Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4154

Browse all 4154 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-1566 Quotes llama < 1.0.0 - Admin+ Stored Cross-Site Scripting — Quotes llamaCWE-79 4.8 -2022-05-30
CVE-2022-1564 Form Maker By 10Web < 1.14.12 - Admin+ Stored Cross-Site Scripting — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderCWE-79 4.8 -2022-05-30
CVE-2022-1562 Enable SVG < 1.4.0 - Author+ Stored Cross Site Scripting via SVG — Enable SVGCWE-79 5.4 -2022-05-30
CVE-2022-1556 StaffList < 3.1.5 - Admin+ SQLi — StaffListCWE-89 9.8 -2022-05-30
CVE-2022-1542 HPB Dashboard <= 1.3.1 - Admin+ Stored Cross Site Scripting — hpb DashboardCWE-79 4.8 -2022-05-30
CVE-2022-1528 VikBooking < 1.5.9 - Reflected Cross-Site Scripting — VikBooking Hotel Booking Engine & PMSCWE-79 6.1 -2022-05-30
CVE-2022-1527 WP 2FA < 2.2.1 - Reflected Cross-Site Scripting — WP 2FA – Two-factor authentication for WordPressCWE-79 6.1 -2022-05-30
CVE-2022-1456 Poll Maker < 4.0.2 - Admin+ Stored Cross-Site Scripting — Poll MakerCWE-79 4.8 -2022-05-30
CVE-2022-1395 Easy FAQ with Expanding Text <= 3.2.8.3.1 - Admin+ Stored Cross-Site Scripting — Easy FAQ with Expanding TextCWE-79 4.8 -2022-05-30
CVE-2022-1387 No Future Posts <= 1.4 - Admin+ Stored Cross-Site Scripting — No Future PostsCWE-79 4.8 -2022-05-30
CVE-2022-1299 Slideshow <= 2.3.1 - Admin+ Stored Cross-Site Scripting — SlideshowCWE-79 4.8 -2022-05-30
CVE-2022-1294 IMDB info box <= 2.0 - Admin+ Stored Cross-Site Scripting — IMDB Info BoxCWE-79 4.8 -2022-05-30
CVE-2022-1275 BannerMan <= 0.2.4 - Multiple Admin+ Stored Cross-Site Scripting — BannerManCWE-79 4.8 -2022-05-30
CVE-2022-1009 Smush < 3.9.9 - Admin+ Reflected Cross-Site Scripting — Smush – Lazy Load Images, Optimize & Compress ImagesCWE-79 6.1 -2022-05-30
CVE-2022-0642 JivoChat < 1.3.5.4 - Stored Cross-Site Scripting via CSRF — JivoChat Live Chat – WP live chat plugin for WordPressCWE-352 5.4 -2022-05-30
CVE-2022-0376 User Meta < 2.4.3 - Admin+ Stored Cross-Site Scripting — User Meta – User Profile Builder and User management pluginCWE-79 4.8 -2022-05-30
CVE-2022-1203 Content Mask < 1.8.4.1 - Subscriber+ Arbitrary Options Update — Content Mask 3.5 -2022-05-30
CVE-2022-1558 Curtain <= 1.0.2 - Admin+ Stored Cross-Site Scripting — CurtainCWE-79 4.8 -2022-05-23
CVE-2022-1547 Check & Log email < 1.0.6 - Reflected Cross-Site Scripting — Check & Log EmailCWE-79 6.1 -2022-05-23
CVE-2022-1320 Sliderby10Web < 1.2.52 - Admin+ Stored Cross-Site Scripting — Sliderby10WebCWE-79 4.8 -2022-05-23
CVE-2022-1298 Tabs Responsive < 2.2.8 - Editor+ Stored Cross-Site Scripting — TabsCWE-79 4.8 -2022-05-23
CVE-2022-1268 Donate Extra <= 2.02 - Reflected Cross-Site Scripting — Donate ExtraCWE-79 6.1 -2022-05-23
CVE-2022-1221 Gwyn's Imagemap Selector <= 0.3.3 - Reflected Cross-Site Scripting — Gwyn's Imagemap SelectorCWE-79 6.1 -2022-05-23
CVE-2022-1218 Domain Replace <= 1.3.8 - Reflected Cross-Site Scripting — Domain ReplaceCWE-79 6.1 -2022-05-23
CVE-2022-1192 Turn off all comments <= 1.0 - Reflected Cross-Site Scripting — Turn off all commentsCWE-79 6.1 -2022-05-23
CVE-2022-1093 WP Meta SEO < 4.4.7 - Admin+ Stored Cross-Site Scripting via breadcrumbs — WP Meta SEOCWE-79 4.8 -2022-05-23
CVE-2022-1014 WP Contacts Manager <= 2.2.4 - Unauthenticated SQLi — WP Contacts ManagerCWE-89 9.8 -2022-05-23
CVE-2022-0781 Nirweb support < 2.8.2 - Unauthenticated SQLi — Nirweb supportCWE-89 9.8 -2022-05-23
CVE-2022-0346 Google XML Sitemap Generator < 2.0.4 - Reflected Cross-Site Scripting — XML Sitemap Generator for GoogleCWE-79 6.1 -2022-05-23
CVE-2022-1560 Amministrazione Aperta < 3.8 - Admin+ LFI — Amministrazione ApertaCWE-22 8.1 -2022-05-16

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.