Resources

Vulnerability & Exploit Database

This is the list of vulnerabilities you can detect with Pentest-Tools.com and the exploits currently available in the platform.

We detect more than 17.125 vulnerabilities with multiple tools (Network Scanner, Website Scanner, Wordpress Scanner, and more) and we also have 190 exploit modules in Sniper to validate the risk level of critical CVEs.

Display

Displaying 1 - 25 results out of 17.125

Pentest-Tools.com Vulnerabilities
Name
Detectable with
Detection added
CVSSv3
EPSS Score
EPSS Percentile
Exploitable
with Sniper
Dahua ICC Default LoginNetwork Scanner

High

N/A
N/A
No
Weaver Ecology ExecForStr Remote Command ExecutionNetwork Scanner

Critical

N/A
N/A
No
Weaver E-cology getEmDsList Sensitive Information DisclosureNetwork Scanner

High

N/A
N/A
No
Weaver E-cology9 api/doc/out/more/list SQL InjectionNetwork Scanner

High

N/A
N/A
No
motionEye Partial - Authentication BypassNetwork Scanner

Critical

N/A
N/A
No
Xerte Online Toolkits <= 3.15 - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.030.85No
FOSSBilling - Server-Side Template InjectionNetwork Scanner

Critical

0.020.77No
Open SOCKS4/SOCKS5 proxyNetwork Scanner

Medium

N/A
N/A
No
Gogs < 0.14.3 - Unauthenticated Organization Teams DisclosureNetwork Scanner

Medium(4.3)

0.020.73No
Magento 2 Amasty Order Attributes < 4.0.0 - Unauthenticated Arbitrary File UploadNetwork Scanner

Critical(9.8)

0.040.89No
Dashy <= 4.3.6 - Reflected XSS via WorkspaceNetwork Scanner

Medium(6.1)

N/A
N/A
No
UniFi Network Application - Path TraversalNetwork Scanner

Critical(10)

0.160.97No
LobeHub LobeChat <= 2.1.56 - Server-Side Request ForgeryNetwork Scanner

Medium(9)

0.020.76No
Samba Printing Subsystem - Remote Code ExecutionNetwork Scanner

Critical(9.8)

0.130.96No
Dify < 1.13.0 - Unauthenticated SSRF via Remote File UploadNetwork Scanner

High

N/A
N/A
No
Cybersecurity Infrastructure Security Agency (CISA)Oracle PeopleSoft PeopleTools PSEMHUB - Pre-Auth Java Deserialization RCENetwork Scanner

Critical(9.8)

0.91No
FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data DisclosureNetwork Scanner

High(7.5)

0.010.26No
mcp-atlassian < 0.17.0 - Server-Side Request ForgeryNetwork Scanner

High(8.2)

0.140.96No
OpenCATS - Command InjectionNetwork Scanner

High(8.1)

0.230.98No
Cybersecurity Infrastructure Security Agency (CISA)Check Point IKEv1 Remote-Access VPN - Certificate Authentication BypassNetwork Scanner

Critical(10)

0.721No
SiYuan Note <= 3.6.5 - Authentication BypassNetwork Scanner

Critical(9.1)

0.010.45No
DokuWiki <= 2025-05-14a Librarian - Reflected Cross-Site ScriptingNetwork Scanner

Medium(6.1)

0.020.67No
Campaign Monitor for WordPress - Information DisclosureNetwork Scanner

Medium(5.3)

0.010.54No
OpenBullet2 <= 0.3.2 - Authentication BypassNetwork Scanner

Critical(9.8)

0.020.72No
UpdraftPlus WP Backup & Migration Plugin - Authentication BypassNetwork Scanner

High(8.1)

0.030.86No