Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.269 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 177 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.127

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
User Role Editor - Full Path DisclosureNetwork Scanner

Low

No
Bash Configuration - ExposureNetwork Scanner

Low

No
WordPress Easy Digital Downloads <= 3.2.12 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Rails/Ruby Console History - ExposureNetwork Scanner

Medium

No
phpLDAPadmin <= 1.2.3 - Reflected XSSNetwork Scanner

Medium(6.1)

No
WordPress Newsletter - Log File ExposureNetwork Scanner

Medium

No
LibreChat <= 0.7.9 - HTML Injection via Accept-Language HeaderNetwork Scanner

Medium(5.4)

No
Makefile - ExposureNetwork Scanner

Low

No
Zimbra Collaboration - Local File InclusionNetwork Scanner

High(8.8)

No
Kaswara Modern VC Addons <= 3.0.1 - Missing AuthorizationNetwork Scanner

High(7.3)

No
Flow Configuration - ExposureNetwork Scanner

Medium

No
Cybersecurity Infrastructure Security Agency (CISA)MongoDB Server - Information Disclosure (MongoBleed)Network Scanner

High(7.5)

No
WordPress Custom Post Type UI - Full Path DisclosureNetwork Scanner

Medium

No
YITH WooCommerce Ajax Search <= 2.4.0 - Cross-Site ScriptingNetwork Scanner

High(7.2)

No
JFrog Artifactory Build - ExposureNetwork Scanner

Medium

No
Roundcube Webmail Installer - ExposureNetwork Scanner

High

No
Ultimate Addons for Elementor <= 1.24.1 - Registration BypassNetwork Scanner

High(7.2)

No
AWStats <= 7.5 - Full Path DisclosureNetwork Scanner

Medium(5.3)

No
Jetpack < 6.5 - Stored Cross-Site ScriptingNetwork Scanner

Medium

No
Social Auto Poster <= 5.3.14 - Stored Cross-Site ScriptingNetwork Scanner

High(7.2)

No
Kubernetes API Server - YAML Parsing DoS (Billion Laughs)Network Scanner

High(7.5)

No
Python Requirements File DisclosureNetwork Scanner

Medium

No
Instagram Feed < 1.6 - Cross-Site ScriptingNetwork Scanner

Medium

No
Emby Server - Authentication BypassNetwork Scanner

Critical(9.1)

No
WordPress Plugin iThemes Security - Full Path DisclosureNetwork Scanner

Low

No