Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.264 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 164 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 701

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)Dahua IPC/VTH/VTO - Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link Network Attached Storage - Backdoor AccountNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)NUUO NVRmini - Remote Command ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Tenda AC15 AC1900 version 15.03.05.19 - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR820LA1_FW105B03 'ping_addr' - OS Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Roundcube Webmail - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Nazgul Nostromo nhttpd < 1.9.7 Multiple Directory Traversal VulnerabilitiesNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-859 < 1.07b03_beta RCE Vulnerability (SAP10146)Network Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-300 Multiple Vulnerabilities (2011 - 2024)Network Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-605 - Information DisclosureNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)ZKTeco BioTime v8.5.5 - Path TraversalNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)TP-Link Archer AX21 (AX1800) - Unauthenticated Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)PRTG Network Monitor - Local File InclusionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)ThinkPHP 5.0.23 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Wazuh - Unsafe Deserialization Remote Code ExecutionNetwork Scanner

Critical(9.9)

No
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Unauthenticated Remote Code ExecutionNetwork Scanner

Medium(5.3)

No
Cybersecurity Infrastructure Security Agency (CISA)Sonicwall - Pre-Authentication Arbitrary File ReadNetwork Scanner

Critical(9.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Commvault - SSRF via /commandcenter/deployWebpackage.doNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)SAP NetWeaver Visual Composer Metadata Uploader - DeserializationNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)TP-Link AX21 Router Devices Multiple Vulnerabilities (Apr 2023)Network Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Kentico CMS <= 12.0.14 RCE VulnerabilityNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Erlang/OTP SSH - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)CrushFTP - Authentication BypassNetwork Scanner

Critical(9.8)

No