Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.073 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.073

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
QNAP Music Station < 5.4.0 - Authentication BypassNetwork Scanner

Medium(4.3)

No
Oracle WebLogic Server - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
SAP Solution Manager - Open RedirectNetwork Scanner

Medium(6.1)

No
WordPress Custom 404 Pro <= 3.11.1 - Reflected XSSNetwork Scanner

High(7.1)

No
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code ExecutionNetwork Scanner

Critical(10)

Yes
IBM BigFix Platform - Information DisclosureNetwork Scanner

Medium(5.3)

No
Bitrix Site Manager - Log File DisclosureNetwork Scanner

Medium

No
LiteSpeed Cache <= 6.5.0.2 - Stored XSSNetwork Scanner

High(7.1)

No
Beautiful Cookie Consent Banner < 2.10.2 - Cross-Site ScriptingNetwork Scanner

High(7.2)

No
Apache Kvrocks - ExposedNetwork Scanner

High

No
WordPress BuddyPress < 2.9.2 - Authenticated Open RedirectNetwork Scanner

Low

No
GiveWP - Missing Authorization to Settings UpdateNetwork Scanner

Medium(5.3)

No
Metabase Installer - ExposureNetwork Scanner

High

No
X-Backend-Server Header - ExposureNetwork Scanner

Low

No
Munin Monitoring Dashboard - ExposureNetwork Scanner

Medium

No
ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
ZZZCMS ZZZPHP 1.6.3 – Remote PHP Code Execution (RCE)Network Scanner

Critical(9.8)

No
WordPress <= 5.2.4 - Unauthenticated View Private/Draft PostsNetwork Scanner

Medium(5.3)

No
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Microsoft SharePoint - List API DisclosureNetwork Scanner

Low

No
Post Grid <= 2.2.50 - Information Exposure via REST APINetwork Scanner

High(7.5)

No
WP Google Maps < 9.0.48 - Cross-Site ScriptingNetwork Scanner

High(8.8)

No
HT Mega – Absolute Addons for Elementor <= 2.2.0 - Missing Authorization to Privilege EscalationNetwork Scanner

Critical(9.8)

No
elFinder < 2.1.58 - Remote Code ExecutionNetwork Scanner

High(8.1)

No
freeFTPD < 1.0.12 PASS Command Buffer Overflow VulnerabilityNetwork Scanner

Critical(9.8)

No