Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.520 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 868

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)Citrix StoreFront Server - XML External EntityNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Gogs <= 0.13.3 - Remote Code ExecutionNetwork Scanner

High(8.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Grandstream UCM6200 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)SmarterTools SmarterMail - Admin Password ResetNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Digiever DS-2105 Pro - Command InjectionNetwork Scanner

High(8.8)

No
Cybersecurity Infrastructure Security Agency (CISA)FortiOS - Insecure LDAP ConfigurationNetwork Scanner

Medium(6.5)

No
Cybersecurity Infrastructure Security Agency (CISA)QNAP HBS 3 - Broken Access ControlNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)SmarterMail - Unrestricted File UploadNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)VMware NSX SD-WAN Edge - Command InjectionNetwork Scanner

High(8.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra Collaboration Suite - Memcached Command InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra Collaboration - Local File InclusionNetwork Scanner

High(8.8)

No
Cybersecurity Infrastructure Security Agency (CISA)MongoDB Server - Information Disclosure (MongoBleed)Network Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)ThinkPHP < 3.2.4 - Remote Code ExecutionNetwork Scanner

High(8.8)

No
Cybersecurity Infrastructure Security Agency (CISA)HPE OneView - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)Gladinet CentreStack & Triofox - Hardcoded CredentialsNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Zoho ManageEngine ServiceDesk Plus - Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code Execution (React2Shell)Network Scanner

Critical(10)

Yes
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code Execution (CVE-2025-55182 - React2Shell)Network Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiWeb - Authentication Bypass & Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)GeoServer - XML External Entity InjectionNetwork Scanner

High(8.2)

No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra - Cross-Site Scripting via ICS FilesNetwork Scanner

Medium(5.4)

No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft SharePoint Server - Authentication BypassNetwork Scanner

Medium(6.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Oracle Identity Manager REST WebServices - Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)FortiWeb - Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Triofox - Improper Access ControlNetwork Scanner

Critical(9.8)

No