
vFeed IO Vulnerability Intelligence As A Service
@vFeed_IO
Followers
1K
Following
327
Media
368
Statuses
1K
Providing actionable correlated vulnerability & threat intelligence feed.
Anycast server near you
Joined August 2016
vFeed Newsletter July 2025. We present interesting vulnerability trends during the month, critical vulnerabilities to pay attention to, and exploitable vulnerabilities to remediate. Read the full newsletter here: #cybersecurity #vulnerability.
0
2
3
See Rapid7 print hacks. See Rapid7 Brother vulnerabilities.
github.com
Multiple Brother Devices: Multiple Vulnerabilities (CVE-2024-51977, CVE-2024-51978, CVE-2024-51979, CVE-2024-51980, CVE-2024-51981, CVE-2024-51982, CVE-2024-51983, CVE-2024-51984) - sfewer-r7/Broth...
0
0
0
See advisory for more info:
rapid7.com
Multiple Brother Devices: Multiple Vulnerabilities (FIXED) - Rapid7 Blog
1
0
0
vFeed Newsletter June 2025. We present critical vulnerability and exploitability trends during in this month. Read the full newsletter here: #cybersecurity #vulnerability.
0
0
0
Did you know recent Envoy vulnerabilities reveal serious risks: command injection via admin (CVE-2025-24030, EPSS 39.6%), log poison (CVE-2025-25294, EPSS 32.1%), bypass 2FA (CVE-2025-30236, EPSS 24.5%). Patch them now — EPSS scores show real-world exploit potential. #envoyproxy.
1
0
0
CVE-2025-24201.Apple iOS < 17.2.Zero-day in Apple WebKit iOS, Safari. Maliciously crafted web content may be able to break out of Web Content sandbox. Fixed in iOS 18.3.2, iPadOS 18.3.2, Sequoia 15.3.2, Safari 18.3.1 .CVSS3 8.8, Impact 5.9, EPSS 30.24%.
support.apple.com
This document describes the security content of iOS 18.3.2 and iPadOS 18.3.2.
0
0
1
CVE-2025-0912.Donations Widget plugin for WordPress vulnerable to PHP Object Injection, allowing unauthenticated attackers to inject a PHP object, could allows attackers RCE, versions <= 3.19.4.CVSS3 9.8, Impact 5.9, EPSS 43.11%.
wordfence.com
0
0
1
CVE-2025-22867.On Darwin, building a Go module with CGO can trigger arbitrary code execution when using Apple version of ld, due to usage of special values in a cgo LDFLAGS . Affected go1.24rc2.Base 7.5, Impact 3.6, Explot 3.9, EPSS % 0.18.
github.com
cmd/go: arbitrary code execution during build on darwin On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of t...
0
0
1
WordPress plugin critical CVEs with high EPSS percentile of 42% in March. SetSail (CVE-2025-1564).Alloggio (CVE-2025-1638).Academist (CVE-2025-1671). Could lead to unauthorized access, privilege escalation, or data exposure #vulnerability #wordpress.
wordfence.com
0
1
1
vFeed Newsletter February 2025. We analyze vulnerability trends, feature monthly Curiosity questionnaire, EPSS Tracker, K8s vulnerabilities, MITRE CALDERA, AI impact on cyber, threat tools. Read the full newsletter here: #cybersecurity #vulnerability #ai.
1
2
5
CVE-2025-0108.Authn bypass in PAN-OS enables an unauthenticated attacker to use web interface to bypass the authentication. CVSS3 base 8.8, Impact 5.2, Network vector, CWE-306.
security.paloaltonetworks.com
An authentication bypass in the in the management web interface of Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass...
0
1
1
CVE-2025-24016.Wazuh OSS threat detection and prevention servers. Unsafe deserialization vulnerability allows for remote code execution, triggered with API access, versions 4.4.0 .CVSS3 base 9.9, Impact 6.0, Network vector, CWE-502.
github.com
### Summary An unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wa...
0
0
2