EQST (Experts, Qualified Security Team)
11 exploits
Active since Jun 2024
GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection via give_title
pfSense 2.5.2 - Stored Cross-Site Scripting via $pconfig Variable in interfaces_groups_edit.php
jsonpath-plus < 10.3.0 - Remote Code Execution via Unsafe Eval Mode
Apache Struts 2.0.0-6.3.9 - Path Traversal and Remote Code Execution via File Upload
GiveWP Unauthenticated Donation Process Exploit
lobehub/lobe_chat < 1.19.13 - Server-Side Request Forgery via Redirect Bypass
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
MP3 Audio Player by Sonaar <= 5.7.0.1 - Arbitrary File Deletion via removeTempFiles
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8
GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection via give_title
CVSS 10.0