Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.824 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 182 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.824

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Grocy - Default Admin CredentialsNetwork Scanner

High

N/A
N/A
No
SiYuan <= v3.5.9 - SVG Animate Element XSSNetwork Scanner

Medium(6.1)

0.010.09No
PhotoPrism - Unauthenticated ExposureNetwork Scanner

High

N/A
N/A
No
Heimdall - Host Header Injection & Open RedirectNetwork Scanner

Medium(9.8)

0.060.91No
Revive Adserver - Exposed InstallerNetwork Scanner

High

N/A
N/A
No
WordPress Contact Form by Supsystic - Server-Side Template InjectionNetwork Scanner

Critical(9.8)

0.130.94No
NocoBase - VM Sandbox Escape to Remote Code ExecutionNetwork Scanner

Critical(10)

0.060.9No
NetBox - Default Admin CredentialsNetwork Scanner

High

N/A
N/A
No
Heimdall Application Dashboard < 2.7.3 - Reflected XSSNetwork Scanner

Medium(6.1)

0.020.8No
SiYuan Note - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.020.78No
Magento PolyShell – Unauthenticated File Upload to RCENetwork Scanner

Critical

N/A
N/A
No
Heimdall Application Dashboard - Unauthenticated AccessNetwork Scanner

Medium

N/A
N/A
No
Graylog - Default Admin CredentialsNetwork Scanner

High

N/A
N/A
No
SiYuan Note - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.010.37No
Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code ExecutionNetwork Scanner

High(8.8)

0.941No
Vite dev server - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.090.93No
Gradio - Absolute Path TraversalNetwork Scanner

High(7.5)

0.020.8No
Gravity SMTP WordPress Plugin - Sensitive Information ExposureNetwork Scanner

High(7.5)

0.050.9No
Service Finder Bookings - Authentication BypassNetwork Scanner

Critical(9.8)

0.550.99No
Synway SMG Gateway 9-2radius.php - Remote Command ExecutionNetwork Scanner

Critical

N/A
N/A
No
ManageEngine PAM360 - Default CredentialsNetwork Scanner

High(8.3)

N/A
N/A
No
DedeCMS - Open Redirect via download.phpNetwork Scanner

Medium(6.1)

0.110.94No
Google Gemini API Key - ExposureNetwork Scanner

High

N/A
N/A
No
pfSense - Default Admin CredentialsNetwork Scanner

High

N/A
N/A
No
Spring Cloud Config Server - Path TraversalNetwork Scanner

High(8.6)

0.120.94No