Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.245 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 852

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)ThinkPHP < 3.2.4 - Remote Code ExecutionNetwork Scanner

High(8.8)

0.951No
Cybersecurity Infrastructure Security Agency (CISA)Gladinet CentreStack & Triofox - Hardcoded CredentialsNetwork Scanner

Critical(9.8)

0.350.97No
Cybersecurity Infrastructure Security Agency (CISA)Zoho ManageEngine ServiceDesk Plus - Authentication BypassNetwork Scanner

Critical(9.8)

0.931No
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code Execution (React2Shell)Network Scanner

Critical(10)

0.470.98Yes
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code ExecutionNetwork Scanner

Critical(10)

0.470.98No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiWeb - Authentication Bypass & Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.881Yes
Cybersecurity Infrastructure Security Agency (CISA)GeoServer - XML External Entity InjectionNetwork Scanner

High(8.2)

0.831No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra - Cross-Site Scripting via ICS FilesNetwork Scanner

Medium(5.4)

0.30.97No
Cybersecurity Infrastructure Security Agency (CISA)Oracle Identity Manager REST WebServices - Authentication BypassNetwork Scanner

Critical(9.8)

0.811No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft SharePoint Server - Authentication BypassNetwork Scanner

Medium(6.5)

0.730.99No
Cybersecurity Infrastructure Security Agency (CISA)FortiWeb - Authentication BypassNetwork Scanner

Critical(9.8)

0.881No
Cybersecurity Infrastructure Security Agency (CISA)Triofox - Improper Access ControlNetwork Scanner

Critical(9.8)

0.790.99No
Cybersecurity Infrastructure Security Agency (CISA)Oracle WebLogic Server - Remote Code Execution (Insecure Deserialization)Network Scanner

Critical(9.8)

0.941No
Cybersecurity Infrastructure Security Agency (CISA)Oracle E-Business Suite - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.81Yes
Cybersecurity Infrastructure Security Agency (CISA)FortiManager Unauthenticated Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.941No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra Collaboration - Cross-Site Scripting (XSS)Network Scanner

Medium(6.1)

0.270.97No
Cybersecurity Infrastructure Security Agency (CISA)Oracle E-Business Suite - Server-Side Request ForgeryNetwork Scanner

High(7.5)

0.450.98No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra Collaboration Suite - Cross-site ScriptingNetwork Scanner

Medium(6.8)

0.620.99No
Cybersecurity Infrastructure Security Agency (CISA)Windows Server Update Service - Insecure DeserializationNetwork Scanner

Critical(9.8)

0.760.99No
Cybersecurity Infrastructure Security Agency (CISA)VMware vCenter Server - Out-of-Bounds WriteNetwork Scanner

Critical(9.8)

0.941No
Cybersecurity Infrastructure Security Agency (CISA)Adobe Experience Manager Forms - Insecure DeserializationNetwork Scanner

Critical(10)

0.490.98No
Cybersecurity Infrastructure Security Agency (CISA)Mitel MiCollab - Information Disclosure & Denial of ServiceNetwork Scanner

Critical(9.8)

0.91No
Cybersecurity Infrastructure Security Agency (CISA)Adobe Commerce - Authentication BypassNetwork Scanner

Critical(9.1)

0.60.99No
Cybersecurity Infrastructure Security Agency (CISA)Kentico Xperience 13 CMS - Staging Service Authentication Bypass (WT-2025-0006)Network Scanner

Critical(9.8)

0.891No
Cybersecurity Infrastructure Security Agency (CISA)Kaseya VSA 2017 ConnectWise ManagedITSync - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.821No