Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.079 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.079

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Ivanti Sentry - OS Command InjectionNetwork Scanner

Critical(10)

No
dotCMS Core Publish Audit API - Unauthenticated SQL InjectionNetwork Scanner

Critical

No
UniFi OS Server - Command InjectionNetwork Scanner

Critical(10)

No
WordPress ARMember Premium <= 7.3.1 - Unauthenticated SQL InjectionNetwork Scanner

High(7.5)

No
changedetection.io <= 0.52.9 - Unauthenticated Path TraversalNetwork Scanner

Medium(5.3)

No
Dozzle - Server Side Request ForgeryNetwork Scanner

High(8.6)

No
Milvus - Unauthenticated Metrics API AccessNetwork Scanner

Critical(9.8)

No
PrestaShop lgcookieslaw - SQL InjectionNetwork Scanner

Critical(9.8)

No
phpBB - Authentication bypassNetwork Scanner

Critical(9.4)

No
Starlette - Improper Validation of Unsafe Equivalence in InputNetwork Scanner

Medium(6.5)

No
MLflow < 3.10.0 - Authentication Bypass on FastAPI RoutesNetwork Scanner

High(8.6)

No
Open WebUI 'LDAP Empty Password' - Authentication BypassNetwork Scanner

Critical(9.1)

No
Label Studio < 1.18.0 - Reflected XSSNetwork Scanner

Medium(6.1)

No
YesWiki - Cross-Site ScriptingNetwork Scanner

High

No
Scramble Laravel - Remote Code ExecutionNetwork Scanner

Critical(9.4)

No
E-Learning System 1.0 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path TraversalNetwork Scanner

Critical(10)

No
Bitrix Site Management 2.x - Open RedirectNetwork Scanner

Medium(6.1)

No
WordPress Print Invoice & Delivery Notes for WooCommerce <= 5.8.0 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
DataEase < 2.10.10 - JWT Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)LiteLLM - Command InjectionNetwork Scanner

Critical(9.8)

No
BrightSign Digital Signage 8.2.26 - Server-Side Request ForgeryNetwork Scanner

Medium

No
Open WebUI < 0.9.5 - Information DisclosureNetwork Scanner

Medium(5.3)

No
Cybersecurity Infrastructure Security Agency (CISA)Palo Alto Networks PAN-OS - Authentication BypassNetwork Scanner

Critical(9.1)

No
JoomSport <= 5.7.7 - SQL InjectionNetwork Scanner

Critical(9.3)

No