Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 407

407 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE IDTitleCVSSSeverityPublished
CVE-2023-47246 Sysaid Technologies SysAid 安全漏洞 — n/a 8.8 -2023-11-10
CVE-2023-31418 Elasticsearch uncontrolled resource consumption — ElasticsearchCWE-400 7.5 High2023-10-26
CVE-2023-30801 qBittorrent Web UI Default Credentials Lead to RCE — qBittorrent clientCWE-1392 9.8 Critical2023-10-10
CVE-2023-44487 Apache HTTP/2 资源管理错误漏洞 — n/a 7.5 -2023-10-10
CVE-2023-42824 Apple iOS和iPadOS 安全漏洞 — iOS and iPadOS 7.8 -2023-10-04
CVE-2023-41993 Apple Safari 代码问题漏洞 — macOS 8.8 -2023-09-21
CVE-2023-41992 Apple watchOS 代码问题漏洞 — macOS 7.8 -2023-09-21
CVE-2023-41991 Apple watchOS 信任管理问题漏洞 — iOS and iPadOS 5.5 -2023-09-21
CVE-2023-3892 Unsafe XML parsing of 3rd party DICOM private tags may lead to XXE — MIM AssistantCWE-611 5.6 Medium2023-09-19
CVE-2023-41990 Apple watchOS 安全漏洞 — iOS and iPadOS 7.8 -2023-09-11
CVE-2023-41064 Apple macOS Ventura 安全漏洞 — macOS 7.8 -2023-09-07
CVE-2023-41061 Apple watchOS 安全漏洞 — iOS and iPadOS 7.8 -2023-09-07
CVE-2023-38831 WinRAR 安全漏洞 — n/a 8.8 -2023-08-23
CVE-2023-40711 Veilid 缓冲区错误漏洞 — n/a 7.5 -2023-08-20
CVE-2023-39910 Libbitcoin Explorer 安全特征问题漏洞 — n/a 7.5 -2023-08-09
CVE-2023-38606 Apple macOS Ventura 安全漏洞 — tvOS 5.5 -2023-07-26
CVE-2023-37450 Apple iOS 和 iPadOS 安全漏洞 — Safari 8.8 -2023-07-26
CVE-2023-38198 acme.sh 安全漏洞 — n/a 9.8 -2023-07-13
CVE-2023-3460 Ultimate Member < 2.6.7 - Unauthenticated Privilege Escalation — Ultimate Member 9.8 -2023-07-04
CVE-2023-32373 Apple Safari 资源管理错误漏洞 — macOS 8.8 -2023-06-23
CVE-2023-28204 Apple iOS 和iPadOS 缓冲区错误漏洞 — macOS 6.5 -2023-06-23
CVE-2023-32409 部分Apple产品 安全漏洞 — macOS 8.6 -2023-06-23
CVE-2023-32439 Apple Safari 安全漏洞 — iOS and iPadOS 8.8 -2023-06-23
CVE-2023-32434 Apple macOS Big Sur 输入验证错误漏洞 — macOS 7.8 -2023-06-23
CVE-2023-32435 Apple macOS Ventura 缓冲区错误漏洞 — macOS 8.8 -2023-06-23
CVE-2023-35042 GeoServer 安全漏洞 — n/a 9.8 -2023-06-12
CVE-2023-34362 MoveIT SQL注入漏洞 — n/a 9.8 -2023-06-02
CVE-2023-27639 PrestaShop 路径遍历漏洞 — n/a 7.5 -2023-06-01
CVE-2023-27640 PrestaShop 路径遍历漏洞 — n/a 7.5 -2023-06-01
CVE-2023-33297 Bitcoin Core 资源管理错误漏洞 — n/a 7.5 -2023-05-22

Vulnerabilities classified as state:in-the-wild represent 407 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.