Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4152

Browse all 4152 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-7879 WP ULike < 4.7.5 - Admin+ Stored XSS via Widgets — WP ULike 4.8AIMediumAI2024-11-06
CVE-2024-9883 Pods < 3.2.7.1 - Admin+ Stored XSS — Pods 4.8AIMediumAI2024-11-05
CVE-2024-7877 Appointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin 4.8AIMediumAI2024-11-05
CVE-2024-9689 Post From Frontend <= 1.0.0 - Post Deletion via CSRF — Post From Frontend 6.5AIMediumAI2024-11-05
CVE-2024-7876 Appointment Booking Calendar < 1.6.7.55 - Admin+ Stored XSS — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin 4.8AIMediumAI2024-11-05
CVE-2024-5578 Table of Contents Plus <= 2408 - Editor+ Stored XSS — Table of Contents Plus 4.8AIMediumAI2024-11-05
CVE-2024-8444 Download Manager < 3.3.00 - Contributor+ Stored XSS — Download Manager 6.1AIMediumAI2024-10-30
CVE-2024-8625 TS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection — TS Poll 7.2AIHighAI2024-10-21
CVE-2024-5429 Logo Slider < 4.1.0 - Contributor+ Stored XSS — Logo Slider 5.4AIMediumAI2024-10-17
CVE-2024-9796 WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection — WP-Advanced-Search 9.8AICriticalAI2024-10-10
CVE-2024-9156 TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection via lang parameters — TI WooCommerce Wishlist 7.5AIHighAI2024-10-10
CVE-2024-5968 Photo Gallery by 10Web <= 1.8.27 - Admin+ Stored XSS — Photo Gallery by 10Web 4.8AIMediumAI2024-10-09
CVE-2024-9021 Relevanssi < 4.23.1 - Contributor+ Stored XSS — Relevanssi 6.1AIMediumAI2024-10-08
CVE-2024-8983 Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS — Custom Twitter Feeds 6.9AIMediumAI2024-10-08
CVE-2024-7315 Migration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure — Migration, Backup, Staging 7.5 -2024-10-02
CVE-2024-8536 Ultimate Blocks < 3.2.2 - Contributor+ Stored XSS — Ultimate Blocks 5.4 -2024-09-30
CVE-2024-8239 Starbox < 3.5.3 - Contributor+ Stored XSS — Starbox 5.4 -2024-09-30
CVE-2024-8379 Cost Calculator Builder < 3.2.29 - Admin+ SQL Injection — Cost Calculator Builder 7.2 -2024-09-30
CVE-2024-8283 Slider by 10Web < 1.2.59 - Admin+ Stored XSS — Slider by 10Web 4.8 -2024-09-30
CVE-2024-3635 The Post Grid < 7.5.0 - Editor+ Stored XSS via Grid Creation — The Post Grid 4.8 -2024-09-30
CVE-2024-7714 AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls — AI ChatBot with ChatGPT and Content Generator by AYS 5.3AIMediumAI2024-09-27
CVE-2024-7713 AI Chatbot with ChatGPT by AYS <= 2.0.9 - Unauthenticated OpenAI Key Disclosure — AI ChatBot with ChatGPT and Content Generator by AYS 7.5AIHighAI2024-09-27
CVE-2024-6517 Contact Form 7 Math Captcha <= 2.0.1 - Reflected XSS — Contact Form 7 Math Captcha 6.1AIMediumAI2024-09-26
CVE-2024-7892 adstxt Plugin <= 1.0.0 - Settings Update via CSRF — adstxt Plugin 4.3AIMediumAI2024-09-25
CVE-2024-6845 SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure — Chatbot with ChatGPT WordPress 7.5AIHighAI2024-09-25
CVE-2024-7878 WP ULike < 4.7.4 - Admin+ Stored XSS — WP ULike 4.8AIMediumAI2024-09-25
CVE-2024-8758 Quiz and Survey Master (QSM) < 9.1.3 - Author+ Stored XSS — Quiz and Survey Master (QSM) 4.8AIMediumAI2024-09-23
CVE-2024-7846 YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS — YITH WooCommerce Ajax Search 5.4AIMediumAI2024-09-23
CVE-2024-8093 Posts reminder <= 0.20 - Settings Update via CSRF — Posts reminder 4.3 -2024-09-17
CVE-2024-8091 Enhanced Search Box <= 0.6.1 - Settings Update via CSRF — Enhanced Search Box 4.3 -2024-09-17

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.