EQSTLab
35 exploits
Active since Feb 2024
GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection via give_title
pfSense 2.5.2 - Stored Cross-Site Scripting via $pconfig Variable in interfaces_groups_edit.php
jsonpath-plus < 10.3.0 - Remote Code Execution via Unsafe Eval Mode
Apache Struts 2.0.0-6.3.9 - Path Traversal and Remote Code Execution via File Upload
GiveWP Unauthenticated Donation Process Exploit
pgAdmin < 8.12 - OAuth2 Credential Exposure
Vendure asset-server-plugin < 2.3.3 and 3.0.0-3.0.5 - Path Traversal and Denial of Service via Malformed URI
Adobe Commerce and Magento - XML External Entity Injection to Code Execution
martinbarker/rendertune 1.1.4 - Cross-Site Scripting via Upload Title Parameter
Ghost 3.24.0-6.19.0 - Info Disclosure
Langflow: Path Traversal in Langflow Knowledge Bases API
Langflow - Path Traversal Arbitrary File Write via upload_user_file
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
n8n 1.65.0-1.120.9 - Unauthenticated Arbitrary File Read via Form-Based Workflow Execution
StrongKey FIDO Server <4.15.1 - RCE
Next.js Middleware Bypass
Apache HTTP Server: mod_http2 denial of service
CVSS 7.5
mathjs 13.1.1-15.1.9 - Remote Code Execution via Expression Parser
CVSS 8.8
Red Hat AMQ Broker 7 - SQL Injection via InlineIdsOrClauseBuilder ID Column
CVSS 8.3
Handlebars.js has JavaScript Injection via AST Type Confusion
CVSS 9.8
MikroORM is vulnerable to SQL Injection via specially crafted object
CVSS 9.8
Sequelize < 6.37.8 - SQL Injection via Unescaped Cast Type in JSON/JSONB Where Clause
CVSS 7.5
Tomcat Partial PUT Java Deserialization
CVSS 9.8
OpenClaw <2026.1.29 - Info Disclosure
CVSS 8.8
React Server Components <19.2.0 - RCE
CVSS 10.0