Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 407

407 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE ID Title CVSS Severity Published
CVE-2025-30355 Synapse vulnerable to federation denial of service via malformed events — synapse CWE-20 7.1 High 2025-03-27
CVE-2025-30349 IMP 安全漏洞 — IMP CWE-79 7.2 High 2025-03-21
CVE-2025-30259 WhatsApp 安全漏洞 — WhatsApp cloud service 3.5 Low 2025-03-19
CVE-2025-27363 FreeType 缓冲区错误漏洞 — FreeType 8.1 High 2025-03-11
CVE-2025-24888 Path traversal in SecureDrop Client API.download_reply() — securedrop-client CWE-22 8.1 High 2025-02-13
CVE-2025-1146 CrowdStrike Falcon Sensor for Linux TLS Issue — Falcon sensor for Linux CWE-296 8.1 High 2025-02-12
CVE-2025-24085 Apple iOS和Apple iPadOS 资源管理错误漏洞 — iOS and iPadOS 7.8 - 2025-01-27
CVE-2024-12847 NETGEAR DGN setup.cgi OS Command Injection — DGN1000 CWE-78 9.8 Critical 2025-01-10
CVE-2024-44309 Apple iOS和Apple iPadOS 安全漏洞 — Safari 6.1AI Medium AI 2024-11-19
CVE-2024-44308 Apple iOS和Apple iPadOS 安全漏洞 — Safari 8.8AI High AI 2024-11-19
CVE-2024-4741 Use After Free with SSL_free_buffers — OpenSSL CWE-416 9.8 - 2024-11-13
CVE-2024-51567 CyberPanel 安全漏洞 — n/a 10.0 Critical 2024-10-29
CVE-2024-51378 CyberPanel 安全漏洞 — n/a 10.0 Critical 2024-10-29
CVE-2021-4444 Product Filter by WooBeWoo <= 1.4.9 - Missing Authorization — Product Filter for WooCommerce by WBW CWE-862 7.3 High 2024-10-16
CVE-2024-47763 Wasmtime runtime crash when combining tail calls with trapping imports — wasmtime CWE-670 5.5 Medium 2024-10-09
CVE-2024-9680 Mozilla Firefox 安全漏洞 — Firefox 8.8 - 2024-10-09
CVE-2024-45506 HAProxy 安全漏洞 — n/a 7.5AI High AI 2024-09-04
CVE-2024-45389 Pagefind DOM clobbering could escalate to Cross-site Scripting (XSS) — pagefind CWE-79 6.4 Medium 2024-09-03
CVE-2024-42252 closures: Change BUG_ON() to WARN_ON() — Linux 7.1AI High AI 2024-08-08
CVE-2024-39891 Twilio Authy API 安全漏洞 — n/a 5.3 Medium 2024-07-02
CVE-2024-28200 N-central Authentication Bypass — N-central CWE-288 9.1 Critical 2024-07-01
CVE-2021-47337 scsi: core: Fix bad pointer dereference when ehandler kthread is invalid — Linux 7.8AI High AI 2024-05-21
CVE-2024-35960 net/mlx5: Properly link new fs rules into the tree — Linux 5.5 - 2024-05-20
CVE-2024-23660 Binance Trust Wallet app 安全特征问题漏洞 — n/a 7.5 - 2024-02-08
CVE-2023-50428 Bitcoin Core 安全漏洞 — n/a - - 2023-12-09
CVE-2023-47630 Attacker can cause Kyverno user to unintentionally consume insecure image — kyverno CWE-345 7.1 High 2023-11-14
CVE-2023-42813 Denial of service from malicious manifest in kyverno — kyverno CWE-400 6.1 Medium 2023-11-13
CVE-2023-42814 Denial of service from malicious image manifest in kyverno — kyverno CWE-835 3.1 Low 2023-11-13
CVE-2023-42815 Denial of service from malicious image manifest in kyverno — kyverno CWE-835 3.1 Low 2023-11-13
CVE-2023-42816 Denial of service from malicious signature in kyverno — kyverno CWE-345 6.1 Medium 2023-11-13

Vulnerabilities classified as state:in-the-wild represent 407 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.