EQSTLab
35 exploits
Active since Feb 2024
Langflow AI - Unauthenticated Remote Code Execution
CVSS 9.8
nteract 0.28.0 - Remote Code Execution via Markdown Link
CVSS 9.8
mjml_app 3.0.4 and 3.1.0-beta - Remote Code Execution via Href Attribute
CVSS 9.3
Deskfiler 1.2.3 - Remote Code Execution via Crafted Plugin Upload
CVSS 9.8
Another Redis Desktop Manager <= 1.6.1 - Cross-Site Scripting in Setting Component
CVSS 9.6
Beekeeper Studio <= 4.1.13 - Cross-Site Scripting in Database Table Column Name
CVSS 6.1
Advanced REST Client 17.0.9 - Cross-Site Scripting via New Project Edit Details Parameter
CVSS 4.7
yana <= 1.0.16 - Cross-Site Scripting via src/electron-main.ts
CVSS 9.6
GiveWP Unauthenticated Donation Process Exploit
CVSS 9.8
GiveWP <= 3.14.1 - Unauthenticated PHP Object Injection via give_title
CVSS 10.0