Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.073 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 177

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)React Server Components - Remote Code ExecutionNetwork Scanner

Critical(10)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiWeb - Authentication Bypass & Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
WordPress Simple File List - Unauthenticated RCENetwork Scanner

Critical(9.8)

Yes
React Native Community CLI development server - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
ASP.NET Core - Request SmugglingNetwork Scanner

Critical(9.9)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Oracle E-Business Suite - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Magento & Adobe Commerce - Account TakeoverNetwork Scanner

Critical(9.1)

Yes
Cybersecurity Infrastructure Security Agency (CISA)FreePBX - Authentication Bypass leading to SQL Injection & Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Fortinet FortiSIEM - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Microsoft Sharepoint - Authentication Bypass & Remote Code ExecutionNetwork Scanner

High(8.8)

Yes
SSH user enumerationNetwork Scanner

Medium(5.3)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Endpoint Manager Mobile - Remote Code ExecutionNetwork Scanner

High(7.5)

Yes
Wordpress TemplateInvaders - Arbitrary File UploadNetwork Scanner

Critical(10)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Craft CMS - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
SMB - Anonymous Write AccessNetwork Scanner

Critical(9.8)

Yes
SMB - Anonymous AccessNetwork Scanner

High(8.2)

Yes
Zyxel - Default credentialsNetwork Scanner

Critical(9.8)

Yes
WordPress WP File Upload Plugin - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Zyxel - Telnet Command InjectionNetwork Scanner

High(8.8)

Yes
Wordpress WP Query Console - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Craft CMS - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes
Wordpress Really Simple Security - Authentication BypassNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)Cleo Harmony, VLTrader and LexiCom - Arbitrary File Read and WriteNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)ProjectSend - Authentication BypassNetwork Scanner

Critical(9.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)CyberPanel - Remote Code ExecutionNetwork Scanner

Critical(9.8)

Yes