Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4151

Browse all 4151 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-25111 English WordPress Admin < 1.5.2 - Unauthenticated Open Redirect — English WordPress AdminCWE-601 6.1 -2022-04-25
CVE-2021-25094 Tatsu < 3.3.12 - Unauthenticated RCE — TatsuCWE-306 8.1 -2022-04-25
CVE-2021-24957 Advanced Page Visit Counter < 6.1.6 - Subscriber+ Blind SQL injection — Advanced Page Visit Counter – Advanced WordPress Visit CounterCWE-89 8.8 -2022-04-25
CVE-2021-24805 DW Question & Answer Pro <= 1.3.4 - Multiple CSRF — DW Question Answer ProCWE-352 6.5 -2022-04-25
CVE-2021-24800 DW Question & Answer Pro <= 1.3.4 - Arbitrary Comment Edition via IDOR — DW Question Answer ProCWE-639 4.3 -2022-04-25
CVE-2022-1112 Autolinks <= 1.0.1 - Stored Cross-Site Scripting via CSRF — AutolinksCWE-79 5.4 -2022-04-18
CVE-2022-1091 Safe SVG < 1.9.10 - SVG Sanitisation Bypass — Safe SVGCWE-79 6.1 -2022-04-18
CVE-2022-1090 Good & Bad Comments <= 1.0.0 - Admin+ Stored Cross-Site Scripting — Good & Bad commentsCWE-79 4.8 -2022-04-18
CVE-2022-1088 Page Security & Membership <= 1.5.15 - Admin+ Stored Cross-Site Scripting — Page Security & MembershipCWE-79 4.8 -2022-04-18
CVE-2022-1063 Thank Me Later <= 3.3.4 - Admin+ Stored Cross-Site Scripting — Thank Me LaterCWE-79 4.8 -2022-04-18
CVE-2022-1054 RSVP and Event Management < 2.7.8 - Unauthenticated Entries Export — RSVP and Event Management PluginCWE-862 5.3 -2022-04-18
CVE-2022-1037 EXMAGE < 1.0.7 - Admin+ Blind SSRF — EXMAGE – WordPress Image LinksCWE-918 8.8 -2022-04-18
CVE-2022-1020 Woo Product Table < 3.1.2 - Unauthenticated Arbitrary Function Call — Product Table for WooCommerce (wooproducttable)CWE-862 9.8 -2022-04-18
CVE-2022-1001 WP Downgrade < 1.2.3 - Admin+ Stored Cross-Site Scripting — WP Downgrade | Specific Core VersionCWE-79 4.8 -2022-04-18
CVE-2022-0994 Hummingbird < 3.3.2 - Admin+ Stored Cross-Site Scripting — Hummingbird – Optimize Speed, Enable Cache, Minify CSS & Defer Critical JSCWE-79 4.8 -2022-04-18
CVE-2022-0879 Caldera Forms < 1.9.7 - Reflected Cross-Site Scripting — Caldera Forms – More Than Contact FormsCWE-79 6.1 -2022-04-18
CVE-2022-0785 Daily Prayer Time < 2022.03.01 - Unauthenticated SQLi — Daily Prayer TimeCWE-89 9.8 -2022-04-18
CVE-2022-0780 SearchIQ < 3.9 - Unauthenticated Stored XSS — SearchIQ – The Search SolutionCWE-79 6.1 -2022-04-18
CVE-2022-0765 Loco Translate < 2.6.1 - Authenticated Stored Cross-Site Scripting — Loco TranslateCWE-79 4.8 -2022-04-18
CVE-2022-0737 Text Hover < 4.2 - Admin+ Stored Cross-Site Scripting — Text HoverCWE-79 4.8 -2022-04-18
CVE-2022-0707 Easy Digital Downloads < 2.11.6 - Arbitrary Payment Note Insertion via CSRF — Easy Digital Downloads – Simple eCommerce for Selling Digital FilesCWE-352 4.3 -2022-04-18
CVE-2022-0706 Easy Digital Downloads < 2.11.6 - Admin+ Stored Cross-Site Scripting — Easy Digital Downloads – Simple eCommerce for Selling Digital FilesCWE-79 4.8 -2022-04-18
CVE-2022-0661 Ad Injection <= 1.2.0.19 - Admin+ Stored Cross-Site Scripting & RCE — Ad InjectionCWE-94 7.2 -2022-04-18
CVE-2021-25120 Easy Social Feed < 6.2.7 - Reflected Cross-Site Scripting — Easy Social Feed ProCWE-79 6.1 -2022-04-18
CVE-2022-0142 Visual Form Builder < 3.0.6 - CSV Injection — Visual Form BuilderCWE-1236 9.8 -2022-04-12
CVE-2022-0141 Visual Form Builder < 3.0.8 - Entries Deletion/Restoration via CSRF — Visual Form BuilderCWE-352 8.1 -2022-04-12
CVE-2022-0140 Visual Form Builder < 3.0.6 - Unauthenticated Information Disclosure — Visual Form Builder 7.5 -2022-04-12
CVE-2022-1023 Podcast Importer SecondLine < 1.3.8 - Admin+ SQLi — Podcast Importer SecondLineCWE-89 9.8 -2022-04-11
CVE-2022-1008 One Click Demo Import < 3.1.0 - Admin+ Arbitrary File Upload — One Click Demo ImportCWE-434 7.2 -2022-04-11
CVE-2022-1007 Advanced Booking Calendar < 1.7.1 - Reflected Cross-Site Scripting — Advanced Booking CalendarCWE-79 6.1 -2022-04-11

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.