Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 15.773 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 170 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 15.773

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
74CMS - Remote File InclusionNetwork Scanner

Critical(9.8)

No
KACE Systems Management Appliance - InstallerNetwork Scanner
N/A
No
VMware vRealize Log Insight < v8.10.2 - Information DisclosureNetwork Scanner

Medium(5.3)

No
Formidable Form Builder < 2.05.03 - Unauthenticated Information DisclosureNetwork Scanner

Medium(5.3)

No
Kramer VIAware - Privilege Escalation and Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Odoo Apps - Cross-Site Scripting via Prototype PollutionNetwork Scanner

High(8.8)

No
Traccar(Windows) 6.1- 6.8.1 - Local File InclusionNetwork Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Microsoft Exchange - Authentication BypassNetwork Scanner

High(7.3)

No
Mitel MiCollab <= 9.8.0.33 - SQL InjectionNetwork Scanner

Critical(9.8)

No
Vite Dev Server - Path TraversalNetwork Scanner

Medium(5.3)

No
Cybersecurity Infrastructure Security Agency (CISA)Zimbra Collaboration Suite < 8.8.15 - Improper EncodingNetwork Scanner

Medium(6.1)

No
Cybersecurity Infrastructure Security Agency (CISA)IBM Data Risk Manager - Authentication Bypass via SAMLNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Cisco vManage (Log4j) - Remote Code ExecutionNetwork Scanner

Critical(10)

No
PrestaShop - SQL Injection to Eval InjectionNetwork Scanner

Critical(9.8)

No
Cybersecurity Infrastructure Security Agency (CISA)Metabase - Remote Code Execution (Apache Log4j)Network Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)JamF (Log4j) - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Redis < 8.2.1 Lua Long-String Delimiter - Out-of-Bounds ReadNetwork Scanner

Medium(6.3)

No
Redis < 8.2.1 lua script - Integer OverflowNetwork Scanner

High(7)

No
Elastic Cloud API KeyNetwork Scanner
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)VMware Operations Manager - Remote Code Execution (Apache Log4j)Network Scanner

Critical(10)

No
Canon Devices - Authentication Bypass in Catwalk ServerNetwork Scanner

High(7.5)

No
Kaseya VSA < 9.5.7 - Arbitrary File Upload to Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
Redis Lua Sandbox < 8.2.2 - Cross-User EscapeNetwork Scanner

Medium(6)

No
Cybersecurity Infrastructure Security Agency (CISA)Ivanti MobileIron (Log4j) - Remote Code ExecutionNetwork Scanner

Critical(10)

No
Cybersecurity Infrastructure Security Agency (CISA)Seeyon OA (Log4j) - Remote Code ExecutionNetwork Scanner

Critical(10)

No