Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4393

Browse all 4393 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-3996 Post Grid, Post Carousel, & List Category Posts < 2.4.28 - Editor+ Stored XSS — Smart Post Show 4.8AIMediumAI2025-05-15
CVE-2024-1663 Ultimate Noindex Nofollow Tool II < 1.3.6 - Admin+ Stored XSS — Ultimate Noindex Nofollow Tool II 4.8AIMediumAI2025-05-15
CVE-2024-2643 My Sticky Bar < 2.6.8 - Admin+ Stored XSS — Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme 4.8AIMediumAI2025-05-15
CVE-2024-2869 Easy Property Listings <= 3.5.3 - Admin+ Stored XSS — Easy Property Listings 4.8AIMediumAI2025-05-15
CVE-2024-12767 BuddyBoss platform < 2.7.60 - Private Comment Exposure via IDOR — buddyboss-platform 4.3AIMediumAI2025-05-15
CVE-2024-0970 User Activity Tracking and Log < 4.1.4 - IP Spoofing — User Activity Tracking and Log 7.5AIHighAI2025-05-15
CVE-2024-0852 coreActivity < 1.8.1 - Unauthenticated Stored XSS — coreActivity: Activity Logging for WordPress 6.1AIMediumAI2025-05-15
CVE-2024-0249 Advanced Schedule Posts <= 2.1.8 - Reflected XSS — Advanced Schedule Posts 6.1AIMediumAI2025-05-15
CVE-2023-7297 TwitterPosts <= 1.0.2 - Settings Update via CSRF — TwitterPosts 4.3AIMediumAI2025-05-15
CVE-2023-7230 illi Link Party! <= 1.0 - Admin+ Stored Cross-Site Scripting — illi Link Party! 5.4AIMediumAI2025-05-15
CVE-2023-7239 wp-dashboard-notes < 1.0.11 - Contributor+ Arbitrary Private Notes Update via IDOR — WP Dashboard Notes 4.3AIMediumAI2025-05-15
CVE-2023-7231 illi Link Party! <= 1.0 - Unauthenticated Arbitrary Link Deletion — illi Link Party! 5.3AIMediumAI2025-05-15
CVE-2023-7229 illi Link Party! <= 1.0 - Settings Update via CSRF — illi Link Party! 4.3AIMediumAI2025-05-15
CVE-2023-7228 illi Link Party! <= 1.0 - Unauthenticated Stored XSS — illi Link Party! 6.1AIMediumAI2025-05-15
CVE-2023-7195 WP-Reply Notify <= 1.1 - Settings Update via CSRF — WP-Reply Notify 4.3AIMediumAI2025-05-15
CVE-2023-7196 Ultimate Noindex Nofollow Tool <= 1.1.2 - Settings Update via CSRF — Ultimate Noindex Nofollow Tool 4.3AIMediumAI2025-05-15
CVE-2023-7197 Marketing Twitter Bot <= 1.11 - Settings Update to Stored XSS via CSRF — Marketing Twitter Bot 6.1AIMediumAI2025-05-15
CVE-2023-7174 aBitGone CommentSafe <= 1.0.0 - Settings Update to Stored XSS via CSRF — aBitGone CommentSafe 6.1AIMediumAI2025-05-15
CVE-2023-7168 Better Follow Button for Jetpack <= 8.0 - Admin+ Stored XSS — Better Follow Button for Jetpack 4.8AIMediumAI2025-05-15
CVE-2023-7086 SVG Uploads Support <= 2.1.1 - Author+ Stored XSS via SVG — SVG Uploads Support 5.4AIMediumAI2025-05-15
CVE-2023-7088 Add SVG Support for Media Uploader | inventivo <= 1.0.5 - Author+ Stored XSS via SVG — Add SVG Support for Media Uploader | inventivo 5.4AIMediumAI2025-05-15
CVE-2023-6783 WolfNet IDX for WordPress <= 1.19.1 - Admin+ Stored XSS — WolfNet IDX for WordPress 4.8AIMediumAI2025-05-15
CVE-2023-6786 Payment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect — Payment Gateway for Telcell 6.1AIMediumAI2025-05-15
CVE-2023-6541 Allow SVG < 1.2.0 - Author+ Stored XSS via SVG — Allow SVG 5.4AIMediumAI2025-05-15
CVE-2023-6030 LogDash Activity Log < 1.1.4 - Unauthenticated SQLi — LogDash Activity Log 9.8AICriticalAI2025-05-15
CVE-2023-5934 Travelpayouts < 1.1.13 - Settings Update via CSRF — Travelpayouts: All Travel Brands in One Place 4.3AIMediumAI2025-05-15
CVE-2023-5932 Travelpayouts < 1.1.14 - Reflected XSS — Travelpayouts: All Travel Brands in One Place 6.1AIMediumAI2025-05-15
CVE-2023-5529 Advanced Page Visit Counter <= 8.0.6 - Admin+ Stored XSS — Advanced Page Visit Counter 4.8AIMediumAI2025-05-15
CVE-2023-2334 Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF — edd-google-sheet-connector-pro 6.5AIMediumAI2025-05-15
CVE-2025-2248 WP-PManager <= 1.2 - Admin+ SQL Injection — WP-PManager 7.2AIHighAI2025-05-15

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.