Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.922 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.922

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Chatwoot - InstallationNetwork Scanner

High

No
ionCube Tester Plus <= 1.3 - Local File InclusionNetwork Scanner

High(7.5)

No
esm.sh <= v136 - Arbitrary File Write via Path TraversalNetwork Scanner

Medium(5.3)

No
OpenAM <= 16.0.5 - Pre-Auth RCE via jato.clientSession DeserializationNetwork Scanner

Critical(9.8)

No
Chainlit - Unauthenticated AccessNetwork Scanner

Low

No
Retool Self-Hosted - postMessage XSS via Custom Component CollectionsNetwork Scanner

High

No
Nginx UI - Broken Access ControlNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)SmarterMail - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
AnythingLLM - Username Enumeration via Password RecoveryNetwork Scanner

Medium(5.3)

No
WordPress Madara Theme < 2.2.2.1 - Local File InclusionNetwork Scanner

Critical(9.1)

No
ChromaDB - Unauthenticated API ExposureNetwork Scanner

Medium

No
Vite Dev Server - Arbitrary File ReadNetwork Scanner

High(8.2)

No
Arcane <= 1.17.2 - Server-Side Request ForgeryNetwork Scanner

High(7.2)

No
Vendure Core - SQL InjectionNetwork Scanner

Critical(9.1)

No
Reflected Odoo - Open RedirectNetwork Scanner

Low

No
Cockpit Web Console < 360 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
DbGate Anonymous AccessNetwork Scanner

High

No
Flowise - NVIDIA NIM Endpoints Missing AuthenticationNetwork Scanner

High(8.6)

No
WCAPF WooCommerce Ajax Product Filter - SQL InjectionNetwork Scanner

High(7.5)

No
User Registration & Membership WordPress plugin - Open RedirectNetwork Scanner

Medium(6.1)

No
Team WordPress Plugin (TLP Team) <= 5.0.9 - SQL InjectionNetwork Scanner

High(8.6)

No
LoLLMs WEBUI - Server-Side Request ForgeryNetwork Scanner

Critical(9.1)

No
AstrBot <= 4.22.1 - Command InjectionNetwork Scanner

High(8.8)

No
Cisco Secure Firewall Management Center - Authentication BypassNetwork Scanner

Critical(10)

No
HT Mega < 3.0.7 - Sensitive Information DisclosureNetwork Scanner

High(7.5)

No