ToolsVulnerability Scanner
webSlow

Vulnerability Scanner

Template-Based Vulnerability Assessment Engine

"7,000+ signatures scanning for CVEs, misconfigs, exposed panels, and default credentials."

▶ Scan with Vulnerability Scanner
Overview

Vulnerability Scanner is Pentoolkit's flagship vulnerability assessment engine, powered by 7,000+ updated security definitions. Each definition evaluates specific exposure vectors — zero-day CVEs, cloud misconfigurations, exposed administrative panels, and default credentials.

PTK runs Vulnerability Scanner with automated rate-limiting and smart concurrency across your targets. You can filter by severity (only run critical and high templates, skip info) and set a rate limit to avoid overwhelming the target or triggering WAFs.

Scan options
OptionDescriptionEst. time
critical only
Critical severity templates only
~fastest
critical + highDEFAULT
Critical and high templates only
~faster
medium and above
Medium severity and above
~medium
all severities
Run all templates including info/low
~slowest
Example findings
CRITICALCVE-2021-44228 — Log4Shell RCE in Apache Log4j
CRITICALJenkins — Unauthenticated Remote Code Execution
HIGHphpMyAdmin Exposed — Default Credentials Accepted
HIGH.env File Exposed — Contains Database Credentials
What it discovers
  • CVEs in web applications and frameworks
  • Exposed admin panels (phpMyAdmin, Jenkins, Grafana, Kibana)
  • Default credentials on common services
  • API keys and secrets exposed in responses
  • SSRF (Server-Side Request Forgery) vulnerabilities
  • Path traversal vulnerabilities
  • Misconfigured cloud services (S3, Azure, GCP)
  • Exposed .git, .env, backup files
  • Subdomain takeover candidates