Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11843 Panorama – WordPress Project Management Plugin <= 1.5.1 - Admin+ Stored XSS — Panorama 4.8AIMediumAI2025-05-15
CVE-2024-11718 tarteaucitron.js for WordPress < 0.3.0 - Author+ Stored XSS — tarteaucitron-wp 5.4AIMediumAI2025-05-15
CVE-2024-11719 tarteaucitron.js for WordPress < 0.3.0 - Stored XSS via CSRF — tarteaucitron-wp 6.1AIMediumAI2025-05-15
CVE-2024-11502 Planning Center Online Giving <= 1.0.0 - Contributor+ XSS via Shortcode — Planning Center Online Giving 5.4AIMediumAI2025-05-15
CVE-2024-11372 Connexion Logs <= 3.0.2 - Admin+ SQL Injection — Connexion Logs 7.2AIHighAI2025-05-15
CVE-2024-11373 Connexion Logs <= 3.0.2 - Log Deletion via CSRF — Connexion Logs 4.3AIMediumAI2025-05-15
CVE-2024-11269 AHAthat Plugin <= 1.6 - Admin+ SQL Injection — AHAthat Plugin 7.2AIHighAI2025-05-15
CVE-2024-11267 JSP Store Locator <= 1.0 - Contributor+ SQL Injection — JSP Store Locator 8.8AIHighAI2025-05-15
CVE-2024-11266 Geocache Stat Bar Widget <= 0.911 - Admin+ Stored XSS — Geocache Stat Bar Widget 4.8AIMediumAI2025-05-15
CVE-2024-11190 jwp-a11y <= 4.1.7 - Admin+ Stored XSS — jwp-a11y 4.8AIMediumAI2025-05-15
CVE-2024-11141 Sailthru Triggermail < 1.1 - Subscriber+ Stored XSS — Sailthru Triggermail 5.4AIMediumAI2025-05-15
CVE-2024-11189 Social Share And Social Locker – ARSocial < 1.4.2 - Admin+ Stored XSS — Social Share And Social Locker 4.8AIMediumAI2025-05-15
CVE-2024-11221 Full Screen (Page) Background Image Slideshow <= 1.1 - Admin+ Stored XSS — Full Screen (Page) Background Image Slideshow 4.8AIMediumAI2025-05-15
CVE-2024-11109 WP Google Review Slider < 15.6 - Admin+ Stored XSS — WP Google Review Slider 4.8AIMediumAI2025-05-15
CVE-2024-11140 Real WP Shop Lite Ajax eCommerce Shopping Cart <= 2.0.8 - Admin+ Stored XSS — Real WP Shop Lite Ajax eCommerce Shopping Cart 4.8AIMediumAI2025-05-15
CVE-2024-10818 JSFiddle Shortcode < 1.1.3 - Contributor+ XSS via Shortcode — JSFiddle Shortcode 5.4AIMediumAI2025-05-15
CVE-2024-10677 BTEV <= 2.0.2 - Settings Update via CSRF — BTEV 4.3AIMediumAI2025-05-15
CVE-2024-10639 Auto Prune Posts < 3.0.0- Admin+ Stored XSS — Auto Prune Posts 4.8AIMediumAI2025-05-15
CVE-2024-10632 Nokaut Offers Box <= 1.4.0 - Admin+ Stored XSS — Nokaut Offers Box 4.8AIMediumAI2025-05-15
CVE-2024-10631 Countdown Timer <= 1.0.5 - Contributor+ Stored XSS — Countdown Timer for WordPress Block Editor 5.4AIMediumAI2025-05-15
CVE-2024-10634 Nokaut Offers Box <= 1.4.0 - Plugin Reset via CSRF — Nokaut Offers Box 6.5AIMediumAI2025-05-15
CVE-2024-10504 ARForms Builder < 1.7.1 - Unauthenticated Stored XSS — Contact Form, Survey, Quiz & Popup Form Builder 6.1AIMediumAI2025-05-15
CVE-2024-10475 Lead Form Builder < 1.9.8 - Admin+ Stored XSS — Responsive Contact Form Builder & Lead Generation Plugin 4.8AIMediumAI2025-05-15
CVE-2024-10362 Social Media Share Buttons < 2.9.0 - Admin+ Stored XSS — Social Media Share Buttons & Social Sharing Icons 4.8AIMediumAI2025-05-15
CVE-2024-10145 Hubbub Lite < 1.34.4 - Admin+ Stored XSS — Hubbub Lite 4.8AIMediumAI2025-05-15
CVE-2024-10149 Social Slider Feed < 2.2.9 - Admin+ Stored XSS via Widgets — Social Slider Feed 4.8AIMediumAI2025-05-15
CVE-2024-10144 Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.22 - Contributor+ Stored XSS — Photo Gallery, Images, Slider in Rbs Image Gallery 4.8AIMediumAI2025-05-15
CVE-2024-10143 MB Custom Post Types & Custom Taxonomies < 2.7.7 - Admin+ Stored XSS — MB Custom Post Types & Custom Taxonomies 4.8AIMediumAI2025-05-15
CVE-2024-10107 Giveaways and Contests by RafflePress < 1.12.17 - Admin+ Stored XSS — Giveaways and Contests by RafflePress 4.8AIMediumAI2025-05-15
CVE-2024-10098 ApplyOnline – Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access — ApplyOnline 7.5AIHighAI2025-05-15

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.