Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 405

405 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE IDTitleCVSSSeverityPublished
CVE-2023-30536 Insecure header validation in slim/psr7 — Slim-Psr7CWE-436 6.5 Medium2023-04-17
CVE-2023-29197 Improper header name validation in guzzlehttp/psr7 — psr7CWE-436 5.3 Medium2023-04-17
CVE-2023-28206 Apple macOS Ventura 缓冲区错误漏洞 — iOS and iPadOS 7.8 -2023-04-10
CVE-2023-28205 Apple Safari 资源管理错误漏洞 — iOS and iPadOS 8.8 -2023-04-10
CVE-2023-29389 Toyota RAV4 注入漏洞 — n/a 6.8 -2023-04-05
CVE-2023-29218 Twitter Recommendation Algorithm 安全漏洞 — n/a 7.5 -2023-04-03
CVE-2023-29059 3CX 安全漏洞 — n/a 8.4 -2023-03-30
CVE-2023-28445 Deno improperly handles resizable ArrayBuffer — denoCWE-125 10.0 Critical2023-03-23
CVE-2023-27638 PrestaShop SQL注入漏洞 — n/a 9.8 -2023-03-22
CVE-2023-27637 PrestaShop SQL注入漏洞 — n/a 9.8 -2023-03-22
CVE-2023-28725 General Bytes Crypto Application Server 代码问题漏洞 — n/a 9.8 -2023-03-21
CVE-2023-23529 Apple iOS和iPadOS 安全漏洞 — iOS and iPadOS 8.8 -2023-02-27
CVE-2023-24059 Grand Theft Auto V 安全漏洞 — n/a 9.4 -2023-01-22
CVE-2022-26486 Mozilla Firefox 资源管理错误漏洞 — Firefox 9.6 -2022-12-22
CVE-2022-26485 Mozilla Firefox 资源管理错误漏洞 — Firefox 8.8 -2022-12-22
CVE-2022-34478 Mozilla Firefox 安全漏洞 — Firefox 6.5 -2022-12-22
CVE-2022-42856 Apple iOS 安全漏洞 — tvOS 8.8 -2022-12-15
CVE-2022-45045 多款Xiongmai设备操作系统命令注入漏洞 — n/a 8.8 -2022-12-01
CVE-2022-42827 Apple iOS和iPadOS 缓冲区错误漏洞 — iOS and iPadOS 7.8 -2022-11-01
CVE-2016-20016 MV POWER CCTV DVR 安全漏洞 — n/a 9.8 -2022-10-19
CVE-2016-20017 D-Link DSL-2750B 命令注入漏洞 — n/a 9.8 -2022-10-19
CVE-2017-20149 MikroTik RouterOS 缓冲区错误漏洞 — n/a 9.8 -2022-10-15
CVE-2022-32917 Apple macOS Big Sur 缓冲区错误漏洞 — iOS 7.3 -2022-09-20
CVE-2022-40769 profanity 安全特征问题漏洞 — n/a 7.5 -2022-09-18
CVE-2022-40734 laravel-filemanager 路径遍历漏洞 — n/a 7.5 -2022-09-14
CVE-2022-32894 Apple macOS Monterey 缓冲区错误漏洞 — iOS and iPadOS 7.8 -2022-08-24
CVE-2022-32893 Apple macOS Monterey Safari 缓冲区错误漏洞 — Safari 8.8 -2022-08-24
CVE-2022-37450 Go Ethereum 安全漏洞 — n/a 5.9 -2022-08-05
CVE-2022-22675 Apple iOS和Apple iPadOS 缓冲区错误漏洞 — iOS and iPadOS 7.8 -2022-05-26
CVE-2022-29164 Privilege Escalation in argo-workflows — argo-workflowsCWE-269 7.1 High2022-05-05

Vulnerabilities classified as state:in-the-wild represent 405 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.