Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 408

408 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE ID Title CVSS Severity Published
CVE-2026-77136 Server-Side Template Injection in extension "powermail" (powermail) — Extension "powermail" CWE-1336 9.5 Critical 2026-08-25
CVE-2026-77806 SPIP<4.4.21远程代码执行漏洞 — SPIP CWE-94 9.8 Critical 2026-08-21
CVE-2026-77647 SPIP<4.4.20远程代码执行漏洞 — SPIP CWE-94 9.8 Critical 2026-08-20
CVE-2026-16812 VeloCloud Orchestrator OS Command Injection — VeloCloud Orchestrator On-Prem CWE-78 10.0 Critical 2026-07-27
CVE-2026-64210 net/mlx5e: xsk: Fix unlocked writing to ICOSQ — Linux 7.5 High 2026-07-24
CVE-2026-42566 Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh-wide client decode failure — firmware CWE-20 7.5 High 2026-07-19
CVE-2026-15719 Site isolation issue in the DOM: Navigation component — Firefox - - 2026-07-14
CVE-2026-15718 Invalid pointer in the JavaScript: WebAssembly component — Firefox - - 2026-07-14
CVE-2026-14898 OpenAI Codex Desktop App 信息泄露漏洞 — Codex desktop app for macOS CWE-200 - - 2026-07-06
CVE-2026-54420 LiteSpeed cPanel Plugin 后置链接漏洞 — cPanel Plugin CWE-61 8.5 High 2026-06-14
CVE-2026-48172 LiteSpeed User-End cPanel Plugin 安全漏洞 — cPanel Plugin CWE-266 - - 2026-05-21
CVE-2026-34234 CtrlPanel: Unauthenticated RCE using installer script — panel CWE-78 10.0 Critical 2026-05-19
CVE-2026-44742 Postorius 跨站脚本漏洞 — Postorius CWE-79 7.2 High 2026-05-07
CVE-2026-23866 Facebook WhatsApp 安全漏洞 — WhatsApp for Android 4.3 Medium 2026-05-01
CVE-2026-23863 Facebook WhatsApp 安全漏洞 — WhatsApp Desktop for Windows 6.5 Medium 2026-05-01
CVE-2026-26331 yt-dlp: Arbitrary Command Injection when using the `--netrc-cmd` option — yt-dlp CWE-78 8.8 High 2026-02-24
CVE-2026-25815 Fortinet FortiOS 安全漏洞 — FortiOS CWE-1394 3.2 Low 2026-02-05
CVE-2026-25137 NixOs Odoo database and filestore publicly accessible with default odoo configuration — nixpkgs CWE-552 9.1 Critical 2026-02-02
CVE-2025-70974 Fastjson 安全漏洞 — Fastjson CWE-829 10.0 Critical 2026-01-09
CVE-2025-66644 Array Networks ArrayOS AG 操作系统命令注入漏洞 — ArrayOS AG CWE-78 7.2 High 2025-12-05
CVE-2025-55179 Facebook WhatsApp 安全漏洞 — WhatsApp Business for iOS 5.4 Medium 2025-11-18
CVE-2023-7325 Mingyu Operations and Maintenance Audit and Risk Control System xmlrpc.sock SSRF — Mingyu Operations and Maintenance Audit and Risk Control System CWE-306 9.3 Critical 2025-10-30
CVE-2021-4461 Seeyon Zhiyuan OA Web Application System < 7.0 SP1 Authentication Bypass — Zhiyuan OA Web Application System CWE-306 5.3AI Medium AI 2025-10-30
CVE-2025-43027 Genetec Security Center 安全漏洞 — Genetec Security Center CWE-284 9.8 Critical 2025-10-30
CVE-2016-15048 AMTT HiBOS Command Injection RCE via server_ping.php — Hotel Broadband Operation System (HiBOS) CWE-78 9.8AI Critical AI 2025-10-22
CVE-2023-53691 Hikvision CSMP iSecure Center 安全漏洞 — CSMP iSecure Center CWE-24 8.3 High 2025-10-22
CVE-2024-58274 Hikvision CSMP iSecure Center 安全漏洞 — CSMP iSecure Center CWE-78 8.3 High 2025-10-22
CVE-2018-25118 GeoVision Command Injection RCE via /PictureCatch.cgi — GV-BX1500 CWE-78 9.8AI Critical AI 2025-10-20
CVE-2023-7305 SmartBI RMIServlet Unrestricted File Upload RCE — SmartBI CWE-434 10.0AI Critical AI 2025-10-15
CVE-2011-10033 WordPress Plugin is-human <= v1.4.2 Eval Injection RCE — is-human WordPress Plugin CWE-95 9.8AI Critical AI 2025-10-15

Vulnerabilities classified as state:in-the-wild represent 408 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.