L/BLAB BOTSPUBLIC THREAT INTELLIGENCE NODE
CVE KNOWLEDGE BASE

Intelligence
Explorer.

Investigue vulnerabilidades por identificador, produto afetado ou descrição. Use severidade, CVSS e EPSS juntos para orientar a prioridade.

// THREAT ACTIVITY

Grupos & malware emergente

Atividade pública observada em leak sites e repositórios comunitários. Alegações de vítimas não representam confirmação independente de incidente.

RANSOMWARE GROUPSRECENT CLAIMS
lamashtu10 menções
Storm9 menções
krybit9 menções
thegentlemen9 menções
akira7 menções
Booba Project6 menções
incransom6 menções
qilin5 menções
rhysida5 menções
Wallstreet3 menções
INFOSTEALERSOBSERVED

Sem famílias correlacionadas no recorte recente.

RECENT RANSOMWARE CLAIMSRANSOMWARE.LIVE
krybiteuroditel.comFR · Technology · 2026-10-04
krybitsuperpack.com.coCO · Retail & E-Commerce · 2026-10-04
krybitdaralteb.comIR · Healthcare · 2026-10-04
thegentlemenCenter State EngineeringUS · Manufacturing · 2026-10-04
qilinGenesis Credit ManagementUS · Financial Services · 2026-10-03
netrunnerPrecon Marine Inc— · Transportation · 2026-10-03
rhysidaSkaff Group— · Other · 2026-10-03
WallstreetSt. Francis Healthcare Systems of HawaiiUS · Healthcare · 2026-10-03
WallstreetWorld Cup 2034SA · Other · 2026-10-03
akiraThe Official Collegeof Architects of León (COAL)MX · Professional Services · 2026-10-03
Spiralsseven seas groupAE · Transportation · 2026-10-03
qilinThai Lion AirTH · Transportation · 2026-10-02
MALWARE FAMILIES / 7 DAYSMALWAREBAZAAR
Configure a Auth-Key gratuita do abuse.ch para habilitar detecções recentes do MalwareBazaar.

FONTES: RANSOMWARE.LIVE + MALWAREBAZAAR / ABUSE.CH · CACHE 1H

11641 REGISTROS ENCONTRADOSFEED 2026-09-29
CVE-2026-95529HIGH

Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-95528HIGH

Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-95527MEDIUM

Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.25%
CVE-2026-95525MEDIUM

Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.47%
CVE-2026-95524MEDIUM

Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-95523MEDIUM

Subscriber Bypass Vulnerability in WP User Frontend <= 4.3.11 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.34%
CVE-2026-95522HIGH

Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.6EPSS 0.29%
CVE-2026-95515HIGH

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.18%
CVE-2026-95514MEDIUM

Unauthenticated Bypass Vulnerability in Netgsm <= 2.10.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.3EPSS 0.25%
CVE-2026-95513HIGH

Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.5EPSS 0.26%
CVE-2026-94684MEDIUM

Contributor Cross Site Scripting (XSS) in Ocean Extra <= 2.6.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94682MEDIUM

Contributor Cross Site Scripting (XSS) in Podcast Importer SecondLine <= 1.5.6 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94680MEDIUM

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94679MEDIUM

Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions.

AFFECTED SURFACEProduct not specified
CVSS 5.4EPSS 0.23%
CVE-2026-94671MEDIUM

Contributor Cross Site Scripting (XSS) in The Post Grid <= 7.9.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94500MEDIUM

Contributor Cross Site Scripting (XSS) in ElementsKit Elementor addons Lite <= 4.0.5 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94498MEDIUM

Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.24%
CVE-2026-94487HIGH

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 8.1EPSS 0.13%
CVE-2026-94461MEDIUM

Contributor Cross Site Scripting (XSS) in Ditty <= 3.1.69 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94457MEDIUM

Unauthenticated Bypass Vulnerability in Captcha Code <= 3.32 versions.

AFFECTED SURFACEProduct not specified
CVSS 4.8EPSS 0.19%
CVE-2026-94391MEDIUM

Contributor Cross Site Scripting (XSS) in Ultimate FAQ <= 2.4.14 versions.

AFFECTED SURFACEProduct not specified
CVSS 6.5EPSS 0.17%
CVE-2026-94181HIGH

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

AFFECTED SURFACEProduct not specified
CVSS 7.4EPSS 0.26%
CVE-2026-94179HIGH

Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.19%
CVE-2026-94176HIGH

Unauthenticated Cross Site Scripting (XSS) in Mang Board WP <= 2.4.1 versions.

AFFECTED SURFACEProduct not specified
CVSS 7.1EPSS 0.19%