Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4757

Browse all 4757 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-1603 Mail Subscribe List < 2.1.4 - Arbitrary Subscribed User Deletion via CSRF — Mail Subscribe ListCWE-352 4.3 -2022-06-20
CVE-2022-1472 Better Find and Replace < 1.3.6 - Admin+ SQLi — Better Find and ReplaceCWE-89 7.2 -2022-06-20
CVE-2022-1266 Post Grid, Slider & Carousel Ultimate < 1.5.0 - Admin+ Stored XSS — Post Grid, Slider & Carousel UltimateCWE-79 4.8 -2022-06-20
CVE-2022-0663 Print, PDF, Email by PrintFriendly < 5.2.3 - Admin+ Stored Cross-Site Scripting — Print, PDF, Email by PrintFriendlyCWE-79 4.8 -2022-06-20
CVE-2021-25121 Rating by BestWebSoft < 1.6 - Rating Denial of Service — Rating by BestWebSoftCWE-191 6.5 -2022-06-20
CVE-2021-25104 Ocean Extra < 1.9.5 - Reflected Cross-Site Scripting — Ocean ExtraCWE-79 6.1 -2022-06-20
CVE-2021-25088 Google XML Sitemaps < 4.1.3 - Admin+ Stored Cross-Site Scripting — XML SitemapsCWE-79 4.8 -2022-06-20
CVE-2022-0209 Mitsol Social Post Feed < 1.11 - Admin+ Stored Cross-Site Scripting — Mitsol Social Post FeedCWE-79 4.8 -2022-06-13
CVE-2022-1814 WP Admin Style <= 0.1.2 - Admin+ Stored Cross-Site Scripting — WP Admin StyleCWE-79 4.8 -2022-06-13
CVE-2022-1800 Export any WordPress data to XML/CSV < 1.3.5 - Admin+ SQL Injection — Export any WordPress data to XML/CSVCWE-89 8.8 -2022-06-13
CVE-2022-1793 Private Files <= 0.40 - Protection Disabling via CSRF — Private FilesCWE-352 4.3 -2022-06-13
CVE-2022-1792 Quick Subscribe <= 1.7.1 - Arbitrary Settings Update via CSRF to Stored XSS — Quick SubscribeCWE-352 5.4 -2022-06-13
CVE-2022-1791 One Click Plugin Updater <= 2.4.14 - Arbitrary Settings Update via CSRF — One Click Plugin UpdaterCWE-352 4.3 -2022-06-13
CVE-2022-1790 New User Email Set Up <= 0.5.2 - Arbitrary Settings Update via CSRF — New User Email Set UpCWE-352 4.3 -2022-06-13
CVE-2022-1788 Change Uploaded File Permissions <= 4.0.0 - File Permission Update via CSRF — Change Uploaded File PermissionsCWE-352 6.5 -2022-06-13
CVE-2022-1787 Sideblog <= 6.0 - Arbitrary Settings Update via CSRF to Stored XSS — Sideblog WordPress PluginCWE-352 5.4 -2022-06-13
CVE-2022-1781 postTabs <= 2.10.6 - Arbitrary Settings Update via CSRF to Stored XSS — postTabsCWE-352 5.4 -2022-06-13
CVE-2022-1780 LaTeX for WordPress <= 3.4.10 - Arbitrary Settings Update via CSRF to Stored XSS — LaTeX for WordPressCWE-352 5.4 -2022-06-13
CVE-2022-1779 Auto Delete Posts <= 1.3.0 - Arbitrary Settings Update via CSRF — Auto Delete PostsCWE-352 6.5 -2022-06-13
CVE-2022-1777 Filr - Secure Document Library < 1.2.2.1 - Subscriber+ AJAX Calls — Filr – Secure document libraryCWE-862 8.3 -2022-06-13
CVE-2022-1773 WP Athletics <= 1.1.7 - Reflected Cross-Site Scripting — WP AthleticsCWE-79 6.1 -2022-06-13
CVE-2022-1772 Google Places Review < 2.0.0 - Admin+ Stored Cross Site Scripting — Google Places ReviewsCWE-79 6.9 -2022-06-13
CVE-2022-1765 Hot Linked Image Cacher <= 1.16 - Image upload/cache abuse via CSRF — Hot Linked Image CacherCWE-352 8.1 -2022-06-13
CVE-2022-1764 WP-chgFontSize <= 1.8 - Arbitrary Settings Update via CSRF to Stored XSS — WP-chgFontSizeCWE-352 4.1 -2022-06-13
CVE-2022-1763 Static Page eXtended <= 2.1 - Arbitrary Settings Update via CSRF to Stored XSS — Static Page eXtendedCWE-352 9.3 -2022-06-13
CVE-2022-1762 iQ Block Country < 1.2.20 - Protection Bypass due to IP Spoofing — iQ Block Country 5.3 -2022-06-13
CVE-2022-1761 Peter’s Collaboration E-mails <= 2.2.0 - Arbitrary Settings Update via CSRF — Peter’s Collaboration E-mailsCWE-352 6.5 -2022-06-13
CVE-2022-1759 RB Internal Links <= 2.0.16 - Stored Cross-Site Scripting via CSRF — RB Internal LinksCWE-352 5.4 -2022-06-13
CVE-2022-1758 Genki Pre-Publish Reminder <= 1.4.1 - Stored XSS & RCE via CSRF — Genki Pre-Publish ReminderCWE-352 8.8 -2022-06-13
CVE-2022-1756 Newsletter < 7.4.5 - Reflected Cross-Site Scripting — Newsletter – Send awesome emails from WordPressCWE-79 6.1 -2022-06-13

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.