Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

state:in-the-wild — CVE vulnerabilities tagged 396

396 CVE security advisories tagged "state:in-the-wild" with AI Chinese analysis, CVSS, references and POCs.

The tag "state:in-the-wild" signifies that a disclosed vulnerability has been actively exploited by attackers in real-world environments, rather than remaining theoretical or limited to controlled laboratory testing. This classification is critical because it indicates an immediate and tangible threat to public infrastructure, demanding urgent mitigation strategies from administrators and developers. Typically, these vulnerabilities involve remote code execution, authentication bypasses, or critical logic flaws that allow adversaries to compromise systems without physical access. The presence of this tag implies that exploit code is likely circulating in the wild, increasing the risk of widespread data breaches, service disruptions, or lateral movement within networks. Consequently, organizations must prioritize patching these specific CVEs to prevent active intrusion, as the window between disclosure and exploitation has effectively closed, leaving systems exposed to sophisticated threat actors seeking immediate gain.

CVE IDTitleCVSSSeverityPublished
CVE-2018-10299 Beauty Ecosystem Coin smart contract 数字错误漏洞 — n/a 7.5 -2018-04-23
CVE-2018-4878 Adobe Flash Player 安全漏洞 — Adobe Flash Player before 28.0.0.161 9.8 -2018-02-06
CVE-2017-16651 Roundcube Webmail 安全漏洞 — n/a 7.8 -2017-11-09
CVE-2017-12637 SAP NetWeaver Application Server Java 路径遍历漏洞 — n/a 7.5 -2017-08-07
CVE-2017-8291 Artifex Ghostscript 安全漏洞 — n/a 7.8 -2017-04-27
CVE-2017-2404 Apple iOS Quick Look组件安全漏洞 — n/a 7.5 -2017-04-02
CVE-2017-7269 Microsoft Internet Information Services 缓冲区错误漏洞 — n/a 9.8 -2017-03-27
CVE-2017-5638 Apache Struts 2 输入验证错误漏洞 — Apache Struts 9.8 -2017-03-11
CVE-2016-5195 Linux kernel 竞争条件问题漏洞 — n/a 7.0 -2016-11-10
CVE-2016-7855 Adobe Flash Player 远程代码执行漏洞 — n/a 8.8 -2016-11-01
CVE-2016-6195 vBulletin SQL注入漏洞 — n/a 9.8 -2016-08-30
CVE-2016-4171 Adobe Flash Player 安全漏洞 — n/a 9.8 -2016-06-16
CVE-2016-1409 Cisco IOS XR、IOS XE和NX-OS 拒绝服务漏洞 — n/a 6.5 -2016-05-29
CVE-2010-5326 SAP NetWeaver Application Server Invoker Servlet 任意代码执行漏洞 — n/a 10.0 -2016-05-13
CVE-2016-4117 Adobe Flash Player 任意代码执行漏洞 — n/a 9.8 -2016-05-11
CVE-2016-1019 Adobe Flash Player 安全漏洞 — n/a 9.8 -2016-04-07
CVE-2015-8562 Joomla! Core 远程代码执行漏洞 — n/a 9.8 -2015-12-16
CVE-2015-7645 Adobe Flash Player 任意代码执行漏洞 — n/a 8.8 -2015-10-15
CVE-2015-2502 Microsoft Internet Explorer 缓冲区溢出漏洞 — n/a 7.5 -2015-08-19
CVE-2015-4495 多款Mozilla产品PDF阅读器安全漏洞 — n/a 9.8 -2015-08-08
CVE-2015-5122 Adobe Flash Player ActionScript 3 释放后重用漏洞 — n/a 8.8 -2015-07-14
CVE-2015-5123 Adobe Flash Player ActionScript 3 释放后重用漏洞 — n/a 8.8 -2015-07-14
CVE-2015-5119 Adobe Flash Player ActionScript 3 缓冲区溢出漏洞 — n/a 9.8 -2015-07-08
CVE-2015-3113 Adobe Flash Player 基于堆的缓冲区溢出漏洞 — n/a 8.8 -2015-06-23
CVE-2015-2945 Hajime Fujimoto mt-phpincgi 代码注入漏洞 — n/a 9.8 -2015-05-25
CVE-2014-8361 Realtek SDK 输入验证错误 — n/a 9.8 -2015-05-01
CVE-2015-1701 Microsoft Windows Win32k 特权提升漏洞 — n/a 7.8 -2015-04-21
CVE-2015-3043 Adobe Flash Player 内存损坏漏洞 — n/a 8.8 -2015-04-14
CVE-2015-1494 WordPress FancyBox for WordPress插件跨站脚本漏洞 — n/a 6.1 -2015-02-17
CVE-2015-0313 Adobe Flash Player 任意代码执行漏洞 — n/a 8.8 -2015-02-02

Vulnerabilities classified as state:in-the-wild represent 396 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.