Vulnerability Intelligence Search Engine vulmon.com Offical Account | Follow @VulmonFeeds for vulnerability feed

Joined November 2017
152 Photos and videos
Vulmon retweeted
9 Jul 2025
Today we published CVE-2025-53548 in response to a vulnerability in our verifyWebhook() helper. It advises those using this helper to upgrade their npm package. Customers we believe were using affected versions were notified yesterday, in advance of the public disclosure. We regret the introduction of this vulnerability and are extremely grateful to the Clerk customer who responsibly disclosed the issue. More details are available here: clerk.com/changelog/2025-07-…
1
1
15
2,847
1 Jul 2025
🚨 Two critical Electron vulns patched: 🔹 CVE-2024-46993 (CVSS: 4.4) — Heap buffer overflow in nativeImage functions 🔹 CVE-2024-46992 (CVSS: 7.8) — ASAR integrity bypass on Windows 👉 Update now! #Electron #Vulmon #Electronjs
1
1
4
441
1 Jul 2025
🚨 CVE-2025-6554: High-severity type confusion vuln in Chrome V8 (pre-138.0.7204.96) allows arbitrary memory access via crafted HTML. Exploit detected in the wild — update now! #CyberSecurity #Vulmon vulmon.com/vulnerabilitydeta…
1
5
1,599
Vulmon retweeted
30 Jun 2025
I published blogs detailing two vulnerabilities I recently discovered in Sudo. Update to 1.9.17p1. CVE-2025-32462 - Sudo Host option Elevation of Privilege Vulnerability stratascale.com/vulnerabilit… CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability stratascale.com/vulnerabilit…

11
81
266
45,554
Vulmon retweeted
Just finished reproducing CVE-2025-32433 and putting together a quick PoC exploit — surprisingly easy. Wouldn’t be shocked if public PoCs start dropping soon. If you’re tracking this, now’s the time to take action. #Erlang #SSH
12
133
425
59,999
9 Apr 2025
🚨 CVE-2024-48887 Fortinet FortiSwitch GUI vuln (CVSS 9.3) A remote attacker can change admin passwords without authentication via the set_password endpoint. Unauthenticated access no verification = full control. #Vulmon #CyberSecurity #Fortinet
1
5
6
791
6 Apr 2025
🚨 WhatsApp for Windows Vulnerability: CVE-2025-30401 A crafted attachment could trick users into running malicious code instead of just opening the file — simply by clicking it inside WhatsApp. #Vulmon #WhatsApp #infosec
1
4
7
763
4 Apr 2025
CVE-2025-22457: Stack-based buffer overflow in Ivanti Connect Secure (≤22.7R2.5), Policy Secure & ZTA Gateways could lead to remote code execution (CVSS 9.0). 🚨 limited exploitation observed. #vulmon #ivanti #infosec
1
2
2
332
4 Apr 2025
Details of CVE-2025-22457: vulmon.com/vulnerabilitydeta…

185
21 Mar 2025
Authorization Bypass Vulnerability in Vercel Next.js: CVE-2025-29927 It is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware. CVSS: 9.1 #Vulmon #React #nextjs #Vercel
1
2
5
951
21 Mar 2025

1
277
18 Mar 2025
🚨 CVE-2025-0755: MongoDB Buffer Overflow Vulnerability 🚨 CVSS Score: 8.4 Affected: 🔹 libbson < 1.27.5 🔹 MongoDB Server < 8.0.1 (v8.0) 🔹 MongoDB Server < 7.0.16 (v7.0) Update now! 🔒 #CyberSecurity #MongoDB #Vulmon
1
2
348
18 Mar 2025
🚀 NASA CryptoLib RCE vulnerabilities impact space communication systems! CryptoLib secures spacecraft-ground station comms using CCSDS SDLS-EP. #CyberSecurity #SpaceTech #Vulmon CVE-2025-29909, CVE-2025-29911, CVE-2025-29912, CVE-2025-29913
1
1
1
262
14 Mar 2025
🚨 CVE-2024-46662 – Fortinet FortiManager Command Execution 🚨 Functional exploits exist! Affected: FortiManager 7.4.1–7.4.3 & FortiManager Cloud 7.4.1–7.4.3 #Fortinet #Infosec #Vulmon
1
9
30
2,991
14 Mar 2025
Details of CVE-2024-46662 vulmon.com/vulnerabilitydeta…

228