Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.017 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.017

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
WordPress LiveChat < 3.7.6 - Unauthenticated Stored XSSNetwork Scanner

High

No
Squid Proxy - HTTP Authentication Credentials DisclosureNetwork Scanner

Critical(10)

No
Infinispan - Default Admin LoginNetwork Scanner

High

No
LiteLLM Proxy - Model ExposureNetwork Scanner

Medium

No
phpVMS < 7.0.6 - Legacy Importer Authorization BypassNetwork Scanner

Critical(9.4)

No
Spring Boot Actuator SBOM - ExposureNetwork Scanner

Low

No
MagicMirror <= 2.35.0 - Server-Side Request ForgeryNetwork Scanner

Critical(9.2)

No
Ninja Forms File Uploads <= 3.3.26 - Arbitrary File UploadNetwork Scanner

Critical(9.8)

No
Apache Tomcat Tribes EncryptInterceptor Bypass - Remote Code ExecutionNetwork Scanner

Critical(9.8)

No
dash-uploader 0.1.0 - 0.7.0a2 - Unauthenticated Arbitrary File Write via Path TraversalNetwork Scanner

Critical(9.8)

No
sar2html <=3.2.2 Plot Parameter - Remote Code ExecutionNetwork Scanner

Critical(10)

No
dash-uploader 0.1.0 - 0.7.0a2 - Denial-of-Service via flowTotalChunksNetwork Scanner

High(7.5)

No
EspoCRM <= 9.3.3 - Server-Side Request ForgeryNetwork Scanner

Medium(4.3)

No
Appsmith <= v1.97 - Information DisclosureNetwork Scanner

Medium

No
WordPress Campress Theme <= 1.35 - Unauthenticated Local File InclusionNetwork Scanner

Critical(9.8)

No
LoLLMS WebUI < 9.8 - Path TraversalNetwork Scanner

High(7.5)

No
WordPress Formality Plugin <= 1.5.9 - Local File InclusionNetwork Scanner

Critical(9.8)

No
TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File UploadNetwork Scanner

Critical(9.8)

No
Cloudlog - SQL InjectionNetwork Scanner

High(7.3)

No
ASP.NET Trace.AXD - ExposureNetwork Scanner

Low

No
Tattile Camera < 1.181.5 - Default LoginNetwork Scanner

Critical(9.3)

No
IBM MobileFirst Foundation - Default CredentialsNetwork Scanner

Critical

No
Hoppscotch <= 2026.2.1 - Open RedirectNetwork Scanner

Medium(4.7)

No
Coveralls Configuration File ExposureNetwork Scanner

Medium

No