Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.996 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.996

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Hoppscotch <= 2026.2.1 - Open RedirectNetwork Scanner

Medium(4.7)

0.010.56No
Coveralls Configuration File ExposureNetwork Scanner

Medium

N/A
N/A
No
Mailcow < 2026-03b - Href Link InjectionNetwork Scanner

Low(3.1)

0.060.91No
Redis Exporter Metrics - ExposureNetwork Scanner

Medium

N/A
N/A
No
DataEase 2.10.4-2.10.7 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.120.94No
Astro SSR - Server-Side Request ForgeryNetwork Scanner

High(8.6)

0.060.91No
OpenCode Web - Unauthenticated AccessNetwork Scanner

Medium

N/A
N/A
No
Apache ActiveMQ 6.x < 6.1.2 - Broken Access ControlNetwork Scanner

High(8.8)

0.730.99No
Google ADK-Python - Unauthenticated Builder EndpointNetwork Scanner

Critical(9.3)

0.030.85No
CKAN DataStore SQL Search - SQL InjectionNetwork Scanner

Critical(9.8)

N/A
N/A
No
MLflow Job API - Authentication BypassNetwork Scanner

Critical(9.1)

0.060.91No
WordPress Widgets for Social Photo Feed <= 1.8 - Information DisclosureNetwork Scanner

Medium(6.5)

0.040.88No
Detects Springboot HTTP Exchanges ActuatorNetwork Scanner

Low

N/A
N/A
No
XWiki - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.020.83No
Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport BypassNetwork Scanner

High(8.8)

0.090.93No
Apache Casbin MCP Gateway - Default LoginNetwork Scanner

High

N/A
N/A
No
WordPress OrderConvo < 14 - Path TraversalNetwork Scanner

High(7.5)

0.390.98No
Supabase Studio - ExposureNetwork Scanner

High

N/A
N/A
No
MajorDoMo - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.010.27No
Vite - Path TraversalNetwork Scanner

Medium(6)

0.020.84No
ChurchCRM - API Authentication Bypass via URL InjectionNetwork Scanner

Critical(9.1)

0.160.95No
Spring Framework - Path TraversalNetwork Scanner

Medium(5.9)

0.070.92No
LMDeploy - Server-Side Request ForgeryNetwork Scanner

High(7.5)

0.030.87No
Cybersecurity Infrastructure Security Agency (CISA)Langflow < 1.9.0 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.420.98No
Weglot API Key - ExposedNetwork Scanner

Medium

N/A
N/A
No