Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 407

407 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE ID Title CVSS Severity Published
CVE-2014-1761 Microsoft Word 内存损坏漏洞 — n/a 9.8 - 2014-03-24
CVE-2013-7331 Microsoft.XMLDOM ActiveX控件输入验证漏洞 — n/a 5.3 - 2014-02-26
CVE-2014-0502 Adobe Flash Player/Adobe AIR 双重释放漏洞 — n/a 8.8 - 2014-02-21
CVE-2014-0322 Microsoft Internet Explorer 释放后重用漏洞 — n/a 8.8 - 2014-02-14
CVE-2014-0253 Microsoft .NET Framework POST请求DoS漏洞 — n/a 7.5 - 2014-02-12
CVE-2014-0295 Microsoft VSAVB7RT ASLR 漏洞 — n/a 8.1 - 2014-02-12
CVE-2013-1904 RoundCube Webmail ‘generic_message_footer’值任意文件访问漏洞 — n/a 7.5 - 2014-02-08
CVE-2013-7246 Daum Communications DaumGame ActiveX插件缓冲区溢出漏洞 — n/a 9.8 - 2014-01-30
CVE-2013-5211 NTP monlist功能输入验证错误漏洞 — n/a 7.5 - 2014-01-02
CVE-2013-7102 WordPress OptimizePress主题‘media-upload.php’任意文件上传漏洞 — n/a 9.8 - 2013-12-23
CVE-2013-5331 Adobe Flash Player/Adobe AIR 类型混淆漏洞 — n/a 8.8 - 2013-12-11
CVE-2013-5054 Microsoft Office 令牌劫持漏洞 — n/a 9.1 - 2013-12-11
CVE-2013-5057 Microsoft Office 权限许可和访问控制漏洞 — n/a 8.1 - 2013-12-11
CVE-2013-5065 Microsoft Windows 内核中的漏洞可能允许特权提升 — n/a 8.4 - 2013-11-27
CVE-2013-6282 Linux kernel 输入验证漏洞 — n/a 7.1 - 2013-11-19
CVE-2013-3918 Microsoft IE ActiveX控件缓冲区溢出漏洞 — n/a 8.8 - 2013-11-12
CVE-2013-3906 多个Microsoft产品图形组件远程代码执行漏洞 — n/a 8.8 - 2013-11-06
CVE-2011-4106 WordPress Timthumb Plugin timthumb目录任意文件上传漏洞 — n/a 9.8 - 2013-10-26
CVE-2013-6026 D-Link和Planex/路由器Web接口安全漏洞 — n/a 9.1 - 2013-10-19
CVE-2013-6129 vBulletin install/upgrade.php脚本安全漏洞 — n/a 9.8 - 2013-10-19
CVE-2013-3897 Microsoft Internet Explorer内存损坏漏洞 — n/a 7.5 - 2013-10-09
CVE-2013-5576 Joomla! ‘media.php’任意文件上传漏洞 — n/a 8.8 - 2013-10-09
CVE-2013-4854 ISC BIND/DNSco BIND RFC 5011实现拒绝服务漏洞 — n/a 7.5 - 2013-07-26
CVE-2013-1347 Microsoft Internet Explorer 8 远程执行代码漏洞 — n/a 8.1 - 2013-05-05
CVE-2013-1493 Oracle Java SE 2D组件远程代码执行漏洞 — n/a 8.8 - 2013-03-04
CVE-2013-0643 Adobe Flash Player Firefox沙盒任意代码执行漏洞 — n/a 8.8 - 2013-02-27
CVE-2013-0648 Adobe Flash Player ExternalInterface ActionScript功能未明安全漏 — n/a 8.8 - 2013-02-27
CVE-2013-0640 Adobe Reader/Acrobat 未明安全漏洞 — n/a 7.8 - 2013-02-14
CVE-2013-0641 Adobe Reader/Acrobat 未明安全漏洞 — n/a 7.8 - 2013-02-14
CVE-2013-0633 Adobe Flash Player 缓冲区溢出漏洞 — n/a 8.8 - 2013-02-08

Vulnerabilities classified as state:in-the-wild represent 407 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.