Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

state:in-the-wild — CVE vulnerabilities tagged 405

405 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE IDTitleCVSSSeverityPublished
CVE-2021-35941 Western Digital WD My Book Live 访问控制错误漏洞 — n/a 9.1 -2021-06-29
CVE-2021-22893 Pulse Secure Pulse Connect Secure 资源管理错误漏洞 — Pulse Connect SecureCWE-287 10.0 -2021-04-23
CVE-2021-24175 The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass — The Plus Addons for Elementor Page BuilderCWE-287 9.8 -2021-04-05
CVE-2021-1879 Apple iOS WebKit 跨站脚本漏洞 — iOS and iPadOS 6.1 -2021-04-02
CVE-2021-1871 Apple iOS 安全漏洞 — iOS and iPadOS 9.8 -2021-04-02
CVE-2021-1870 苹果 Apple iOS 安全漏洞 — iOS and iPadOS 9.8 -2021-04-02
CVE-2021-1782 Apple Kernel 竞争条件问题漏洞 — iOS and iPadOS 7.0 -2021-04-02
CVE-2021-3122 NCR Command Center Agent 操作系统命令注入漏洞 — n/a 9.8 -2021-02-07
CVE-2021-3006 Seal Finance Farm 安全漏洞 — n/a 7.5 -2021-01-03
CVE-2020-35234 WordPress 日志信息泄露漏洞 — n/a 9.1 -2020-12-14
CVE-2020-26876 WordPress 安全漏洞 — n/a--2020-10-07
CVE-2020-25213 wordpress 代码问题漏洞 — n/a 10.0 Critical2020-09-09
CVE-2020-13125 WordPress Ultimate Addons for Elementor 安全漏洞 — n/a 5.3 -2020-05-17
CVE-2020-13126 WordPress Elementor Pro 代码问题漏洞 — n/a 8.8 -2020-05-17
CVE-2020-1631 Out of Cycle Security Advisory: Junos OS: Security vulnerability in J-Web and web based (HTTP/HTTPS) services — Junos OSCWE-22 8.8 High2020-05-04
CVE-2020-12271 Sophos XG Firewall SFOS SQL注入漏洞 — n/a 9.8 -2020-04-27
CVE-2020-6819 多款Mozilla产品 竞争条件问题漏洞 — Thunderbird 7.5 -2020-04-24
CVE-2020-6820 多款Mozilla产品 竞争条件问题漏洞 — Thunderbird 7.5 -2020-04-24
CVE-2019-17026 Mozilla Firefox、Firefox ESR和Thunderbird IonMonkey JIT compiler 安全漏洞 — Firefox ESR 8.8 -2020-03-02
CVE-2014-8739 Adobe Creative Cloud Desktop Application 代码问题漏洞 — n/a 9.8 -2020-02-08
CVE-2019-17049 NETGEAR SRX5308 SQL注入漏洞 — n/a 9.1 -2019-09-30
CVE-2019-11707 Mozilla Firefox 代码问题漏洞 — Firefox ESR 9.8 -2019-07-23
CVE-2018-18472 Western Digital WD My Book Live 操作系统命令注入漏洞 — n/a 9.8 -2019-06-19
CVE-2018-18852 CERIO DT-300N 操作系统命令注入漏洞 — n/a 9.8 -2019-06-18
CVE-2019-9978 WordPress social-warfare插件跨站脚本漏洞 — n/a 6.1 -2019-03-24
CVE-2017-18362 Kaseya VSA ConnectWise ManagedITSync SQL注入漏洞 — n/a 9.8 -2019-02-05
CVE-2018-20753 Kaseya VSA RMM 权限许可和访问控制问题漏洞 — n/a 9.8 -2019-02-05
CVE-2018-19207 WordPress Van Ons WP GDPR Compliance插件安全漏洞 — n/a 9.8 -2018-11-12
CVE-2018-18956 Suricata 输入验证错误漏洞 — n/a 7.5 -2018-11-05
CVE-2017-15705 Apache SpamAssassin 安全漏洞 — Apache SpamAssassin 5.3 -2018-09-17

Vulnerabilities classified as state:in-the-wild represent 405 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.