Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4457

Browse all 4457 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2026-14840 YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing — YOP Poll--2026-08-01
CVE-2026-14561 Authora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP Disclosure — Authora : Easy login with mobile number--2026-08-01
CVE-2026-14839 Mapster WP Maps < 1.24.0 - Unauthenticated Private and Draft Post Content Disclosure — Mapster WP Maps--2026-08-01
CVE-2026-14823 Event Tickets < 5.29.0.1 - Contributor+ Seating Layout and Ticket Inventory Modification via IDOR — Event Tickets and Registration--2026-08-01
CVE-2026-14822 Event Tickets < 5.29.0.1 - Unauthenticated PayPal Order Status Manipulation — Event Tickets and Registration--2026-08-01
CVE-2026-14292 WordPress Download Manager < 3.3.66 - Author+ Stored XSS via Package Title — Download Manager--2026-08-01
CVE-2026-14315 Pixel Manager for WooCommerce < 2.2.1 - Unauthenticated Forged Conversion Event Submission — Pixel Tag Manager for WooCommerce--2026-08-01
CVE-2026-14195 Brizy – Page Builder < 2.8.18 - Contributor+ Sensitive Information Disclosure via get_post_info — Brizy--2026-08-01
CVE-2026-14214 Amelia < 2.4.4 - Amelia Manager+ Arbitrary User-Field Modification via Mass Assignment — Booking for Appointments and Events Calendar--2026-08-01
CVE-2026-13729 Podlove Podcast Publisher < 4.5.3 - Podcast Contributor/Group/Role Creation and Deletion via CSRF — Podlove Podcast Publisher--2026-08-01
CVE-2026-13725 Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax — Dynamic Pricing With Discount Rules for WooCommerce--2026-08-01
CVE-2026-11882 Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public REST Routes — Builderall for WordPress--2026-08-01
CVE-2026-12696 wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field — wpForo Forum--2026-08-01
CVE-2026-13329 WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund — Buckaroo Woocommerce Payments Plugin--2026-08-01
CVE-2026-13596 Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search — Participants Database--2026-08-01
CVE-2026-13604 Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX — Pixelavo--2026-08-01
CVE-2026-10827 Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via Block Attributes — Spectra Legacy--2026-08-01
CVE-2026-13158 Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload — Everest Toolkit--2026-08-01
CVE-2026-13157 Theme Demo Import <= 1.1.3 - Admin+ Arbitrary File Upload — Theme Demo Import--2026-08-01
CVE-2026-15262 Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column — Admin Columns for ACF Fields--2026-08-01
CVE-2026-15234 Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute — Codeless Page Builder--2026-08-01
CVE-2026-15368 Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration — User Profile Builder--2026-08-01
CVE-2026-15244 HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view — HUSKY--2026-08-01
CVE-2026-14197 Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR — Fluent Support--2026-08-01
CVE-2026-14836 Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass — Login & Register Forms--2026-08-01
CVE-2026-14596 DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection — DynamicKit for Elementor--2026-08-01
CVE-2026-14309 Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass — Chat On Desk Order Notifications--2026-08-01
CVE-2026-15932 Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal — Support Genix--2026-08-01
CVE-2026-12966 Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering via digages AJAX Actions — Direct Payments for WooCommerce--2026-08-01
CVE-2025-15669 Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label — Bit Form--2026-08-01

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.