Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.155 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 164 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.155

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
WordPress XStore Theme - SQL InjectionNetwork Scanner

Critical(9.3)

No
Quest KACE SMA /common/run_cross_report.php 'fmt' XSSNetwork Scanner

Medium(6.1)

No
Evertz SDVN 3080ipx-10G - Unauthenticated Arbitrary Command InjectionNetwork Scanner

Critical(9.3)

No
DataEase v2.10.2 - JWT Signature Verification BypassNetwork Scanner

Critical(9.1)

No
Kyocera Net View Address Book ExposureNetwork Scanner

High(8.6)

No
OptinMonster Plugin < 2.6.5 - Unprotected REST-APINetwork Scanner

High(8.2)

No
PHPSHE 1.7 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Avaya Aura Device Services - OS Command InjectionNetwork Scanner

High(8.6)

No
Spring Data REST < 2.6.9 (Ingalls SR9) / 3.0.1 (Kay SR1) - PATCH Request Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Boa 0.94.13 - Information DisclosureNetwork Scanner

High(7.5)

No
Synology BeeStation BST150-4T - Unauthenticated Command InjectionNetwork Scanner

Critical(9.8)

No
Schneider Electric APC NMC - Default LoginNetwork Scanner
N/A
No
Abandoned Cart Lite for WooCommerce - Authentication BypassNetwork Scanner

Critical(9.8)

No
SonLogger - Arbitrary File UploadNetwork Scanner

Critical(9.8)

No
LabKey Server 19.1.0 - XML External Entity (XXE)Network Scanner

High(7.5)

No
D-Link Central WiFi Manager CWM(100) - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Ruckus vRioT IoT Controller - Authentication BypassNetwork Scanner

Critical(9.8)

No
Siemens SIMATIC 300 Dashboard - ExposedNetwork Scanner
N/A
No
WPGraphQL 0.2.3 - User CreationNetwork Scanner

Critical(9.8)

No
PrestaShop 'possearchproducts' <= 1.7 - SQL InjectionNetwork Scanner

Critical(9.8)

No
SRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL InjectionNetwork Scanner

High(7.5)

No
FortiWLM - Directory TraversalNetwork Scanner

Critical(9.8)

No
TotoLink Router setMacFilterRules - Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)D-Link DIR-605 - Information DisclosureNetwork Scanner

High(7.5)

No
SolarWinds Security Event Manager - Unauthenticated RCENetwork Scanner

High(8.8)

No