Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 407

407 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE ID Title CVSS Severity Published
CVE-2022-22675 Apple iOS和Apple iPadOS 缓冲区错误漏洞 — iOS and iPadOS 7.8 - 2022-05-26
CVE-2022-29164 Privilege Escalation in argo-workflows — argo-workflows CWE-269 7.1 High 2022-05-05
CVE-2022-22620 Apple多款产品资源管理错误漏洞 — Safari (v and ) 8.8 - 2022-03-18
CVE-2022-22587 Apple多款产品缓冲区错误漏洞 — iOS and iPadOS 7.8 - 2022-03-18
CVE-2022-24740 Improper Authentication in Volto — volto CWE-287 5.0 Medium 2022-03-14
CVE-2022-26143 Mitel Networks MiCollab和Mitel Networks MiVoice Business Express 访问控制错误漏洞 — n/a 9.1 - 2022-03-09
CVE-2022-25335 RigoBlock Dragos 安全漏洞 — n/a 7.5 - 2022-02-18
CVE-2022-24682 Zimbra Collaboration Suite 跨站脚本漏洞 — n/a 6.1 - 2022-02-09
CVE-2022-23597 Remote program execution with user interaction — n/a 8.3 High 2022-02-01
CVE-2021-45461 FreePBX 安全漏洞 — n/a 9.8 - 2021-12-22
CVE-2021-43844 Externally Controlled Reference to a Resource in Another Sphere in MSEdgeRedirect — MSEdgeRedirect CWE-610 8.8 High 2021-12-20
CVE-2021-44515 ZOHO ManageEngine Desktop Central MSP 授权问题漏洞 — n/a 9.8 - 2021-12-12
CVE-2021-42258 BEQ BillQuick Web Suite SQL注入漏洞 — n/a 9.8 - 2021-10-22
CVE-2021-30807 Apple iPadOS 缓冲区错误漏洞 — macOS 7.8 - 2021-10-19
CVE-2021-41773 Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 — Apache HTTP Server CWE-22 9.1 - 2021-10-05
CVE-2021-41083 CSRF Vulnerability in dada-mail 11.15.1 and below — dada-mail CWE-352 8.0 High 2021-09-20
CVE-2021-39205 DOM-based XSS/Content Spoofing via Prototype Pollution — jitsi-meet CWE-79 6.8 Medium 2021-09-15
CVE-2021-39212 Issue when Configuring the ImageMagick Security Policy — ImageMagick CWE-668 4.4 Medium 2021-09-13
CVE-2021-30657 Apple macOS 安全特征问题漏洞 — macOS 5.5 - 2021-09-08
CVE-2021-30661 Apple WebKitGTK+ 资源管理错误漏洞 — iOS and iPadOS 8.8 - 2021-09-08
CVE-2021-30713 Apple macOS Big Sur 输入验证错误漏洞 — macOS 6.6 - 2021-09-08
CVE-2021-30666 Apple iOS 缓冲区错误漏洞 — iOS 8.8 - 2021-09-08
CVE-2021-30665 Apple tvOS 缓冲区错误漏洞 — macOS 8.8 - 2021-09-08
CVE-2021-30762 Apple iOS 资源管理错误漏洞 — iOS 8.8 - 2021-09-08
CVE-2021-30761 Apple iOS 缓冲区错误漏洞 — iOS 8.8 - 2021-09-08
CVE-2021-38154 Canon 多款产品信息泄露漏洞 — n/a 9.1 - 2021-08-29
CVE-2021-31010 多款Apple产品代码问题漏洞 — macOS 7.5 - 2021-08-24
CVE-2021-30883 Apple 多款产品缓冲区错误漏洞 — iOS and iPadOS 7.8 - 2021-08-24
CVE-2021-30869 多款 Apple 产品安全漏洞 — iOS and iPadOS 7.8 - 2021-08-24
CVE-2021-30860 Apple macOS Big Sur输入验证错误漏洞 — macOS 7.8 - 2021-08-24

Vulnerabilities classified as state:in-the-wild represent 407 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.