Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.107 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.107

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
OpenBullet2 <= 0.3.2 - Authentication BypassNetwork Scanner

Critical(9.8)

No
Campaign Monitor for WordPress - Information DisclosureNetwork Scanner

Medium(5.3)

No
SiYuan Note <= 3.6.5 - Authentication BypassNetwork Scanner

Critical(9.1)

No
Cybersecurity Infrastructure Security Agency (CISA)Check Point IKEv1 Remote-Access VPN - Certificate Authentication BypassNetwork Scanner

Critical(10)

No
DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
UpdraftPlus WP Backup & Migration Plugin - Authentication BypassNetwork Scanner

High(8.1)

No
Splunk Enterprise & Cloud Platform - Unrestricted File UploadNetwork Scanner

Critical(9.8)

No
Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History APINetwork Scanner

High(7.5)

No
DbGate - Remote Code Execution via Dynamic Import BypassNetwork Scanner

Critical(9.4)

No
Lyrion Music Server <= 9.2.0 - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
W3 Total Cache < 2.8.2 - Log File ExposureNetwork Scanner

Medium(5.3)

No
Cybersecurity Infrastructure Security Agency (CISA)Joomla! JCE extension < 2.9.99.5 unauthenticated RCENetwork Scanner

Critical(10)

No
Dgraph <= 25.3.2 - Admin Token DisclosureNetwork Scanner

Critical(9.8)

No
SiYuan <= v3.6.1 - Path TraversalNetwork Scanner

High(7.5)

No
Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula InjectionNetwork Scanner

Critical(9.8)

No
WordPress Product Slider Pro for WooCommerce < 3.5.4 - Supply Chain Backdoor RCENetwork Scanner

Critical(10)

No
phpMyFAQ <= 4.1.1 - SQL InjectionNetwork Scanner

Critical(9.8)

No
WordPress MapPress Maps <= 2.96.6 - Unauthenticated IDORNetwork Scanner

Medium(5.3)

No
MuleSoft DataWeave Interactive Learning Environment - Unauthenticated AccessNetwork Scanner

High

No
Budibase - Admin InstallerNetwork Scanner

High

No
PraisonAI - Authentication BypassNetwork Scanner

High(7.3)

No
WP User Manager – User Profile Builder & Membership - Local File InclusionNetwork Scanner

High(7.5)

No
Hippoo Mobile App for WooCommerce <= 1.9.4 - Authentication Bypass to Admin Account TakeoverNetwork Scanner

Critical(9.8)

No
PraisonAI AgentOS - Information DisclosureNetwork Scanner

Medium(5.3)

No
WordPress Newsletters <= 4.13 - Unauthenticated SQL InjectionNetwork Scanner

High(7.5)

No