Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-5595 Essential Blocks < 4.7.0 - Contributor+ Stored XSS — Essential Blocks 5.4AIMediumAI2024-08-02
CVE-2024-6529 Ultimate Classified Listings < 1.4 - Reflected XSS — Ultimate Classified Listings 6.1AIMediumAI2024-08-01
CVE-2024-6496 Light Poll <= 1.0.0 - Polls Deletion via CSRF — Light Poll 4.3AIMediumAI2024-08-01
CVE-2024-4090 My Sticky Bar < 2.7.2 - Admin+ Stored XSS — Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme 4.8AIMediumAI2024-08-01
CVE-2024-2872 Swift Framework < 2024.04.30 - Contributor+ Stored XSS — socialdriver-framework 4.8AIMediumAI2024-08-01
CVE-2024-3983 WooCommerce Customers Manager < 30.1 - Bulk Action via CSRF — WooCommerce Customers Manager 4.3AIMediumAI2024-08-01
CVE-2024-2843 WooCommerce Customers Manager < 30.1 - User Deletion via CSRF — WooCommerce Customers Manager 6.5AIMediumAI2024-08-01
CVE-2024-1747 WooCommerce Customers Manager < 30.2 - Subscriber+ Stored XSS — WooCommerce Customers Manager 5.4AIMediumAI2024-08-01
CVE-2024-6695 profile-builder <= 3.11.8 - Unauthenticated Privilege Escalation — User Profile Builder 9.8AICriticalAI2024-07-31
CVE-2024-6412 HTML Forms – Simple WordPress Forms Plugin < 1.3.34 - Bulk Delete via CSRF — HTML Forms 8.8AIHighAI2024-07-31
CVE-2024-6408 Slider by 10Web < 1.2.57 - Editor+ Stored XSS — Slider by 10Web 4.8AIMediumAI2024-07-31
CVE-2024-6272 SpiderContacts <= 1.1.7 - Reflected XSS — SpiderContacts 6.1AIMediumAI2024-07-31
CVE-2024-6165 WANotifier < 2.6.1 - Admin+ Stored XSS — WANotifier 4.8AIMediumAI2024-07-31
CVE-2024-6230 Pardakht Delkhah <= 2.9.8 - Form Fields Reset via CSRF — پلاگین پرداخت دلخواه 8.8AIHighAI2024-07-30
CVE-2024-6536 Zephyr Project Manager < 3.3.99 - Editor+ XSS — Zephyr Project Manager 4.8AIMediumAI2024-07-30
CVE-2024-6021 Donation Block for PayPal <= 2.1.0 - Unauthenticated Stored XSS — Donation Block For PayPal 6.1AIMediumAI2024-07-30
CVE-2024-6226 WpStickyBar <= 2.1.0 - Reflected XSS — WpStickyBar 6.1AIMediumAI2024-07-30
CVE-2024-6223 Send email only on Reply to My Comment <= 1.0.6 - Reflected XSS — Send email only on Reply to My Comment 6.1AIMediumAI2024-07-30
CVE-2024-6224 Send email only on Reply to My Comment <= 1.0.6 - Stored XSS via CSRF — Send email only on Reply to My Comment 6.1AIMediumAI2024-07-30
CVE-2024-5975 CZ Loan Management <= 1.1 - Unauthenticated SQLi — CZ Loan Management 9.8AICriticalAI2024-07-30
CVE-2024-5808 WP Ajax Contact Form <= 2.2.2 - Arbitrary Email Deletion via CSRF — WP Ajax Contact Form 4.3AIMediumAI2024-07-30
CVE-2024-5809 WP Ajax Contact Form <= 2.2.2 - Reflected Cross-Site Scripting — WP Ajax Contact Form 6.1AIMediumAI2024-07-30
CVE-2024-3986 SportsPress < 2.7.22 - Admin+ Stored XSS — SportsPress 4.8AIMediumAI2024-07-30
CVE-2024-5765 WpStickyBar <= 2.1.0 - Unauthenticated SQLi — WpStickyBar 9.8AICriticalAI2024-07-30
CVE-2024-4096 Responsive Tabs <= 4.0.8 - Contributor+ Stored XSS — Responsive Tabs 4.8AIMediumAI2024-07-30
CVE-2024-5807 Business Card <= 1.0.0 - Admin+ File Upload — Business Card 7.2AIHighAI2024-07-30
CVE-2024-3669 Web Directory Free < 1.7.2 - Reflected XSS — Web Directory Free 6.1AIMediumAI2024-07-30
CVE-2024-3113 FormFlow < 2.12.2 - Admin+ Stored XSS — FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection 4.8AIMediumAI2024-07-30
CVE-2024-1287 Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi — pmpro-member-directory 6.5AIMediumAI2024-07-30
CVE-2024-1286 Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure — pmpro-membership-maps 4.3AIMediumAI2024-07-30

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.