Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24980 Gwolle Guestbook < 4.2.0 - Reflected Cross-Site Scripting — Gwolle GuestbookCWE-79 6.1 -2021-12-27
CVE-2021-24979 Paid Memberships Pro < 2.6.6 - Reflected Cross-Site Scripting — Paid Memberships ProCWE-79 6.1 -2021-12-27
CVE-2021-24967 Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site Scripting — Contact Form & Lead Form Elementor BuilderCWE-79 6.1 -2021-12-27
CVE-2021-24969 Download Manager < 3.2.22 - Subscriber+ Stored Cross-Site Scripting — WordPress Download ManagerCWE-79 5.4 -2021-12-27
CVE-2021-24902 Typebot < 1.4.3 - Admin+ Stored Cross Site Scripting — Typebot | Build beautiful conversational formsCWE-79 4.8 -2021-12-27
CVE-2021-24797 Tickera < 3.4.8.3 - Unauthenticated Stored Cross-Site Scripting — Tickera – WordPress Event TicketingCWE-79 6.1 -2021-12-27
CVE-2021-24753 Rich Reviews by Starfish < 1.9.6 - Admin+ SQL Injection — Rich Reviews by StarfishCWE-89 7.2 -2021-12-27
CVE-2021-24981 Directorist – Business Directory Plugin < 7.0.6.2 - CSRF to Remote File Upload — Directorist – Business Directory PluginCWE-434 8.8 -2021-12-21
CVE-2021-24956 Blog2Social < 6.8.7 - Reflected Cross-Site Scripting — Blog2Social: Social Media Auto Post & SchedulerCWE-79 6.1 -2021-12-21
CVE-2021-24941 Icegram < 2.0.5 - Reflected Cross-Site Scripting — Popups, Welcome Bar, Optins and Lead Generation Plugin – IcegramCWE-79 6.1 -2021-12-21
CVE-2021-24907 Everest Forms < 1.8.0 - Reflected Cross-Site Scripting — Contact Form, Drag and Drop Form Builder for WordPress – Everest FormsCWE-79 6.1 -2021-12-21
CVE-2021-24849 WCFM - WooCommerce Multivendor Marketplace < 3.4.12 - Unauthenticated SQL Injection — WCFM Marketplace – Best Multivendor Marketplace for WooCommerceCWE-89 9.8 -2021-12-21
CVE-2021-24846 Ni WooCommerce Custom Order Status < 1.9.7 - Subscriber+ SQL Injection — Ni WooCommerce Custom Order StatusCWE-89 8.8 -2021-12-21
CVE-2021-24750 WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection — WP Visitor Statistics (Real Time Traffic)CWE-89 8.8 -2021-12-21
CVE-2021-24739 Logo Carousel < 3.4.2 - Unauthorised Private Post Access — Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo GalleryCWE-639 8.1 -2021-12-21
CVE-2021-24738 Logo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scripting — Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo GalleryCWE-79 5.4 -2021-12-21
CVE-2021-24578 SportsPress < 2.7.9 - Reflected Cross-Site Scripting — SportsPress – Sports Club & League ManagerCWE-79 6.1 -2021-12-21
CVE-2021-24972 Pixel Cat Lite < 2.6.3 - Admin+ Stored Cross-Site Scripting — Pixel Cat – Conversion Pixel ManagerCWE-79 4.8 -2021-12-13
CVE-2021-24970 All-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusion — All-in-One Video GalleryCWE-22 7.2 -2021-12-13
CVE-2021-24955 ProfilePress < 3.2.3 - Reflected Cross-Site Scripting — User Registration, Login Form, User Profile & Membership – ProfilePress (Formerly WP User Avatar)CWE-79 6.1 -2021-12-13
CVE-2021-24954 ProfilePress < 3.2.3 - Reflected Cross-Site Scripting — User Registration, Login Form, User Profile & Membership – ProfilePress (Formerly WP User Avatar)CWE-79 6.1 -2021-12-13
CVE-2021-24951 LearnPress < 4.1.4 - Admin+ SQL Injection — LearnPress – WordPress LMS PluginCWE-89 7.2 -2021-12-13
CVE-2021-24946 Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection — Modern Events Calendar LiteCWE-89 9.8 -2021-12-13
CVE-2021-24945 Like Button Rating < 2.6.38 - Unauthorised Vote Export to Email & IP Addresses Disclosure — Like Button Rating ♥ LikeBtnCWE-200 6.5 -2021-12-13
CVE-2021-24932 Auto Featured Image < 3.9.3 - Reflected Cross-Site Scripting — Auto Featured Image (Auto Post Thumbnail)CWE-79 6.1 -2021-12-13
CVE-2021-24925 Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting — Modern Events Calendar LiteCWE-79 6.1 -2021-12-13
CVE-2021-24922 Pixel Cat Lite < 2.6.2 - CSRF to Stored Cross-Site Scripting — Pixel Cat – Conversion Pixel ManagerCWE-352 8.2 -2021-12-13
CVE-2021-24896 Caldera forms < 1.9.5 - Admin+ Stored Cross-Site Scripting — Caldera Forms – More Than Contact FormsCWE-79 4.8 -2021-12-13
CVE-2021-24872 Get Custom Field Values < 4.0 - Contributors+ Arbitrary Post Metadata Access — Get Custom Field ValuesCWE-863 6.5 -2021-12-13
CVE-2021-24871 Get Custom Field Values < 4.0.1 - Contributor+ Stored Cross-Site Scripting — Get Custom Field ValuesCWE-79 5.4 -2021-12-13

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.