Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.908 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.908

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
DbGate Anonymous AccessNetwork Scanner

High

No
Cockpit Web Console < 360 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Reflected Odoo - Open RedirectNetwork Scanner

Low

No
User Registration & Membership WordPress plugin - Open RedirectNetwork Scanner

Medium(6.1)

No
AstrBot <= 4.22.1 - Command InjectionNetwork Scanner

High(8.8)

No
Flowise - NVIDIA NIM Endpoints Missing AuthenticationNetwork Scanner

High(8.6)

No
Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL InjectionNetwork Scanner

High(8.6)

No
LoLLMs WEBUI - Server-Side Request ForgeryNetwork Scanner

Critical(9.1)

No
WCAPF WooCommerce Ajax Product Filter - SQL InjectionNetwork Scanner

High(7.5)

No
Cisco Secure Firewall Management Center - Authentication BypassNetwork Scanner

Critical(10)

No
HT Mega < 3.0.7 - Sensitive Information DisclosureNetwork Scanner

High(7.5)

No
Geo Mashup <= 1.13.17 - SQL InjectionNetwork Scanner

High(7.5)

No
AstrBot - Default LoginNetwork Scanner

High

No
ComfyUI-Manager < 3.38 - Configuration OverwriteNetwork Scanner

Critical(9.8)

No
WordPress CBX Bookmark & Favorite Plugin <= 2.0.4 - SQL InjectionNetwork Scanner

Critical(9.1)

No
FreeScout Installer ExposureNetwork Scanner

High

No
Spring Framework Path Traversal in Functional Web FrameworksNetwork Scanner

High(7.5)

No
EventON Lite <= 2.4 - Authenticated Local File InclusionNetwork Scanner

High(8.8)

No
WordPress WPCOM Member <= 1.7.6 - SQL InjectionNetwork Scanner

High(7.5)

No
WSO2 - Server Side Request ForgeryNetwork Scanner

Medium(5.9)

No
Leantime - Unfinished InstallationNetwork Scanner

High

No
Devtron JavaScript Environment Configuration - ExposureNetwork Scanner

Low

No
AntD Admin - Sensitive Information DisclosureNetwork Scanner

High(7.5)

No
WordPress File Manager <= 7.2.1 - Directory TraversalNetwork Scanner

Critical(9.9)

No
Chanjet CRM - SQL InjectionNetwork Scanner

High

No