Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.534 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 179 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.534

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
WP Directory Kit <= 1.4.3 - Unauthenticated SQL InjectionNetwork Scanner

High(7.5)

No
MOVEit Transfer - SQL InjectionNetwork Scanner

Critical(9.1)

No
Cybersecurity Infrastructure Security Agency (CISA)vCenter Server - Improper Access ControlNetwork Scanner

Medium(5.3)

No
ProfileGrid <= 5.7.8 - SQL InjectionNetwork Scanner

Critical(9.3)

No
Melis Technology Melis Platform - Unrestricted File Upload & Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
VMWare Cloud Foundation NSX-V - XML External Entity (XXE)Network Scanner

Critical(9.1)

No
WhatsUp Gold GetStatisticalMonitorList SQL Injection - Authentication BypassNetwork Scanner

Critical(9.8)

No
Laravel Livewire v3 - Remote Command ExecutionNetwork Scanner

Critical(9.8)

No
WP Extended < 3.0.0 - Stored Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
OpenCode < 1.0.216 - Unauthenticated Remote Code ExecutionNetwork Scanner

High(8.8)

No
LatePoint <= 5.0.11 - SQL InjectionNetwork Scanner

Critical(9.8)

No
RustDesk Web Client - Default loginNetwork Scanner
N/A
No
Redis < 8.2.3 - Stack Buffer OverflowNetwork Scanner

High(8.8)

No
XWiki Platform Distribution Flavor Main - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
WordPress H5VP Plugin - Full Path DisclosureNetwork Scanner
N/A
No
WhoDB < 0.45.0 - Path TraversalNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Telnet inetutils - Authentication BypassNetwork Scanner

Critical(9.8)

Yes
Contest Gallery - Broken Access ControlNetwork Scanner

Medium(5.3)

No
GUDE - Default LoginNetwork Scanner
N/A
No
CraftCMS Debug Methods ExposedNetwork Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Citrix StoreFront Server - XML External EntityNetwork Scanner

High(7.5)

No
Zoho ManageEngine ADSelfService Plus 6121 - Username EnumerationNetwork Scanner

Medium(5.3)

No
FreshRSS Fever API - ExposureNetwork Scanner
N/A
No
n8n >= 0.123.0 and < 1.121.3 - Remote Code ExecutionNetwork Scanner

Critical(9.9)

No
WordPress LazyLoad Plugin - Full Path DisclosureNetwork Scanner
N/A
No