Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.997 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.997

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
IBM MobileFirst Foundation - Default CredentialsNetwork Scanner
N/A
No
Coveralls Configuration File ExposureNetwork Scanner
N/A
No
Mailcow < 2026-03b - Href Link InjectionNetwork Scanner

Low(3.1)

No
Hoppscotch <= 2026.2.1 - Open RedirectNetwork Scanner

Medium(4.7)

No
OpenCode Web - Unauthenticated AccessNetwork Scanner
N/A
No
DataEase 2.10.4-2.10.7 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Redis Exporter Metrics - ExposureNetwork Scanner
N/A
No
Astro SSR - Server-Side Request ForgeryNetwork Scanner

High(8.6)

No
Apache ActiveMQ 6.x < 6.1.2 - Broken Access ControlNetwork Scanner

High(8.8)

No
Detects Springboot HTTP Exchanges ActuatorNetwork Scanner
N/A
No
Google ADK-Python - Unauthenticated Builder EndpointNetwork Scanner

Critical(9.3)

No
CKAN DataStore SQL Search - SQL InjectionNetwork Scanner

Critical(9.8)

No
MLflow Job API - Authentication BypassNetwork Scanner

Critical(9.1)

No
WordPress Widgets for Social Photo Feed <= 1.8 - Information DisclosureNetwork Scanner

Medium(6.5)

No
XWiki - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Apache Casbin MCP Gateway - Default LoginNetwork Scanner
N/A
No
Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport BypassNetwork Scanner

High(8.8)

No
WordPress OrderConvo < 14 - Path TraversalNetwork Scanner

High(7.5)

No
Supabase Studio - ExposureNetwork Scanner
N/A
No
MajorDoMo - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Vite - Path TraversalNetwork Scanner

Medium(6)

No
ChurchCRM - API Authentication Bypass via URL InjectionNetwork Scanner

Critical(9.1)

No
Spring Framework - Path TraversalNetwork Scanner

Medium(5.9)

No
LMDeploy - Server-Side Request ForgeryNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Langflow < 1.9.0 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No