Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.908 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 908

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiClientEMS 7.4.4 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)FortiClient EMS - Authentication BypassNetwork Scanner

High(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)DrayTek Vigor - OS Command InjectionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Cisco ISE - Unauthenticated Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Citrix NetScaler SAML IDP - Memory OverreadNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command InjectionNetwork Scanner

High(8.6)

No
Cybersecurity Infrastructure Security Agency (CISA)Aviatrix Controller - Remote Code ExecutionNetwork Scanner

Critical(10)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Hikvision IP camera/NVR - Remote Command ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)HPE OneView - Remote Code ExecutionNetwork Scanner

Critical(10)

Yes
Cybersecurity Infrastructure Security Agency (CISA)MeteoBridge <= 6.1 - Remote Code ExecutionNetwork Scanner

High(7.5)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Apache OFBiz - Improper Authorization & Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Cisco CloudCenter Suite (Log4j) - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)Flexnet - Remote Code Execution (Apache Log4j)Network Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)SNMP Remote Code Execution Vulnerabilities in Cisco IOS Software (cisco-sa-20170629-snmp)Network Scanner

High(8.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Cisco IOS Software Autonomic Networking Infrastructure Denial of Service Vulnerability (cisco-sa-20170726-anidos)Network Scanner

Medium(6.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Cisco IOS Software Cluster Management Protocol Remote Code Execution Vulnerability (cisco-sa-20170317-cmp)Network Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Cisco IOS Software IKEv1 Information Disclosure Vulnerability (cisco-sa-20160916-ikev1)Network Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)SolarWinds Web Help Desk < 12.8.8 Hotfix 1 (HF1) - Security Control BypassNetwork Scanner

High(8.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager - Authentication BypassNetwork Scanner

High(8.6)

No
Cybersecurity Infrastructure Security Agency (CISA)BeyondTrust Remote Support - Unauthenticated WebSocket RCENetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)PHPUnit - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Sophos Firewall <= 19.0 MR1 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCENetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)vCenter Server - Improper Access ControlNetwork Scanner

Medium(5.3)

No