EQSTLab
31 exploits
Active since Feb 2024
Givewp < 3.14.2 - Insecure Deserialization
Netgate Pfsense - XSS
NPM Jsonpath-plus < 10.3.0 - Code Injection
Apache Struts < 6.4.0 - Unrestricted File Upload
GiveWP Unauthenticated Donation Process Exploit
Pgadmin 4 < 8.12 - Insufficiently Protected Credentials
Vendure Asset-server-plugin < 2.3.3 - Path Traversal
CosmicSting: Magento Arbitrary File Read (CVE-2024-34102) + PHP Buffer Overflow in the iconv() function of glibc (CVE-2024-2961)
RenderTune 1.1.4 - XSS
Langflow - Path Traversal Arbitrary File Write via upload_user_file
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
N8n < 1.121.0 - Improper Input Validation
Next.js Middleware Bypass
StrongKey FIDO Server <4.15.1 - RCE
Hibernate - SQL Injection
CVSS 8.3
Handlebars.js has JavaScript Injection via AST Type Confusion
CVSS 9.8
MikroORM is vulnerable to SQL Injection via specially crafted object
CVSS 9.8
Sequelize <6.37.8 - SQL Injection
CVSS 7.5
Tomcat Partial PUT Java Deserialization
CVSS 9.8
OpenClaw <2026.1.29 - Info Disclosure
CVSS 8.8
React Server Components <19.2.0 - RCE
CVSS 10.0
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8
Nteract <0.28.0 - RCE
CVSS 9.8
Beekeeper Studio <4.1.13 - XSS
CVSS 6.1
Lukasbach Yana < 1.0.16 - XSS
CVSS 9.6