Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 16.828 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 182 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 16.686

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
Severity
Exploitable
with Sniper
Piwik/Matomo - Unauthenticated AccessNetwork Scanner

High

No
Mirth Connect - Default Admin CredentialsNetwork Scanner

Critical

No
SiYuan <= v3.6.1 - Bookmark Data DisclosureNetwork Scanner

High(7.5)

No
Symfony HttpFoundation - Access Control Bypass via PATH_INFONetwork Scanner

High(7.3)

No
NocoDB - User EnumerationNetwork Scanner

Medium(5.3)

No
Pi-hole Reflected XSS in 404-Error PageNetwork Scanner

Medium(6.1)

No
SiYuan <= v3.5.9 - SVG Animate Element XSSNetwork Scanner

Medium(6.1)

No
Grocy - Default Admin CredentialsNetwork Scanner

High

No
PhotoPrism - Unauthenticated ExposureNetwork Scanner

High

No
Heimdall - Host Header Injection & Open RedirectNetwork Scanner

Medium(9.8)

No
Heimdall Application Dashboard - Unauthenticated AccessNetwork Scanner

Medium

No
SiYuan Note - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
Revive Adserver - Exposed InstallerNetwork Scanner

High

No
Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code ExecutionNetwork Scanner

High(8.8)

No
Gradio - Absolute Path TraversalNetwork Scanner

High(7.5)

No
NetBox - Default Admin CredentialsNetwork Scanner

High

No
WordPress Contact Form by Supsystic - Server-Side Template InjectionNetwork Scanner

Critical(9.8)

No
Gravity SMTP WordPress Plugin - Sensitive Information ExposureNetwork Scanner

High(7.5)

No
Magento PolyShell – Unauthenticated File Upload to RCENetwork Scanner

Critical

No
Heimdall Application Dashboard < 2.7.3 - Reflected XSSNetwork Scanner

Medium(6.1)

No
Graylog - Default Admin CredentialsNetwork Scanner

High

No
Vite dev server - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
SiYuan Note - Cross-Site ScriptingNetwork Scanner

Medium(6.1)

No
NocoBase - VM Sandbox Escape to Remote Code ExecutionNetwork Scanner

Critical(10)

No
DedeCMS - Open Redirect via download.phpNetwork Scanner

Medium(6.1)

No