Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.117 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.975

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File UploadNetwork Scanner

Critical(9.8)

No
LobeHub LobeChat <= 2.1.56 - Server-Side Request ForgeryNetwork Scanner

Medium

No
UniFi Network Application - Path TraversalNetwork Scanner

Critical(10)

No
Dashy <= 4.3.6 - Reflected XSS via WorkspaceNetwork Scanner

Medium(6.1)

No
Samba Printing Subsystem - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Dify < 1.13.0 - Unauthenticated SSRF via Remote File UploadNetwork Scanner

High

No
Cybersecurity Infrastructure Security Agency (CISA)Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCENetwork Scanner

Critical(9.8)

No
FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data DisclosureNetwork Scanner

High(7.5)

No
OpenCATS - Command InjectionNetwork Scanner

High(8.1)

No
mcp-atlassian < 0.17.0 - Server-Side Request ForgeryNetwork Scanner

High(8.2)

No
SiYuan Note <= 3.6.5 - Authentication BypassNetwork Scanner

Critical(9.1)

No
DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
OpenBullet2 <= 0.3.2 - Authentication BypassNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Check Point IKEv1 Remote-Access VPN - Certificate Authentication BypassNetwork Scanner

Critical(10)

No
Campaign Monitor for WordPress - Information DisclosureNetwork Scanner

Medium(5.3)

No
UpdraftPlus WP Backup & Migration Plugin - Authentication BypassNetwork Scanner

High(8.1)

No
Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History APINetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Splunk Enterprise & Cloud Platform - Unrestricted File UploadNetwork Scanner

Critical(9.8)

No
DbGate - Remote Code Execution via Dynamic Import BypassNetwork Scanner

Critical(9.4)

No
Lyrion Music Server <= 9.2.0 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Joomla! JCE extension < 2.9.99.5 unauthenticated RCENetwork Scanner

Critical(10)

No
W3 Total Cache < 2.8.2 - Log File ExposureNetwork Scanner

Medium(5.3)

No
phpMyFAQ <= 4.1.1 - SQL InjectionNetwork Scanner

Critical(9.8)

No
PraisonAI - Authentication BypassNetwork Scanner

High(7.3)

No
WP User Manager – User Profile Builder & Membership - Local File InclusionNetwork Scanner

High(7.5)

No