Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-2330 Caldera Forms Google Sheets Connector < 1.3 - Access Code Update via CSRF — Caldera Forms Google Sheets Connector 6.5 -2023-07-17
CVE-2023-3182 Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS — Membership Plugin 6.1 -2023-07-17
CVE-2023-3245 Floating Chat Widget < 3.1.2 - Admin+ Stored Cross-Site Scripting — Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button 4.8 -2023-07-17
CVE-2023-3179 POST SMTP Mailer < 2.5.7 - Account Takeover via CSRF — POST SMTP Mailer 8.8 -2023-07-17
CVE-2023-1893 Login Configurator <= 2.1 - Reflected Cross-Site Scripting — Login Configurator 6.1 -2023-07-17
CVE-2023-2143 Enable SVG, WebP & ICO Upload <= 1.0.3 - Author+ Stored XSS — Enable SVG, WebP & ICO Upload 6.1 -2023-07-17
CVE-2023-2636 AN_GradeBook <= 5.0.1 - Subscriber+ SQLi — AN_GradeBook 8.8 -2023-07-17
CVE-2023-3186 Supsystic Popup < 1.10.19 - Prototype Pollution — Popup by Supsystic 9.8 -2023-07-17
CVE-2023-3041 Autochat <= 1.1.7- Unauthenticated Stored XSS — Autochat Automatic Conversation 5.4 -2023-07-17
CVE-2023-2329 WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF — WooCommerce Google Sheet Connector 6.5 -2023-07-17
CVE-2023-2579 InventoryPress <= 1.7 - Author+ Stored XSS — InventoryPress 5.4 -2023-07-17
CVE-2022-4023 3DPrint < 3.5.6.9 - CSRF to arbitrary file downlad — 3dprint 6.5 -2023-07-17
CVE-2023-1208 HTTP Headers < 1.18.11 - Admin+ Remote Code Execution — HTTP Headers 9.8 -2023-07-10
CVE-2023-3219 EventON < 2.1.2 - Unauthenticated Post Access via IDOR — EventON 7.5 -2023-07-10
CVE-2023-3131 MStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update — MStore API 9.1 -2023-07-10
CVE-2023-3225 Float menu < 5.0.3 - Admin+ Stored Cross-Site Scripting — Float menu 4.8 -2023-07-10
CVE-2023-2967 TinyMCE Custom Styles < 1.1.4 - Admin+ Stored Cross-Site Scripting — TinyMCE Custom Styles 4.8 -2023-07-10
CVE-2023-2635 Call Now Accessibility Button < 1.1 - Admin+ Stored XSS — Call Now Accessibility Button 4.8 -2023-07-10
CVE-2023-3209 MStore API < 3.9.7 - Settings Update via CSRF — MStore API 9.1 -2023-07-10
CVE-2023-2029 PrePost SEO <= 3.0 - Admin+ Stored Cross-Site Scripting — PrePost SEO 4.8 -2023-07-10
CVE-2023-2028 Call Now Accessibility Button < 1.1 - Admin+ Stored Cross Site Scripting — Call Now Accessibility Button 4.8 -2023-07-10
CVE-2023-3175 AI ChatBot < 4.6.1 - Admin+ Stored Cross-Site Scripting — AI ChatBot 4.8 -2023-07-10
CVE-2023-2709 AN_GradeBook <= 5.0.1 - Admin+ XSS — AN_GradeBook 4.8 -2023-07-10
CVE-2023-3118 Export All URLs < 4.6 - Reflected XSS — Export All URLs 6.1 -2023-07-10
CVE-2023-2529 Enable SVG Uploads <= 2.1.5 - Author+ Stored XSS via SVG — Enable SVG Uploads 5.4 -2023-07-10
CVE-2023-1597 tagDiv Cloud Library < 2.7 - Unauthenticated Arbitrary User Metadata Update to Privilege Escalation — tagDiv Cloud Library 9.1 -2023-07-10
CVE-2023-2495 Greeklish-permalink < 3.5 - Unauthenticated Post Slug Update — Greeklish-permalink 6.5 -2023-07-10
CVE-2023-1780 Companion Sitemap Generator < 4.5.3 - Reflected XSS — Companion Sitemap Generator 6.1 -2023-07-10
CVE-2023-2964 Simple Iframe < 1.2.0 - Contributor+ Stored XSS — Simple Iframe 5.4 -2023-07-10
CVE-2023-2026 Image Protector <= 1.1 - Admin+ Stored Cross-Site Scripting — Image Protector 4.8 -2023-07-10

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.