Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities that can be detected with Pentest-Tools.com and the exploits that are currently available in the platform.

We detect more than 11.457 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 147 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 11.457

Pentest-Tools.com Vulnerabilities
Name
CVE
Detectable
with
Detection added
Severity
CVSSv3
score
Exploitable
with Sniper
Qualitor <= 8.24 - Remote Code ExecutionNetwork Scanner

Critical

9.8No
OpenAM<=15.0.3 FreeMarker - Template InjectionNetwork Scanner

High

8.8No
SPIP BigUp Plugin - Remote Code ExecutionNetwork Scanner

Critical

9.8No
Opti Marketing <= 2.0.9 - SQL InjectionNetwork Scanner

Critical

10No
Apache Tomcat 4.x-7.x - Cross-Site ScriptingNetwork Scanner

High

7.2No
Jakarta Tomcat 3.1 and 3.0 - ExposureNetwork Scanner
---
---No
Cybersecurity Infrastructure Security Agency (CISA)Progress Telerik Report Server - Remote Code ExecutionNetwork Scanner

Critical

9.8Yes
Hoverfly < 1.10.3 - Arbitrary File ReadNetwork Scanner

High

7.5No
TrueBooker <= 1.0.2 - SQL InjectionNetwork Scanner

Critical

9.8No
Viral Signup <= 2.1 - SQL InjectionNetwork Scanner

Critical

9.8No
Push Notification for Post and BuddyPress <= 1.93 - SQL InjectionNetwork Scanner

Critical

10No
SmartSearchWP <= 2.4.4 - Unauthenticated Log PurgeNetwork Scanner

Medium

5.3No
Sensei LMS < 4.24.2 - Email Template LeakNetwork Scanner

High

7.5No
Apache HTTPd Windows UNC - Server-Side Request ForgeryNetwork Scanner

High

7.5No
GiveWP Donation Plugin - Remote Code ExecutionNetwork Scanner

Critical

10No
WP AmASIN – The Amazon Affiliate Shop - Local File InclusionNetwork Scanner

Medium

5No
KiviCare WordPress Plugin - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
GLPI 10.0.10-10.0.14 - SQL InjectionNetwork Scanner

High

7.1No
XWiki >= 13.10.8 - Cross-Site ScriptingNetwork Scanner

Medium

6.1No
WhatsUp Gold HasErrors SQL Injection - Authentication BypassNetwork Scanner

Critical

9.8No
Lightdash v0.1024.6 - Server-Side Request ForgeryNetwork Scanner

High

7.3No
Apache OFBiz - Remote Code ExecutionNetwork Scanner

High

7.5No
Cybersecurity Infrastructure Security Agency (CISA)Roundcube - Cross Site ScriptingNetwork Scanner

Medium

6.1No
Hardcoded Admin Credentials For Cisco Smart Licensing Utility APINetwork Scanner

Critical

9.8No
SolarWinds Web Help Desk - Hardcoded CredentialNetwork Scanner

Critical

9.1No