Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.111 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 161 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.111

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
CraftCMS - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Flarum < 1.8.5 - Open RedirectNetwork Scanner

Medium(4.7)

No
iTop - User Enumeration via REST EndpointNetwork Scanner

Medium(5.3)

No
Oracle Retail Xstore Suite - Pre-authenticated Path TraversalNetwork Scanner

High(8.6)

No
Commvault - SSRF via /commandcenter/deployWebpackage.doNetwork Scanner

Critical(10)

No
Emerson Network Power IntelliSlot Web Card - ExposureNetwork Scanner
N/A
No
NocoBase - Default LoginNetwork Scanner
N/A
No
Yacht - Default LoginNetwork Scanner
N/A
No
SAP NetWeaver - BackdoorNetwork Scanner
N/A
No
SAP NetWeaver Visual Composer Metadata Uploader - DeserializationNetwork Scanner

Critical(10)

No
Unraid OS < 7.0.1 Multiple VulnerabilitiesNetwork Scanner

Critical(9.6)

No
Oracle MySQL Server 8.4.0, 9.0.0 Security Update (cpuapr2025) - WindowsNetwork Scanner

Medium(4.9)

No
Discourse < 3.2.1 Multiple VulnerabilitiesNetwork Scanner

Medium(5.3)

No
Joomla! Authentication Bypass Vulnerability (20250402)Network Scanner

High(7.5)

No
NodeBB < 4.0.5 Multiple VulnerabilitiesNetwork Scanner

Medium(6.1)

No
Cybersecurity Infrastructure Security Agency (CISA)TP-Link AX21 Router Devices Multiple Vulnerabilities (Apr 2023)Network Scanner

Critical(9.8)

No
WordPress ProfilePress Plugin < 4.15.19 Information Disclosure VulnerabilityNetwork Scanner

Medium(5.3)

No
WordPress ProfilePress Plugin < 3.2.3 Multiple VulnerabilitiesNetwork Scanner

Medium(6.1)

No
Tiki Wiki CMS Groupware < 21.12, 22.0 < 24.8, 25.0 < 27.2, 28.0 < 28.3 Code Injection VulnerabilityNetwork Scanner

Critical(9.9)

No
Edimax Router Devices Default Credentials (HTTP)Network Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Kentico CMS <= 12.0.14 RCE VulnerabilityNetwork Scanner

Critical(9.8)

No
Cisco Video Surveillance Operations Manager Multiple Vulnerabilities (cisco-sa-20130724-vsm) - Active CheckNetwork Scanner
N/A
No
Canon Printers Buffer Overflow Vulnerability (CP2024-002)Network Scanner

Critical(9.8)

No
D-Link DIR-618 Multiple Vulnerabilities (2025)Network Scanner
N/A
No
Tiki Wiki CMS Groupware <= 27.0 Multiple XSS VulnerabilitiesNetwork Scanner

Medium(4.8)

No