L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
thegentlemen26 menções
qilin10 menções
UmBra8 menções
Eclipse5 menções
SilentRansomGroup5 menções
Panzer4 menções
incransom4 menções
Black X3 menções
akira3 menções
arcusmedia3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
DeadlockSaber1US · Not Found · 2026-10-09
Deadlockidi pharmaES · Healthcare · 2026-10-09
safepayhoteldelfinolugano.chCH · Hospitality · 2026-10-09
safepaydwi-bau.deDE · Other · 2026-10-09
PanzerSupreme EnergySG · Energy & Utilities · 2026-10-09
Panzersolutend— · Technology · 2026-10-09
qilinVadeto GroupSE · Not Found · 2026-10-09
rhysidaAnne Arundel CountyUS · Government & Defense · 2026-10-09
threeamfleetworksinc.comUS · Transportation · 2026-10-09
qilinTepcompFI · Technology · 2026-10-09
interlockShalom Christian AcademyUS · Education · 2026-10-09
anubisMynd— · Healthcare · 2026-10-09
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

14535 REGISTROS ENCONTRADOSFEED 2026-10-06
CVE-2026-94684MEDIUM

Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94682MEDIUM

Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94680MEDIUM

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94679MEDIUM

Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.23%
CVE-2026-94671MEDIUM

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94500MEDIUM

Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94498MEDIUM

Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.24%
CVE-2026-94487HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.1EPSS 0.13%
CVE-2026-94461MEDIUM

Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94457MEDIUM

Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.19%
CVE-2026-94391MEDIUM

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94181HIGH

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.26%
CVE-2026-94179HIGH

Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.19%
CVE-2026-94176HIGH

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.19%
CVE-2026-94174HIGH

Administrator SQL Injection in Email Log <= 2.63 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.29%
CVE-2026-94168MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Addons for Elementor <= 4.11.105 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94124HIGH

Contributor SQL Injection in WP EasyCart <= 5.9.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.22%
CVE-2026-94118MEDIUM

Contributor Cross Site Scripting (XSS) in Premium Blocks – Gutenberg Blocks for WordPress <= 2.3.17 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94080MEDIUM

Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-94079MEDIUM

Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.22%
CVE-2026-93774HIGH

Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.19%
CVE-2026-93773HIGH

Contributor SQL Injection in Mollie Forms <= 2.11.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.5EPSS 0.22%
CVE-2026-93772MEDIUM

Subscriber Cross Site Scripting (XSS) in wpForo Forum <= 3.1.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.22%
CVE-2026-93623MEDIUM

Unauthenticated Insecure Direct Object References (IDOR) in AI Engine <= 3.7.8 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.23%