L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
qilin12 menções
SilentRansomGroup7 menções
Wallstreet7 menções
everest6 menções
incransom6 menções
Booba Project5 menções
akira5 menções
emperador4 menções
thegentlemen4 menções
Barracuda3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
qilinXICOMX · Not Found · 2026-09-27
qilinIslandCA · Technology · 2026-09-27
qilinRevenga Smart SolutionsES · Technology · 2026-09-27
qilinWillatt & FlickingerUS · Not Found · 2026-09-27
arcusmediaPantaneiro CapasBR · Manufacturing · 2026-09-27
emperadorCar Service AbschleppDE · Transportation · 2026-09-27
StormFirst Secure Bank GroupUS · Financial Services · 2026-09-27
m3rxcipher.systemsUS · Technology · 2026-09-26
BarracudaInternational Chemical Co.— · Manufacturing · 2026-09-26
termiteCrossettUS · Other · 2026-09-26
SilentRansomGroupN...— · Not Found · 2026-09-25
SilentRansomGroupS...— · Not Found · 2026-09-25
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

8621 REGISTROS ENCONTRADOSFEED 2026-09-22
CVE-2026-93978MEDIUM

A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.26%
CVE-2026-93977LOW

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

AFFECTED SURFACEProduct not specified
CVSS 2.0EPSS 0.20%
CVE-2026-93976LOW

A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.

AFFECTED SURFACEProduct not specified
CVSS 1.9EPSS 0.21%
CVE-2026-93975LOW

A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

AFFECTED SURFACEProduct not specified
CVSS 1.9EPSS 0.21%
CVE-2026-86555MEDIUM

The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plaintext in the code. Once the key is obtained, the server information can be decrypted, thus exposing it.

AFFECTED SURFACEProduct not specified
CVSS 6.2EPSS 0.18%
CVE-2026-93974MEDIUM

A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.33%
CVE-2026-93973MEDIUM

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.26%
CVE-2026-93972MEDIUM

A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

AFFECTED SURFACEProduct not specified
CVSS 5.5EPSS 0.27%
CVE-2026-93971MEDIUM

A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.31%
CVE-2026-93970MEDIUM

A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.29%
CVE-2026-86554MEDIUM

SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process. With the obtained SmartLife application authentication parameters, attackers can directly invoke the backend interface /account/verify.serv to determine whether a target email address is registered for a SmartLife account. If the account exists, the real backend account ID can also be retrieved.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.20%
CVE-2026-93969MEDIUM

A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AFFECTED SURFACEProduct not specified
CVSS 6.9EPSS 0.29%
CVE-2026-93968MEDIUM

A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 0.26%
CVE-2026-93967MEDIUM

A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 0.73%
CVE-2026-93966MEDIUM

A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of the argument command leads to command injection. The attack may be launched remotely. The name of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

AFFECTED SURFACEProduct not specified
CVSS 5.1EPSS 1.57%
CVE-2026-92965LOW

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every request to the site rather than only on the administrator's sign-in.

AFFECTED SURFACEProduct not specified
CVSS 3.7EPSS 0.15%
CVE-2026-92541HIGH

The Import and export users and customers WordPress plugin before 2.5.2 does not enforce the promote_users capability in its front-end import functionality, allowing users with only the create_users capability to change the role of existing users, including promoting them to administrator.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.26%
CVE-2026-92540HIGH

The Import and export users and customers WordPress plugin before 2.5.2 does not correctly enforce the promote_users capability when assigning roles during a CSV import, allowing users with only the create_users capability to create new administrator accounts or promote existing users to administrator.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.26%
CVE-2026-92423LOW

The Meow Gallery WordPress plugin before 5.5.5 does not perform a proper capability check or restrict results to the requesting user's own posts before returning post data, allowing authenticated users with Author-level access and above to disclose the titles, authors, dates and statuses of other users' draft and private posts.

AFFECTED SURFACEProduct not specified
CVSS 2.7EPSS 0.19%
CVE-2026-92422MEDIUM

The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it into a shortcode string that it passes to the WordPress shortcode parser on a publicly reachable endpoint, allowing unauthenticated users to execute arbitrary registered shortcodes and disclose non-public gallery content.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.11%
CVE-2026-92410MEDIUM

The Sign-up Sheets WordPress plugin before 2.4.0 does not properly validate the CSRF nonce that protects its sign-up deletion action, allowing attackers to delete sign-up records via a forged request handled in the session of a logged-in user with the required capability.

AFFECTED SURFACEProduct not specified
CVSS 4.3EPSS 0.10%
CVE-2026-87840MEDIUM

The Tripzzy WordPress plugin before 1.5.1 does not perform any capability or ownership checks on its administrative booking-management actions, which are additionally exposed to unauthenticated users and gated only by a token the Tripzzy WordPress plugin before 1.5.1 issues to any anonymous visitor on request, allowing unauthenticated attackers to alter the contents, stored totals and notes of arbitrary bookings.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.18%
CVE-2026-87839HIGH

The Tripzzy WordPress plugin before 1.5.1 does not have authorisation checks, and does not validate the identifier of the object being removed, in an AJAX action available to unauthenticated users, allowing them to permanently delete arbitrary comments on the site.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.21%
CVE-2026-87068MEDIUM

The Forminator Forms WordPress plugin before 1.57.2.1 does not apply the role validation it enforces elsewhere when a registration form is nested inside an imported quiz, allowing a user who may import quizzes to publish a live, publicly reachable form that grants any role, including administrator, to anyone who submits it. The same user is refused an identical form through both the ordinary form editor and the ordinary form import.

AFFECTED SURFACEProduct not specified
CVSS 6.6EPSS 0.21%