Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.920 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.920

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Vendure Core - SQL InjectionNetwork Scanner

Critical(9.1)

N/A
N/A
No
Retool Self-Hosted - postMessage XSS via Custom Component CollectionsNetwork Scanner

High

N/A
N/A
No
esm.sh <= v136 - Arbitrary File Write via Path TraversalNetwork Scanner

Medium(5.3)

0.020.81No
Arcane <= 1.17.2 - Server-Side Request ForgeryNetwork Scanner

High(7.2)

0.010.06No
OpenAM <= 16.0.5 - Pre-Auth RCE via jato.clientSession DeserializationNetwork Scanner

Critical(9.8)

0.010.65No
Cybersecurity Infrastructure Security Agency (CISA)SmarterMail - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.670.99No
AnythingLLM - Username Enumeration via Password RecoveryNetwork Scanner

Medium(5.3)

0.010.17No
Vite Dev Server - Arbitrary File ReadNetwork Scanner

High(8.2)

0.010.21No
Chainlit - Unauthenticated AccessNetwork Scanner

Low

N/A
N/A
No
WordPress Madara Theme < 2.2.2.1 - Local File InclusionNetwork Scanner

Critical(9.1)

0.020.79No
ChromaDB - Unauthenticated API ExposureNetwork Scanner

Medium

N/A
N/A
No
Nginx UI - Broken Access ControlNetwork Scanner

Critical(9.8)

0.050.9No
Reflected Odoo - Open RedirectNetwork Scanner

Low

N/A
N/A
No
Cockpit Web Console < 360 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.020.83No
DbGate Anonymous AccessNetwork Scanner

High

N/A
N/A
No
Flowise - NVIDIA NIM Endpoints Missing AuthenticationNetwork Scanner

High(8.6)

0.040.88No
WCAPF WooCommerce Ajax Product Filter - SQL InjectionNetwork Scanner

High(7.5)

0.190.96No
User Registration & Membership WordPress plugin - Open RedirectNetwork Scanner

Medium(6.1)

0.020.79No
Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL InjectionNetwork Scanner

High(8.6)

0.070.92No
LoLLMs WEBUI - Server-Side Request ForgeryNetwork Scanner

Critical(9.1)

0.170.95No
AstrBot <= 4.22.1 - Command InjectionNetwork Scanner

High(8.8)

0.040.88No
Cisco Secure Firewall Management Center - Authentication BypassNetwork Scanner

Critical(10)

0.120.94No
HT Mega < 3.0.7 - Sensitive Information DisclosureNetwork Scanner

High(7.5)

N/A
N/A
No
AstrBot - Default LoginNetwork Scanner

High

N/A
N/A
No
Geo Mashup <= 1.13.17 - SQL InjectionNetwork Scanner

High(7.5)

0.270.97No