Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.836 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 182 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.836

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Gradio - Absolute Path TraversalNetwork Scanner

High(7.5)

No
Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code ExecutionNetwork Scanner

High(8.8)

No
Gravity SMTP WordPress Plugin - Sensitive Information ExposureNetwork Scanner

High(7.5)

No
NetBox - Default Admin CredentialsNetwork Scanner

High

No
Graylog - Default Admin CredentialsNetwork Scanner

High

No
NocoBase - VM Sandbox Escape to Remote Code ExecutionNetwork Scanner

Critical(10)

No
SiYuan Note - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Heimdall Application Dashboard < 2.7.3 - Reflected XSSNetwork Scanner

Medium(6.1)

No
WordPress Contact Form by Supsystic - Server-Side Template InjectionNetwork Scanner

Critical(9.8)

No
SiYuan Note - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Vite dev server - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Heimdall Application Dashboard - Unauthenticated AccessNetwork Scanner

Medium

No
Magento PolyShell – Unauthenticated File Upload to RCENetwork Scanner

Critical

No
Revive Adserver - Exposed InstallerNetwork Scanner

High

No
Synway SMG Gateway 9-2radius.php - Remote Command ExecutionNetwork Scanner

Critical

No
DedeCMS - Open Redirect via download.phpNetwork Scanner

Medium(6.1)

No
Service Finder Bookings - Authentication BypassNetwork Scanner

Critical(9.8)

No
ManageEngine PAM360 - Default CredentialsNetwork Scanner

High(8.3)

No
Google Gemini API Key - ExposureNetwork Scanner

High

No
Cybersecurity Infrastructure Security Agency (CISA)Citrix NetScaler SAML IDP - Memory OverreadNetwork Scanner

Critical(9.8)

No
WordPress Varnish/Nginx Proxy Caching <= 1.8.3 - Information ExposureNetwork Scanner

Medium(5.3)

No
OpenProject - Default Admin CredentialsNetwork Scanner

High

No
Liferay Portal & DXP - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Vite Dev Server - Information ExposureNetwork Scanner

High(7.5)

No
WordPress Hummingbird <= 3.18.0 - Sensitive Information Exposure via Log FileNetwork Scanner

High(7.5)

No