL InjectionNetwork Scanner

Critical(9.8)

0.961No
Cybersecurity Infrastructure Security Agency (CISA)Drupal Core - Anonymous SQL Injection via PostgreSQL Entity QueryNetwork Scanner

Critical(9.8)

0.851No
Cybersecurity Infrastructure Security Agency (CISA)Cisco Catalyst SD-WAN Controller - vHub Authentication BypassNetwork Scanner

Critical(10)

0.881No
Cybersecurity Infrastructure Security Agency (CISA)cPanel & WHM - Authentication Bypass via Session-File CRLF InjectionNetwork Scanner

Critical(9.8)

0.991No
Cybersecurity Infrastructure Security Agency (CISA)Langflow < 1.9.0 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.991No
Cybersecurity Infrastructure Security Agency (CISA)SmarterMail - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.881No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiClientEMS 7.4.4 - SQL InjectionNetwork Scanner

Critical(9.8)

0.951No
Cybersecurity Infrastructure Security Agency (CISA)FortiClient EMS - Authentication BypassNetwork Scanner

High(9.8)

0.891No
Cybersecurity Infrastructure Security Agency (CISA)Marimo <= 0.20.4 - Pre-Auth Terminal WebSocket RCENetwork Scanner

Critical(9.3)

0.961No
Cybersecurity Infrastructure Security Agency (CISA)Apache ActiveMQ - Remote Code ExecutionNetwork Scanner

High(8.8)

0.971No
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - OS Command InjectionNetwork Scanner

Critical(9.8)

0.991Yes
Cybersecurity Infrastructure Security Agency (CISA)Cisco ISE - Unauthenticated Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.971Yes
Cybersecurity Infrastructure Security Agency (CISA)Citrix NetScaler SAML IDP - Memory OverreadNetwork Scanner

Critical(9.8)

0.841No
Cybersecurity Infrastructure Security Agency (CISA)FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command InjectionNetwork Scanner

High(8.6)

0.851No
Cybersecurity Infrastructure Security Agency (CISA)Hikvision IP camera/NVR - Remote Command ExecutionNetwork Scanner

Critical(9.8)

11Yes
Cybersecurity Infrastructure Security Agency (CISA)Aviatrix Controller - Remote Code ExecutionNetwork Scanner

Critical(10)

0.991Yes
Cybersecurity Infrastructure Security Agency (CISA)HPE OneView - Remote Code ExecutionNetwork Scanner

Critical(10)

0.91Yes
Cybersecurity Infrastructure Security Agency (CISA)MeteoBridge <= 6.1 - Remote Code ExecutionNetwork Scanner

High(7.5)

0.941Yes