Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

UNKNOWN — Vulnerabilities & Security Advisories 4427

Browse all 4427 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6478 CTT Expresso para WooCommerce < 3.2.13 - Admin+ Stored XSS — CTT Expresso para WooCommerce 4.8AIMediumAI2025-05-15
CVE-2024-5440 If-So Dynamic Content Personalization < 1.8.0.3 - Contributor+ Shortcode Stored XSS — If-So Dynamic Content Personalization 5.4AIMediumAI2025-05-15
CVE-2024-5026 CM Tooltip Glossary < 4.3.4 - Admin+ Stored XSS — CM Tooltip Glossary 4.8AIMediumAI2025-05-15
CVE-2024-13828 Badgearoo <= 1.0.14 - Reflected XSS — Badgearoo 6.1AIMediumAI2025-05-15
CVE-2024-13865 drm-protected-video-streaming <= 4.2.1 - Reflected XSS — S3Player 6.1AIMediumAI2025-05-15
CVE-2024-13823 360 Product Rotation <= 1.5.8 - Reflected XSS — 360 Product Rotation 6.1AIMediumAI2025-05-15
CVE-2024-13730 Podlove Podcast Publisher < 4.2.1 - Admin+ Stored XSS — Podlove Podcast Publisher 4.8AIMediumAI2025-05-15
CVE-2024-13727 MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS — MemberSpace 6.1AIMediumAI2025-05-15
CVE-2024-13621 The GDPR Framework By Data443 < 2.2.0 - Admin+ Stored XSS — The GDPR Framework By Data443 4.8AIMediumAI2025-05-15
CVE-2024-13619 LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes < 8.0.1 - Reflected XSS — LifterLMS 6.1AIMediumAI2025-05-15
CVE-2024-13729 Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS — Podlove Podcast Publisher 4.8AIMediumAI2025-05-15
CVE-2024-13616 VikBooking < 1.7.2 - Admin+ Stored XSS — VikBooking Hotel Booking Engine & PMS 4.8AIMediumAI2025-05-15
CVE-2024-13486 Icegram Engage < 3.1.32 - Admin+ Stored XSS — Icegram Engage 4.8AIMediumAI2025-05-15
CVE-2024-13482 Icegram Engage < 3.1.32 - Admin+ Stored XSS — Icegram Engage 4.8AIMediumAI2025-05-15
CVE-2024-13357 Ditty – Responsive News Tickers, Sliders, and Lists < 3.1.52 - Author+ Stored XSS — Ditty 4.8AIMediumAI2025-05-15
CVE-2024-13382 Calculated Fields Form < 5.2.64 - Admin+ Stored XSS — Calculated Fields Form 4.8AIMediumAI2025-05-15
CVE-2024-13384 Photo Gallery, Images, Slider in Rbs Image Gallery < 3.2.24 - Admin+ Stored XSS — Photo Gallery, Images, Slider in Rbs Image Gallery 4.8AIMediumAI2025-05-15
CVE-2024-13383 HD Quiz < 2.0.0 - Editor+ Stored XSS — HD Quiz 4.8AIMediumAI2025-05-15
CVE-2024-13313 AWeber <= 7.3.20 - Admin+ Stored XSS — AWeber 4.8AIMediumAI2025-05-15
CVE-2024-13127 LearnPress – WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS — LearnPress 4.8AIMediumAI2025-05-15
CVE-2024-13128 LearnPress – WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS — LearnPress 4.8AIMediumAI2025-05-15
CVE-2024-13053 Form Maker by 10Web < 1.15.33 - Admin+ Stored XSS via Theme Title — Form Maker by 10Web 4.8AIMediumAI2025-05-15
CVE-2024-12873 Custom Field Manager <= 1.0 - Reflected XSS Vulnerability — Custom Field Manager 6.1AIMediumAI2025-05-15
CVE-2024-12812 WP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee Information — WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 4.3AIMediumAI2025-05-15
CVE-2024-12874 Top Comments <= 1.0 - Admin+ Stored Cross-Site Scripting — Top Comments 4.8AIMediumAI2025-05-15
CVE-2024-12800 IP Based Login < 2.4.1 - Admin+ Stored XSS — IP Based Login 4.8AIMediumAI2025-05-15
CVE-2024-12770 WP ULike < 4.7.6 - Admin+ Stored XSS — WP ULike 4.8AIMediumAI2025-05-15
CVE-2024-12808 WP ERP | Complete HR solution with recruitment < 1.13.4 - Admin+ Stored XSS — WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 4.8AIMediumAI2025-05-15
CVE-2024-12735 Advance Post Prefix <= 1.1.1 - Admin+ SQL Injection — Advance Post Prefix 7.2AIHighAI2025-05-15
CVE-2024-12743 MailPoet < 5.5.2 - Admin+ Stored XSS — MailPoet 4.8AIMediumAI2025-05-15

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.