Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4769

Browse all 4769 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-2172 LinkWorth Plugin < 3.3.4 - Arbitrary Setting Update via CSRF — LinkWorth PluginCWE-352 6.5 -2022-08-22
CVE-2022-25812 Transposh WordPress Translation < 1.0.8 - Admin+ RCE — Transposh WordPress TranslationCWE-94 7.2 -2022-08-22
CVE-2022-25811 Transposh WordPress Translation <= 1.0.8 - Admin+ SQL Injection — Transposh WordPress TranslationCWE-89 7.2 -2022-08-22
CVE-2022-25810 Transposh WordPress Translation <= 1.0.8 - Subscriber+ Unauthorised Calls — Transposh WordPress TranslationCWE-862 8.1 -2022-08-22
CVE-2022-1932 Rezgo Online Booking < 4.1.8 - Reflected Cross-Site-Scripting — Rezgo Online BookingCWE-79 6.1 -2022-08-22
CVE-2022-1322 Coming Soon - Under Construction <= 1.1.9 - Admin+ Stored Cross-Site Scripting — Coming Soon – Under ConstructionCWE-79 4.8 -2022-08-22
CVE-2022-1251 Ask Me < 6.8.4 - CSRF in Edit Profile — Ask meCWE-352 6.5 -2022-08-22
CVE-2022-0446 Simple Banner < 2.12.0 - Admin+ Stored Cross Site Scripting — Simple BannerCWE-79 4.8 -2022-08-22
CVE-2021-24912 Transposh WordPress Translation < 1.0.8 - CSRF to Stored XSS — Transposh WordPress TranslationCWE-352 5.4 -2022-08-22
CVE-2021-24911 Transposh WordPress Translation < 1.0.8 - Stored Cross-Site Scripting — Transposh WordPress TranslationCWE-79 5.4 -2022-08-22
CVE-2021-24910 Transposh WordPress Translation < 1.0.8 - Reflected Cross-Site Scripting — Transposh WordPress TranslationCWE-79 6.1 -2022-08-22
CVE-2022-2846 Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS — Calendar Event Multi ViewCWE-862 4.3 -2022-08-16
CVE-2022-2535 SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title Disclosure — SearchWP Live Ajax SearchCWE-639 5.3 -2022-08-15
CVE-2022-2384 Digital Publications by Supsystic < 1.7.4 - Admin+ Stored Cross-Site Scripting — Digital Publications by SupsysticCWE-79 4.8 -2022-08-15
CVE-2022-2381 E Unlocked - Student Result <= 1.0.4 - Arbitrary File Upload via CSRF — E Unlocked – Student ResultCWE-352 8.8 -2022-08-15
CVE-2022-2379 Easy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST API — Easy Student ResultsCWE-862 7.5 -2022-08-15
CVE-2022-2378 Easy Student Results <= 2.2.8 - Reflected Cross-Site Scripting — Easy Student ResultsCWE-79 6.1 -2022-08-15
CVE-2022-2354 WP-DBManager < 2.80.8 - Admin+ Remote Command Execution — WP-DBManager 7.2 -2022-08-15
CVE-2022-2314 VR Calendar < 2.3.2 - Unauthenticated Arbitrary Function Call — VR CalendarCWE-78 9.8 -2022-08-15
CVE-2022-2180 GREYD.SUITE < 1.2.7 - Unauthenticated File Upload to RCE — greyd_suiteCWE-434 9.8 -2022-08-15
CVE-2022-2152 Duplicate Page and Post Plugin < 2.8 - Admin+ Stored Cross-Site Scripting — Duplicate Page and PostCWE-79 4.8 -2022-08-15
CVE-2022-2116 Elementor Contact Form DB < 1.8.0 - Reflected Cross-Site Scripting — Contact Form DB – ElementorCWE-79 6.1 -2022-08-15
CVE-2022-2460 WPDating < 7.4.0 - Multiple Unauthenticated SQLi — WPDating 9.8 -2022-08-08
CVE-2022-2426 Thinkific Uploader <= 1.0.0 - Admin+ Stored Cross-Site Scripting — Thinkific UploaderCWE-79 4.8 -2022-08-08
CVE-2022-2425 WP DS Blog Map <= 3.1.3 - Admin+ Stored Cross-Site Scripting — WP DS Blog MapCWE-79 4.8 -2022-08-08
CVE-2022-2424 Google Maps Anywhere <= 1.2.6.3 - Admin+ Stored Cross-Site Scripting — Google Maps AnywhereCWE-79 4.8 -2022-08-08
CVE-2022-2423 DW Promobar <= 1.0.4 - Admin+ Stored Cross-Site Scripting — DW PromobarCWE-79 4.8 -2022-08-08
CVE-2022-2412 Better Tag Cloud <= 0.99.5 - Admin+ Stored Cross-Site Scripting — Better Tag CloudCWE-79 4.8 -2022-08-08
CVE-2022-2411 Auto More Tag <= 4.0.0 - Admin+ Stored Cross-Site Scripting — Auto More TagCWE-79 4.8 -2022-08-08
CVE-2022-2410 mTouch Quiz <= 3.1.3 - Admin+ Stored Cross Site Scripting — mTouch QuizCWE-79 4.8 -2022-08-08

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.