Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

UNKNOWN — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting UNKNOWN. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-7231 illi Link Party! <= 1.0 - Unauthenticated Arbitrary Link Deletion — illi Link Party! 5.3AIMediumAI2025-05-15
CVE-2023-7230 illi Link Party! <= 1.0 - Admin+ Stored Cross-Site Scripting — illi Link Party! 5.4AIMediumAI2025-05-15
CVE-2023-7229 illi Link Party! <= 1.0 - Settings Update via CSRF — illi Link Party! 4.3AIMediumAI2025-05-15
CVE-2023-7228 illi Link Party! <= 1.0 - Unauthenticated Stored XSS — illi Link Party! 6.1AIMediumAI2025-05-15
CVE-2023-7197 Marketing Twitter Bot <= 1.11 - Settings Update to Stored XSS via CSRF — Marketing Twitter Bot 6.1AIMediumAI2025-05-15
CVE-2023-7196 Ultimate Noindex Nofollow Tool <= 1.1.2 - Settings Update via CSRF — Ultimate Noindex Nofollow Tool 4.3AIMediumAI2025-05-15
CVE-2023-7195 WP-Reply Notify <= 1.1 - Settings Update via CSRF — WP-Reply Notify 4.3AIMediumAI2025-05-15
CVE-2023-7174 aBitGone CommentSafe <= 1.0.0 - Settings Update to Stored XSS via CSRF — aBitGone CommentSafe 6.1AIMediumAI2025-05-15
CVE-2023-7168 Better Follow Button for Jetpack <= 8.0 - Admin+ Stored XSS — Better Follow Button for Jetpack 4.8AIMediumAI2025-05-15
CVE-2023-7086 SVG Uploads Support <= 2.1.1 - Author+ Stored XSS via SVG — SVG Uploads Support 5.4AIMediumAI2025-05-15
CVE-2023-7088 Add SVG Support for Media Uploader | inventivo <= 1.0.5 - Author+ Stored XSS via SVG — Add SVG Support for Media Uploader | inventivo 5.4AIMediumAI2025-05-15
CVE-2023-6786 Payment Gateway for Telcell <= 2.0.1 - Unauthenticated Open Redirect — Payment Gateway for Telcell 6.1AIMediumAI2025-05-15
CVE-2023-6783 WolfNet IDX for WordPress <= 1.19.1 - Admin+ Stored XSS — WolfNet IDX for WordPress 4.8AIMediumAI2025-05-15
CVE-2023-6541 Allow SVG < 1.2.0 - Author+ Stored XSS via SVG — Allow SVG 5.4AIMediumAI2025-05-15
CVE-2023-6030 LogDash Activity Log < 1.1.4 - Unauthenticated SQLi — LogDash Activity Log 9.8AICriticalAI2025-05-15
CVE-2023-5932 Travelpayouts < 1.1.14 - Reflected XSS — Travelpayouts: All Travel Brands in One Place 6.1AIMediumAI2025-05-15
CVE-2023-5934 Travelpayouts < 1.1.13 - Settings Update via CSRF — Travelpayouts: All Travel Brands in One Place 4.3AIMediumAI2025-05-15
CVE-2023-5529 Advanced Page Visit Counter <= 8.0.6 - Admin+ Stored XSS — Advanced Page Visit Counter 4.8AIMediumAI2025-05-15
CVE-2023-2334 Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF — edd-google-sheet-connector-pro 6.5AIMediumAI2025-05-15
CVE-2025-2247 WP-PManager <= 1.2 - Category Deletion via CSRF — WP-PManager 4.3AIMediumAI2025-05-15
CVE-2025-2248 WP-PManager <= 1.2 - Admin+ SQL Injection — WP-PManager 7.2AIHighAI2025-05-15
CVE-2025-1454 Ninja Pages <= 1.4.2 - Admin+ Stored XSS — Ninja Pages 4.8AIMediumAI2025-05-15
CVE-2025-1303 Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS — Plugin Oficial 6.1AIMediumAI2025-05-15
CVE-2025-1289 Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Admin+ Stored XSS — Plugin Oficial 4.8AIMediumAI2025-05-15
CVE-2025-2203 WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection — FunnelKit 7.2AIHighAI2025-05-15
CVE-2025-0688 Spiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS — Spiritual Gifts Survey (and optional S.H.A.P.E survey) 6.1AIMediumAI2025-05-15
CVE-2025-1286 Download HTML TinyMCE Button <= 1.2 - Reflected XSS — Download HTML TinyMCE Button 6.1AIMediumAI2025-05-15
CVE-2025-1288 wooexim <= 5.0.0 - CSRF to Reflected XSS — WOOEXIM 6.1AIMediumAI2025-05-15
CVE-2025-1033 Badgearoo <= 1.0.14 - Admin+ Stored XSS — Badgearoo 4.8AIMediumAI2025-05-15
CVE-2025-0329 AI ChatBot for WordPress – WPBot < 6.2.4 - Admin+ Stored XSS — AI ChatBot for WordPress 4.8AIMediumAI2025-05-15

This page lists every published CVE security advisory associated with UNKNOWN. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.