MB-e37ebac76a05bf37ed2a5037f2457f2212bbbbdb2aaee6950f7bb41dc6ba81f2 |
Unknown: file |
high |
Unknown |
1 |
9 |
|
|
|
URLhaus-PL-23f3ae269c70ab194b6d41e797d4f06b22d7a480e31e24c99586445820944e13 |
URLhaus payload: Mirai (elf) 23f3ae269c70ab19… |
medium |
Mirai |
2 |
10 |
|
|
|
URLhaus-PL-d011b612bea1fd0f2c0ebc85b31fe32e7402727156a8bde880d74f2b3ba0f1e2 |
URLhaus payload: Mirai (elf) d011b612bea1fd0f… |
medium |
Mirai |
2 |
10 |
|
|
|
TF-1868525 |
DCRat: ip:port combination that is used for botnet Command&control (C&C) 172.94.9.104:8080 |
high |
DCRat |
2 |
7 |
|
|
|
TF-1868524 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 165.154.244.107:8084 |
high |
VShell |
2 |
9 |
|
|
|
TF-1868523 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 130.94.66.43:19999 |
high |
VShell |
2 |
8 |
|
|
|
TF-1868522 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 103.251.113.127:8084 |
high |
VShell |
2 |
8 |
|
|
|
TF-1868521 |
ClearFake: Domain name that delivers a malware payload rejcck.pasukan138.de.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-18813 |
H3C NX15 esps delete command injection |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70494 |
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder |
high |
cve |
0 |
0 |
|
|
|
TF-1868520 |
ClearFake: Domain name that delivers a malware payload zwkfwqg.quarkpets.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-13227 |
ERPNext v16.25.0 - Improper authorization in Prospect opportunities API |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70492 |
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages |
high |
cve |
0 |
0 |
|
|
|
TF-1868519 |
Unknown malware: Domain that is used for botnet Command&control (C&C) js-mirror.com |
high |
Unknown malware |
2 |
10 |
|
|
|
TF-1868518 |
Unknown malware: Domain that is used for botnet Command&control (C&C) pypi-get.com |
high |
Unknown malware |
2 |
10 |
|
|
|
MB-0ee5fd727530366a8df72350ece5a43f10c340d907be54d440b2a0bfc26d6cf7 |
Unknown: composer.dat |
high |
Unknown |
1 |
10 |
|
|
|
TF-1868517 |
ClearFake: Domain name that delivers a malware payload quarkpets.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-45538 |
OpenSIPS: Stack Buffer Overflow in sip_to_json() Header Name Copy |
critical |
cve |
0 |
0 |
|
|
|
TF-1868516 |
ClearFake: Domain name that delivers a malware payload i3pwieem.rsfoodproducts.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-15452 |
Smash Balloon Social Photo Feed <= 6.11.3 - Reflected Cross-Site Scripting via REQUEST_URI Query String |
medium |
wordpress-vulnerability |
3 |
1 |
|
|
|
MB-4f3bef1f95a022eaaaea086d9da59df0711908633918f724cf865802b698bf45 |
Unknown: wr.php |
high |
Unknown |
1 |
10 |
|
|
|
TF-1868515 |
Unknown malware: Domain that is used for botnet Command&control (C&C) awqhnjewqjkl.icu |
high |
Unknown malware |
3 |
10 |
|
|
|
TF-1868514 |
Unknown malware: Domain that is used for botnet Command&control (C&C) npm-cache.com |
high |
Unknown malware |
3 |
10 |
|
|
|
TF-1868513 |
Aisuru: ip:port combination that is used for botnet Command&control (C&C) 167.99.64.180:34567 |
high |
Aisuru |
2 |
8 |
|
|
|
CVE-2026-18812 |
H3C NX15 esps esps.ipv6.wan command injection |
high |
cve |
0 |
0 |
|
|
|
MB-371ed87e5c9307f9a4065aeec4e913711b0eb7a0ebd83662583e3e63fec159d3 |
CoinMiner: file |
high |
CoinMiner |
1 |
10 |
|
|
|
MB-e38617f054245a6771e7e475fdd557f9bb85bbcadbb2a7604d67f03f97b8ebc3 |
NanoCore: 234aeb22a6abfbdcc159fc37f1395ab5.exe |
high |
NanoCore |
1 |
10 |
|
|
|
MB-7776fd67b6af82cafcfc309ee5e5ead160667085168eaf4a8b665379447a0174 |
Unknown: WSW0 |
high |
Unknown |
1 |
9 |
|
|
|
TF-1868512 |
ClearFake: Domain name that delivers a malware payload nqxtbf.oopsboobs.com |
high |
ClearFake |
2 |
10 |
|
|
|
MB-83354653829e3fc696d9a23d072ab3f3c0779324c579a010a9a5f6b7097ba2ca |
Unknown: p |
high |
Unknown |
1 |
9 |
|
|
|
CVE-2026-18811 |
H3C NX15 esps add command injection |
high |
cve |
0 |
0 |
|
|
|
MB-5b8cc33eec5651def4b6070e73145bbb11a5dba73e344497165cf528b318259b |
NanoCore: 1c7fad36b892bc9c21e6467252b3cf11.exe |
high |
NanoCore |
1 |
10 |
|
|
|
CVE-2026-65986 |
CVAT has stored XSS via annotation guide assets |
high |
cve |
0 |
0 |
|
|
|
MB-8e5a69334b73f3fb0e415042d6d62fbbdc994e8d7f5d2f989072d6adffad85b5 |
Unknown: wr.php |
high |
Unknown |
1 |
10 |
|
|
|
MB-732d975dd11cc538475be1c8241c8073ae4eec0df32dc1943ede5ae6c1b488ad |
CoinMiner: file |
high |
CoinMiner |
1 |
10 |
|
|
|
MB-7aeaca94df5d44c5b6f28ddf998992ba0c872286bf49e00d7d206405dc910ef4 |
Unknown: file |
high |
Unknown |
1 |
9 |
|
|
|
MB-e3bc0a8afab7b840f83795ad6c5fa64740c7a6bfc96603f9f60cf03cdbde5086 |
Unknown: file |
high |
Unknown |
1 |
9 |
|
|
|
MB-4794369d13f654f8e7d5865733d21e0c34607672c14c3c058846e782ffe118fa |
Unknown: file |
high |
Unknown |
1 |
10 |
|
|
|
CVE-2026-70554 |
MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie |
critical |
cve |
0 |
0 |
|
|
|
MB-ff591fcf9b62bf02aaf8b9f3e64fd14e6eb4d2d4275cffee0aa9cdd863c82840 |
Unknown: lil |
high |
Unknown |
1 |
10 |
|
|
|
MB-b3827b8ada00967779406c10e5a1a5581b73bf7fa78c0fc0b14a601c1258cea9 |
Mirai: x86_64 |
high |
Mirai |
1 |
10 |
|
|
|
MB-683cc89d2030b6cd3f3e8530a4e5e93c9dd5bb43b8b4daa79cdfeebc0de2ec89 |
Mirai: x86_64 |
high |
Mirai |
1 |
10 |
|
|
|
TF-1868511 |
ClearFake: Domain name that delivers a malware payload mwkzudz.qualitycounselingcenter.com |
high |
ClearFake |
2 |
10 |
|
|
|
TF-1868510 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 43.138.135.175:18443 |
high |
VShell |
2 |
7 |
|
|
|
TF-1868509 |
VShell: ip:port combination that is used for botnet Command&control (C&C) 38.55.105.238:8084 |
high |
VShell |
2 |
9 |
|
|
|
TF-1868508 |
ClearFake: Domain name that delivers a malware payload qualitycounselingcenter.com |
high |
ClearFake |
2 |
10 |
|
|
|
CVE-2026-70486 |
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin |
high |
cve |
0 |
0 |
|
|
|
MB-8481b4c44ad96ef389be6d197492fddf6e99f75595c0fc653bde2c8ffc38a820 |
AgentTesla: nDocumentos_de_embarque___BL_e_PL.uue |
high |
AgentTesla |
1 |
10 |
|
|
|
CVE-2026-47682 |
CVAT: Missing path-containment validation in multiple entry points allows arbitrary path writes |
high |
cve |
0 |
0 |
|
|
|
CVE-2026-70485 |
Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs |
high |
cve |
0 |
0 |
|
|
|