Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.933 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.933

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
MajorDoMo - Unauthenticated RCENetwork Scanner

Critical(10)

No
Krayin CMS - InstallerNetwork Scanner

High

No
Tandoor Recipes < 1.5.24 - Jinja2 SSTI RCENetwork Scanner

Critical(9.9)

No
DataEase - Remote Code ExecutionNetwork Scanner

High(9.8)

No
Avaya Phone Web Interface - Default LoginNetwork Scanner

High

No
Exposed Prisma Database Schema - ExposureNetwork Scanner

Medium

No
Odoo <= 15.0 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Download Monitor < 1.9.7 - Unauthenticated Download Log ExportNetwork Scanner

High

No
Easy Appointments <= 3.12.21 - Unauthenticated Sensitive Information ExposureNetwork Scanner

High(7.5)

No
WP Directory Kit <= 1.4.4 - Authentication BypassNetwork Scanner

Critical(10)

No
Apache SkyWalking - DashboardNetwork Scanner

High

No
ionCube Tester Plus <= 1.3 - Local File InclusionNetwork Scanner

High(7.5)

No
Chatwoot - InstallationNetwork Scanner

High

No
Vendure Core - SQL InjectionNetwork Scanner

Critical(9.1)

No
Retool Self-Hosted - postMessage XSS via Custom Component CollectionsNetwork Scanner

High

No
Vite Dev Server - Arbitrary File ReadNetwork Scanner

High(8.2)

No
Cybersecurity Infrastructure Security Agency (CISA)SmarterMail - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
ChromaDB - Unauthenticated API ExposureNetwork Scanner

Medium

No
AnythingLLM - Username Enumeration via Password RecoveryNetwork Scanner

Medium(5.3)

No
WordPress Madara Theme < 2.2.2.1 - Local File InclusionNetwork Scanner

Critical(9.1)

No
Chainlit - Unauthenticated AccessNetwork Scanner

Low

No
esm.sh <= v136 - Arbitrary File Write via Path TraversalNetwork Scanner

Medium(5.3)

No
Nginx UI - Broken Access ControlNetwork Scanner

Critical(9.8)

No
OpenAM <= 16.0.5 - Pre-Auth RCE via jato.clientSession DeserializationNetwork Scanner

Critical(9.8)

No
Arcane <= 1.17.2 - Server-Side Request ForgeryNetwork Scanner

High(7.2)

No