Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.650 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 169 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.650

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
All Thrive Themes and Plugins - Unauthenticated Option UpdateNetwork Scanner

Medium(5.3)

No
EyesOfNetwork - Hardcoded API Key & SQL InjectionNetwork Scanner

Critical(9.8)

No
Cellinx NVT Web Server - Local File DisclosureNetwork Scanner

High(7.5)

No
Tolgee API - Misconfiguration Anonymous AccessNetwork Scanner

Medium

No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra Collaboration Suite - SSRFNetwork Scanner

High(7.5)

No
EOL Debian OpenSSHNetwork Scanner

Medium

No
Visual Studio Code launch.json ExposureNetwork Scanner

Low

No
Cybersecurity Infrastructure Security Agency (CISA)SonicWall Email Security <= 10.0.9.x - Unauthenticated Admin Account CreationNetwork Scanner

Critical(9.8)

No
Jeg Elementor Kit < 2.5.7 - Unauthenticated Settings UpdateNetwork Scanner

High(8.6)

No
The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication BypassNetwork Scanner

Critical(9.8)

No
mTheme Unus < 2.3 - Directory TraversalNetwork Scanner

High(7.5)

No
Adning Advertising <= 1.5.5 - Arbitrary File UploadNetwork Scanner

Critical(9.8)

No
Spam protection, AntiSpam, FireWall by CleanTalk < 5.153.4 - Unauthenticated Blind SQL InjectionNetwork Scanner

High(7.5)

No
tagDiv Composer < 4.2 - Stored Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Newspaper Theme 6.4–6.7.1 - Privilege EscalationNetwork Scanner

Critical(9.8)

No
wpDiscuz <= 5.3.5 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Teleport - Authentication BypassNetwork Scanner

Critical(9.8)

No
ListingPro < 2.6.1 - Sensitive Data DisclosureNetwork Scanner

Medium(5.3)

No
GoAnywhere - Authentication BypassNetwork Scanner

Critical(10)

No
Form-Maker < 1.15.20 - Unauthenticated Arbitrary File UploadNetwork Scanner

Critical(9.8)

No
Better Search Replace < 1.4.5 - PHP Object InjectionNetwork Scanner

Critical(9.8)

No
ListingPro < 2.6.1 - Arbitrary Plugin Installation/Activation/DeactivationNetwork Scanner

Critical(9.8)

No
D-Link DIR-300 / DIR-600 RCE Vulnerabilities (Feb 2013) - Active CheckNetwork Scanner

Critical(9.8)

No
ProFTPD Backdoor Unauthorized Access Vulnerability (Dec 2010) - Active CheckNetwork Scanner
N/A
No
DELMIA Apriso - Command InjectionNetwork Scanner

Critical(9)

No