L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
qilin10 menções
krybit9 menções
thegentlemen9 menções
Booba Project7 menções
akira7 menções
incransom6 menções
Storm5 menções
rhysida5 menções
play4 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
playBold Spring NurseryUS · Agriculture and Food Production · 2026-10-04
playSilicon Valley GlassUS · Manufacturing · 2026-10-04
emperadorOMUR HIRDAVAT LTDTR · Manufacturing · 2026-10-04
qilinChadwick SwitchboardsAU · Manufacturing · 2026-10-04
qilinEmserES · Manufacturing · 2026-10-04
qilinCotesmaCL · Manufacturing · 2026-10-04
direwolfSoftruckBR · Technology · 2026-10-04
StormNipigon District Memorial HospitalCA · Healthcare · 2026-10-04
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
qilinUnident GroupUS · Other · 2026-10-04
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-95626HIGH

Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce.

AFFECTED SURFACEProduct not specified
CVSS 8.3EPSS 0.28%
CVE-2026-94251MEDIUM

A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resource This issue affects Apache Sling Security Bundle: before 1.3.12. Users are recommended to upgrade to version 1.3.12, which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.19%
CVE-2026-94243HIGH

A vulnerability in Apache Sling Security Bundle: the ReferrerFilter accepts weaker-than-orgin evidence. This issue affects Apache Sling Security Bundle: before 1.3.2. Users are recommended to upgrade to version 1.3.2, which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 7.3EPSS 0.13%
CVE-2026-92001MEDIUM

Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.17%
CVE-2026-91999MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.17%
CVE-2026-91928MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.17%
CVE-2026-91852MEDIUM

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. This issue affects Apache Sling XSS: before 2.4.12. Users are recommended to upgrade to version 2.4.12, which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.21%
CVE-2026-79616LOW

Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.

AFFECTED SURFACEProduct not specified
CVSS 0.6EPSS 0.10%
CVE-2026-73192MEDIUM

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when using the XSSAPI.getValidHref() in Apache Sling XSS version 2.4.10 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack in every feature using this method. In order to successfully attack an application, the attacker needs to be able to submit a value which is not correctly sanitized by that library. Upgrade to Apache Sling XSS >= 2.4.12

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.17%
CVE-2026-95625MEDIUM

The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check compares the manifest's version field against the current version, and that field is unsigned, an attacker who can serve a crafted manifest can force installation of any older signed release without possessing the developer's private key.

AFFECTED SURFACEProduct not specified
CVSS 5.9EPSS 0.16%
CVE-2026-93368HIGH

The Rename wp-login.php to anything you want plugin for WordPress is vulnerable to time-based SQL Injection via 'log' (Username) Parameter in all versions up to, and including, 2.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. WordPress core applies wp_unslash() to the 'log' POST value before dispatching the wp_login_failed action, stripping magic-quotes backslash escaping and allowing a raw single quote to reach the plugin's handler unimpeded.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.30%
CVE-2026-42801HIGH

NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.21%
CVE-2026-31377HIGH

An Improper Authentication vulnerability in the Apache Doris Frontend (FE) meta service allows an unauthenticated remote attacker to access internal metadata service endpoints. The affected endpoints relied on client-supplied node information for authentication without providing sufficient authentication of the requesting party. Under certain network configurations, a remote attacker may be able to bypass the intended access control and access internal FE metadata interfaces, potentially exposing sensitive cluster information. This issue affects Apache Doris: from 2.0.0 through 2.0.*, from 2.1.0 through 2.1.*, from 3.0.0 through 3.0.*, from 3.1.0 through 3.1.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4. Versions 1.2.x and earlier are not affected by this header-trust vulnerability. Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.54%
CVE-2026-15027HIGH

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.

AFFECTED SURFACEProduct not specified
CVSS 8.6EPSS 3.16%
CVE-2026-92378MEDIUM

A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW Online. Under specific timing conditions during Service Offline Emergency Mode, a previously authenticated session may be retained after logout, which could allow a subsequent user to be authenticated as the previous user and gain unauthorised limited access to device functionality.

AFFECTED SURFACEProduct not specified
CVSS 4.1EPSS 0.12%
CVE-2026-91818HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s JavaScript handling of PDF annotations. Reentrant page-event processing during annotation enumeration may release the associated page object, which is subsequently accessed, resulting in an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91817MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of wide strings in embedded PDF JavaScript. Insufficient validation of string-deletion ranges can cause an integer underflow, resulting in an out-of-bounds read and application crash.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.11%
CVE-2026-91816HIGH

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91815HIGH

Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.13%
CVE-2026-91814MEDIUM

A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.11%
CVE-2026-91813HIGH

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.

AFFECTED SURFACEProduct not specified
CVSS 8.8EPSS 0.09%
CVE-2026-91812HIGH

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows man-in-the-middle attackers to bypass certificate validation and package integrity checks, potentially enabling arbitrary code execution with system privileges.

AFFECTED SURFACEProduct not specified
CVSS 7.9EPSS 0.08%
CVE-2026-91811HIGH

A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.

AFFECTED SURFACEProduct not specified
CVSS 7.8EPSS 0.12%
CVE-2026-91810MEDIUM

A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash.

AFFECTED SURFACEProduct not specified
CVSS 6.1EPSS 0.11%