L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
thegentlemen26 menções
qilin10 menções
UmBra8 menções
Eclipse5 menções
SilentRansomGroup5 menções
Panzer4 menções
incransom4 menções
Black X3 menções
akira3 menções
arcusmedia3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
DeadlockSaber1US · Not Found · 2026-10-09
Deadlockidi pharmaES · Healthcare · 2026-10-09
safepayhoteldelfinolugano.chCH · Hospitality · 2026-10-09
safepaydwi-bau.deDE · Other · 2026-10-09
PanzerSupreme EnergySG · Energy & Utilities · 2026-10-09
Panzersolutend— · Technology · 2026-10-09
qilinVadeto GroupSE · Not Found · 2026-10-09
rhysidaAnne Arundel CountyUS · Government & Defense · 2026-10-09
threeamfleetworksinc.comUS · Transportation · 2026-10-09
qilinTepcompFI · Technology · 2026-10-09
interlockShalom Christian AcademyUS · Education · 2026-10-09
anubisMynd— · Healthcare · 2026-10-09
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-96548LOW

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

AFFECTED SURFACEProduct not specified
CVSS 2.9EPSS 0.26%
CVE-2026-96546LOW

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. This may cause the plug-in to crash if the byte immediately following the pixel buffer is inaccessible; no information disclosure or code execution has been demonstrated.

AFFECTED SURFACEProduct not specified
CVSS 2.5EPSS 0.11%
CVE-2026-96545MEDIUM

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the larger RGBA row size. This can copy adjacent heap contents into the decoded image and may crash the plug-in.

AFFECTED SURFACEProduct not specified
CVSS 4.4EPSS 0.18%
CVE-2026-96541HIGH

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an attacker can prevent new RDP clients from connecting until a holding socket is closed.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.79%
CVE-2026-95604HIGH

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.33%
CVE-2026-95603HIGH

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.2EPSS 0.40%
CVE-2026-95602MEDIUM

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n/a before 4.46.1.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.28%
CVE-2026-95601CRITICAL

Unauthenticated SQL Injection in Product Filter by WBW <= 3.1.7 versions.

AFFECTED SURFACEProduct not specified
CVSS 9.3EPSS 0.25%
CVE-2026-95600MEDIUM

Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-95593HIGH

Editor SQL Injection in Ultimeter <= 3.0.8 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.29%
CVE-2026-95592MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.24%
CVE-2026-95590HIGH

Subscriber SQL Injection in Tainacan <= 1.2.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.29%
CVE-2026-95586MEDIUM

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.16%
CVE-2026-95530MEDIUM

Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.21%
CVE-2026-95529HIGH

Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-95528HIGH

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-95527MEDIUM

Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.25%
CVE-2026-95525MEDIUM

Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.47%
CVE-2026-95524MEDIUM

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-95523MEDIUM

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.34%
CVE-2026-95522HIGH

Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.29%
CVE-2026-95515HIGH

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-95514MEDIUM

Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-95513HIGH

Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.26%