Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.095 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.095

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
WordPress MapPress Maps <= 2.96.6 - Unauthenticated IDORNetwork Scanner

Medium(5.3)

0.010.25No
phpMyFAQ <= 4.1.1 - SQL InjectionNetwork Scanner

Critical(9.8)

0.010.21No
WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCENetwork Scanner

Critical(10)

0.010.2No
SiYuan <= v3.6.1 - Path TraversalNetwork Scanner

High(7.5)

0.010.58No
Label Studio < 1.16.0 - Cross-Site ScriptingNetwork Scanner

Medium(5.4)

0.210.96No
Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account TakeoverNetwork Scanner

Critical(9.8)

0.010.51No
Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadNetwork Scanner

High(7.5)

0.010.29No
Langflow <= 1.8.4 - Path Traversal to RCE via File UploadNetwork Scanner

High(8.8)

0.010.11No
WordPress Newsletters <= 4.13 - Unauthenticated SQL InjectionNetwork Scanner

High(7.5)

0.010.22No
WP User Manager – User Profile Builder & Membership - Local File InclusionNetwork Scanner

High(7.5)

0.010.64No
Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula InjectionNetwork Scanner

Critical(9.8)

0.010.56No
PraisonAI - Authentication BypassNetwork Scanner

High(7.3)

0.010.1No
Budibase - Admin InstallerNetwork Scanner

High

N/A
N/A
No
Dgraph <= 25.3.2 - Admin Token DisclosureNetwork Scanner

Critical(9.8)

0.010.46No
PraisonAI AgentOS - Information DisclosureNetwork Scanner

Medium(5.3)

0.010.19No
MuleSoft DataWeave Interactive Learning Environment - Unauthenticated AccessNetwork Scanner

High

N/A
N/A
No
Ivanti Sentry - OS Command InjectionNetwork Scanner

Critical(10)

0.010.45No
dotCMS Core Publish Audit API - Unauthenticated SQL InjectionNetwork Scanner

Critical

0.070.92No
UniFi OS Server - Command InjectionNetwork Scanner

Critical(10)

0.190.96No
changedetection.io <= 0.52.9 - Unauthenticated Path TraversalNetwork Scanner

Medium(5.3)

0.020.82No
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL InjectionNetwork Scanner

High(7.5)

0.250.97No
Dozzle - Server Side Request ForgeryNetwork Scanner

High(8.6)

0.030.87No
Milvus - Unauthenticated Metrics API AccessNetwork Scanner

Critical(9.8)

0.160.95No
PrestaShop lgcookieslaw - SQL InjectionNetwork Scanner

Critical(9.8)

0.210.96No
phpBB - Authentication bypassNetwork Scanner

Critical(9.4)

N/A
N/A
No