Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4646

Browse all 4646 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2026-16955 AI Engine < 3.6.6 - Subscriber+ Arbitrary File Read via Audio Transcription — AI Engine--2026-08-08
CVE-2026-16953 AI Engine < 3.6.4 - Unauthenticated Cross-Session Chatbot File Deletion via Forgeable Session Cookie — AI Engine--2026-08-08
CVE-2026-16595 WP Directory Kit < 1.5.5 - Subscriber+ User and Unpublished Listing Disclosure — WP Directory Kit--2026-08-08
CVE-2026-16608 Download Monitor < 5.2.6 - Unauthenticated Download Log Injection — Download Monitor--2026-08-08
CVE-2026-16948 Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure — Solace Extra--2026-08-08
CVE-2026-16594 WP Directory Kit < 1.5.5 - Subscriber+ Plugin Settings and API Key Disclosure — WP Directory Kit--2026-08-08
CVE-2026-16590 WP Directory Kit < 1.5.5 - Subscriber+ Contact Message and User Data Disclosure — WP Directory Kit--2026-08-08
CVE-2026-16578 Admin Safety Guard < 1.4.0 - Unauthenticated User Data Disclosure via 2fa/app/users REST Route — Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection--2026-08-08
CVE-2026-16574 Dokan < 5.0.11 - Vendor+ Cross-Vendor Downloadable Product Access Grant via Order Downloads REST Endpoint — Dokan: AI Powered WooCommerce Multivendor Marketplace Solution--2026-08-08
CVE-2026-16562 WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers — WP Statistics--2026-08-08
CVE-2026-16589 WP Directory Kit < 1.5.5 - Subscriber+ SQL Injection via data_fields_list Parameter — WP Directory Kit--2026-08-08
CVE-2026-16535 Link Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabel — Link Library--2026-08-08
CVE-2026-16282 Appointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost Parameter — Appointment Hour Booking--2026-08-08
CVE-2026-16558 YMC Filter < 3.12.8 - Contributor+ Stored XSS via Layout Builder Schema — YMC Filter--2026-08-08
CVE-2026-16269 Newsletters < 4.16 - Unauthenticated API Authentication Bypass via Type Juggling — Newsletters--2026-08-08
CVE-2026-16559 YMC Filter < 3.12.9 - Author+ Stored XSS via SVG Icon Upload — YMC Filter--2026-08-08
CVE-2026-16267 Newsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form Field — Newsletters--2026-08-08
CVE-2026-15239 Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache Key — Simple CAPTCHA with Cloudflare Turnstile 5.3 Medium2026-08-07
CVE-2026-15211 Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture Token — Subscriptions for WooCommerce 5.9 Medium2026-08-07
CVE-2026-15148 WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOR — WP Events Manager 5.3 Medium2026-08-07
CVE-2026-16258 Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics REST Endpoint — Ajax Search Lite--2026-08-07
CVE-2026-16265 WP Maps < 4.9.7 - Subscriber+ Denial of Service — WP Maps--2026-08-07
CVE-2026-16263 WP Maps < 4.9.7 - Subscriber+ Local File Inclusion — WP Maps--2026-08-07
CVE-2026-16041 MStore API < 4.21.0 - Unauthenticated Product Review Creation — MStore API--2026-08-07
CVE-2026-16262 Estatik < 4.3.3 - Login CSRF — Estatik Real Estate Plugin--2026-08-07
CVE-2026-15386 Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text — Meow Gallery--2026-08-07
CVE-2026-15361 Content Views < 4.5 - Subscriber+ SQL Injection via preview_request — Content Views--2026-08-07
CVE-2026-16038 MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways — MStore API--2026-08-07
CVE-2026-16039 MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR — MStore API--2026-08-07
CVE-2026-16030 MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication — MStore API--2026-08-07

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.