Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities that can be detected with Pentest-Tools.com and the exploits that are currently available in the platform.

We detect more than 11.169 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 131 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 11.169

Pentest-Tools.com Vulnerabilities
Name
CVE
Detectable
with
Detection added
Severity
CVSSv3
score
Exploitable
with Sniper
CData Sync < 23.4.8843 - Path TraversalNetwork Scanner

High

8.6No
Mura/Masa CMS - SQL InjectionNetwork Scanner

High

---No
CData Arc < 23.4.8839 - Path TraversalNetwork Scanner

High

8.6No
Combo Blocks < 2.2.76 - Improper Access ControlNetwork Scanner

Medium

---No
mooSocial v.3.1.8 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
Import XML and RSS Feeds < 2.1.5 - Unauthenticated RCENetwork Scanner

High

9.8No
eyoucms v.1.6.5 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
Avada < 7.11.7 - Information DisclosureNetwork Scanner

Medium

5.3No
WordPress Toolbar <= 2.2.6 - Open RedirectNetwork Scanner

Medium

6.1No
Cybersecurity Infrastructure Security Agency (CISA)CrushFTP VFS - Sandbox Escape LFRNetwork Scanner

High

10No
PrestaShop PireosPay - SQL InjectionNetwork Scanner

High

8.8No
Wordpress Email Subscribers by Icegram Express - SQL InjectionNetwork Scanner

High

---No
PrestaShop Step by Step products Pack - SQL InjectionNetwork Scanner

High

9.8No
PrestaShop AdvancedPopupCreator - SQL InjectionNetwork Scanner

High

9.8No
WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File UploadNetwork Scanner

High

9.8No
MasterStudy LMS <= 3.3.3 - Unauthenticated Local File Inclusion via templateNetwork Scanner

High

9.8No
Magento - SQL InjectionNetwork Scanner

High

9.8No
JetBrains TeamCity > 2023.11.3 - Authentication BypassNetwork Scanner

High

9.8No
NextGen Healthcare Mirth Connect - Remote Code ExecutionNetwork Scanner

High

9.8No
Academy LMS 6.0 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
EventON (Free < 2.2.8, Premium < 4.5.5) - Information DisclosureNetwork Scanner

Medium

5.3No
SuperWebMailer 9.31.0.01799 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
CData API Server < 23.4.8844 - Path TraversalNetwork Scanner

High

9.8No
Netmaker - Hardcoded DNS Secret KeyNetwork Scanner

High

7.5No
WordPress Automatic Plugin <= 3.92.0 - SQL InjectionNetwork Scanner

High

9.9No