Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-9796 WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection — WP-Advanced-Search 9.8AICriticalAI2024-10-10
CVE-2024-9156 TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection via lang parameters — TI WooCommerce Wishlist 7.5AIHighAI2024-10-10
CVE-2024-5968 Photo Gallery by 10Web <= 1.8.27 - Admin+ Stored XSS — Photo Gallery by 10Web 4.8AIMediumAI2024-10-09
CVE-2024-9021 Relevanssi < 4.23.1 - Contributor+ Stored XSS — Relevanssi 6.1AIMediumAI2024-10-08
CVE-2024-8983 Custom Twitter Feeds < 2.2.3 - Admin+ Stored XSS — Custom Twitter Feeds 6.9AIMediumAI2024-10-08
CVE-2024-7315 Migration, Backup, Staging – WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure — Migration, Backup, Staging 7.5 -2024-10-02
CVE-2024-8283 Slider by 10Web < 1.2.59 - Admin+ Stored XSS — Slider by 10Web 4.8 -2024-09-30
CVE-2024-8536 Ultimate Blocks < 3.2.2 - Contributor+ Stored XSS — Ultimate Blocks 5.4 -2024-09-30
CVE-2024-8239 Starbox < 3.5.3 - Contributor+ Stored XSS — Starbox 5.4 -2024-09-30
CVE-2024-8379 Cost Calculator Builder < 3.2.29 - Admin+ SQL Injection — Cost Calculator Builder 7.2 -2024-09-30
CVE-2024-3635 The Post Grid < 7.5.0 - Editor+ Stored XSS via Grid Creation — The Post Grid 4.8 -2024-09-30
CVE-2024-7714 AI Assistant with ChatGPT by AYS <= 2.0.9 - Unauthenticated AJAX Calls — AI ChatBot with ChatGPT and Content Generator by AYS 5.3AIMediumAI2024-09-27
CVE-2024-7713 AI Chatbot with ChatGPT by AYS <= 2.0.9 - Unauthenticated OpenAI Key Disclosure — AI ChatBot with ChatGPT and Content Generator by AYS 7.5AIHighAI2024-09-27
CVE-2024-6517 Contact Form 7 Math Captcha <= 2.0.1 - Reflected XSS — Contact Form 7 Math Captcha 6.1AIMediumAI2024-09-26
CVE-2024-7892 adstxt Plugin <= 1.0.0 - Settings Update via CSRF — adstxt Plugin 4.3AIMediumAI2024-09-25
CVE-2024-7878 WP ULike < 4.7.4 - Admin+ Stored XSS — WP ULike 4.8AIMediumAI2024-09-25
CVE-2024-6845 SmartSearchWP < 2.4.6 - Unauthenticated OpenAI Key Disclosure — Chatbot with ChatGPT WordPress 7.5AIHighAI2024-09-25
CVE-2024-8758 Quiz and Survey Master (QSM) < 9.1.3 - Author+ Stored XSS — Quiz and Survey Master (QSM) 4.8AIMediumAI2024-09-23
CVE-2024-7846 YITH WooCommerce Ajax Search < 2.7.1 - Contributor+ Stored XSS — YITH WooCommerce Ajax Search 5.4AIMediumAI2024-09-23
CVE-2024-8093 Posts reminder <= 0.20 - Settings Update via CSRF — Posts reminder 4.3 -2024-09-17
CVE-2024-8052 Review Ratings <= 1.6 - Stored XSS via CSRF — Review Ratings 6.1 -2024-09-17
CVE-2024-8091 Enhanced Search Box <= 0.6.1 - Settings Update via CSRF — Enhanced Search Box 4.3 -2024-09-17
CVE-2024-8092 Accordion Image Menu <= 3.1.3 - Stored XSS via CSRF — Accordion Image Menu 6.1 -2024-09-17
CVE-2024-8044 infolinks Ad Wrap <= 1.0.2 - Settings Update via CSRF — infolinks Ad Wrap 4.3 -2024-09-17
CVE-2024-8051 Special Feed Items <= 1.0.1 - Stored XSS via CSRF — Special Feed Items 6.1 -2024-09-17
CVE-2024-8047 Visual Sound (old) <= 1.06 - Settings Update via CSRF — Visual Sound (old) 4.3 -2024-09-17
CVE-2024-8043 Vikinghammer Tweet <= 0.2.4 - Stored XSS via CSRF — Vikinghammer Tweet 6.1 -2024-09-17
CVE-2024-5170 Logo Manager For Enamad <= 0.7.1 - Admin+ Stored XSS via Widget — Logo Manager For Enamad 4.8 -2024-09-17
CVE-2024-7864 Favicon Generator < 2.1 - Arbitrary File Deletion via CSRF — Favicon Generator (CLOSED) 6.5AIMediumAI2024-09-13
CVE-2024-7133 My Sticky Bar < 2.7.3 - Admin+ Stored XSS — Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme 4.8AIMediumAI2024-09-13

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.