Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.597 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 169 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 768

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Cybersecurity Infrastructure Security Agency (CISA)Acronis Cyber Infrastructure - Default PasswordNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet SSL-VPN - Heap-Based Buffer OverflowNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)FreePBX - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Elastic Logstash Multiple Log4j Vulnerabilities (Dec 2021)Network Scanner

Medium(5.9)

No
Cybersecurity Infrastructure Security Agency (CISA)Elastic Logstash Multiple Log4j Vulnerabilities (ESA-2021-31, Log4Shell)Network Scanner

Critical(9)

No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft Sharepoint - Authentication Bypass & Remote Code ExecutionNetwork Scanner

High(8.8)

Yes
Cybersecurity Infrastructure Security Agency (CISA)QNAP Photo Station - Path TraversalNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti Connect Secure - Stack-based Buffer OverflowNetwork Scanner

Critical(9)

No
Cybersecurity Infrastructure Security Agency (CISA)CrushFTP - Authentication Bypass Race ConditionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Schneider Electric U.motion Builder - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)FXC AE1021 / AE1021PE <= 2.0.9 OS Command Injection VulnerabilityNetwork Scanner

High(8.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Cisco Smart Install - Configuration DownloadNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Samsung MagicINFO 9 Server - File Upload & Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Zyxel NAS Multiple Vulnerabilities (Jun/Nov 2023) - Active CheckNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)PTZOptics Camera Multiple Vulnrebilities (Sep 2024) - Active CheckNetwork Scanner

Medium(7.2)

No
Cybersecurity Infrastructure Security Agency (CISA)Fortinet FortiWeb - SQL InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Laravel < 5.6.30 RCE VulnerabilityNetwork Scanner

High(8.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft SharePoint Server - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Yii2 PHP Framework < 2.0.52 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)QNAP QTS Heap-Based Buffer Overflow Vulnerability (QSA-21-02, Baron Samedit)Network Scanner

High(7.8)

No
Cybersecurity Infrastructure Security Agency (CISA)QNAP QuTS hero Heap-Based Buffer Overflow Vulnerability (QSA-21-02, Baron Samedit)Network Scanner

High(7.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Citrix NetScaler - Memory LeakNetwork Scanner

High(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)VMware ESXi SLP - Heap Overflow DoSNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Citrix NetScaler Memory Disclosure - CitrixBleed 2Network Scanner

Critical(7.5)

No
Cybersecurity Infrastructure Security Agency (CISA)Wing FTP Server <= 7.4.3 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No