Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.007 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.007

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Appsmith <= v1.97 - Information DisclosureNetwork Scanner

Medium

N/A
N/A
No
sar2html <=3.2.2 Plot Parameter - Remote Code ExecutionNetwork Scanner

Critical(10)

0.040.89No
EspoCRM <= 9.3.3 - Server-Side Request ForgeryNetwork Scanner

Medium(4.3)

0.010.66No
dash-uploader 0.1.0 - 0.7.0a2 - Unauthenticated Arbitrary File Write via Path TraversalNetwork Scanner

Critical(9.8)

0.150.95No
dash-uploader 0.1.0 - 0.7.0a2 - Denial-of-Service via flowTotalChunksNetwork Scanner

High(7.5)

0.010.69No
WordPress Campress Theme <= 1.35 - Unauthenticated Local File InclusionNetwork Scanner

Critical(9.8)

0.160.95No
Cloudlog - SQL InjectionNetwork Scanner

High(7.3)

0.020.82No
LoLLMS WebUI < 9.8 - Path TraversalNetwork Scanner

High(7.5)

0.560.99No
WordPress Formality Plugin <= 1.5.9 - Local File InclusionNetwork Scanner

Critical(9.8)

0.060.91No
TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File UploadNetwork Scanner

Critical(9.8)

0.40.98No
ASP.NET Trace.AXD - ExposureNetwork Scanner

Low

N/A
N/A
No
Tattile Camera < 1.181.5 - Default LoginNetwork Scanner

Critical(9.3)

0.150.95No
IBM MobileFirst Foundation - Default CredentialsNetwork Scanner

Critical

N/A
N/A
No
Hoppscotch <= 2026.2.1 - Open RedirectNetwork Scanner

Medium(4.7)

0.010.7No
Coveralls Configuration File ExposureNetwork Scanner

Medium

N/A
N/A
No
Mailcow < 2026-03b - Href Link InjectionNetwork Scanner

Low(3.1)

0.060.91No
Redis Exporter Metrics - ExposureNetwork Scanner

Medium

N/A
N/A
No
DataEase 2.10.4-2.10.7 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.10.93No
Astro SSR - Server-Side Request ForgeryNetwork Scanner

High(8.6)

0.070.91No
OpenCode Web - Unauthenticated AccessNetwork Scanner

Medium

N/A
N/A
No
Apache ActiveMQ 6.x < 6.1.2 - Broken Access ControlNetwork Scanner

High(8.8)

0.730.99No
Detects Springboot HTTP Exchanges ActuatorNetwork Scanner

Low

N/A
N/A
No
Google ADK-Python - Unauthenticated Builder EndpointNetwork Scanner

Critical(9.3)

0.030.85No
CKAN DataStore SQL Search - SQL InjectionNetwork Scanner

Critical(9.8)

N/A
N/A
No
MLflow Job API - Authentication BypassNetwork Scanner

Critical(9.1)

0.060.91No