Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Unknown — Vulnerabilities & Security Advisories 4148

Browse all 4148 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-3248 All-in-one Floating Contact Form < 2.1.2 - Admin+ Stored Cross-Site Scripting — All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs 4.8 -2023-07-24
CVE-2023-2309 wpForo Forum < 2.1.9 - Reflected Cross-Site Scripting — wpForo Forum 6.1 -2023-07-24
CVE-2023-3344 Auto Location for WP Job Manager via Google < 1.1 - Admin+ Cross Site Scripting — Auto Location for WP Job Manager via Google 4.8 -2023-07-24
CVE-2023-2701 Gravity Forms < 2.7.5 - Reflected XSS — gravityforms 6.1 -2023-07-17
CVE-2023-0439 NEX-Forms < 8.4.4 - Authenticated Stored XSS — NEX-Forms 4.8 -2023-07-17
CVE-2023-2330 Caldera Forms Google Sheets Connector < 1.3 - Access Code Update via CSRF — Caldera Forms Google Sheets Connector 6.5 -2023-07-17
CVE-2023-3182 Membership Plugin - Restrict Content < 3.2.3 - Reflected XSS — Membership Plugin 6.1 -2023-07-17
CVE-2023-3245 Floating Chat Widget < 3.1.2 - Admin+ Stored Cross-Site Scripting — Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button 4.8 -2023-07-17
CVE-2023-3179 POST SMTP Mailer < 2.5.7 - Account Takeover via CSRF — POST SMTP Mailer 8.8 -2023-07-17
CVE-2023-1893 Login Configurator <= 2.1 - Reflected Cross-Site Scripting — Login Configurator 6.1 -2023-07-17
CVE-2023-2143 Enable SVG, WebP & ICO Upload <= 1.0.3 - Author+ Stored XSS — Enable SVG, WebP & ICO Upload 6.1 -2023-07-17
CVE-2023-2636 AN_GradeBook <= 5.0.1 - Subscriber+ SQLi — AN_GradeBook 8.8 -2023-07-17
CVE-2023-3186 Supsystic Popup < 1.10.19 - Prototype Pollution — Popup by Supsystic 9.8 -2023-07-17
CVE-2023-3041 Autochat <= 1.1.7- Unauthenticated Stored XSS — Autochat Automatic Conversation 5.4 -2023-07-17
CVE-2023-2329 WooCommerce Google Sheet Connector < 1.3.6 - Access Code Update via CSRF — WooCommerce Google Sheet Connector 6.5 -2023-07-17
CVE-2023-2579 InventoryPress <= 1.7 - Author+ Stored XSS — InventoryPress 5.4 -2023-07-17
CVE-2022-4023 3DPrint < 3.5.6.9 - CSRF to arbitrary file downlad — 3dprint 6.5 -2023-07-17
CVE-2023-1208 HTTP Headers < 1.18.11 - Admin+ Remote Code Execution — HTTP Headers 9.8 -2023-07-10
CVE-2023-3219 EventON < 2.1.2 - Unauthenticated Post Access via IDOR — EventON 7.5 -2023-07-10
CVE-2023-3131 MStore API < 3.9.7 - Subscriber+ Unauthorized Settings Update — MStore API 9.1 -2023-07-10
CVE-2023-3225 Float menu < 5.0.3 - Admin+ Stored Cross-Site Scripting — Float menu 4.8 -2023-07-10
CVE-2023-2967 TinyMCE Custom Styles < 1.1.4 - Admin+ Stored Cross-Site Scripting — TinyMCE Custom Styles 4.8 -2023-07-10
CVE-2023-2635 Call Now Accessibility Button < 1.1 - Admin+ Stored XSS — Call Now Accessibility Button 4.8 -2023-07-10
CVE-2023-3209 MStore API < 3.9.7 - Settings Update via CSRF — MStore API 9.1 -2023-07-10
CVE-2023-2029 PrePost SEO <= 3.0 - Admin+ Stored Cross-Site Scripting — PrePost SEO 4.8 -2023-07-10
CVE-2023-2028 Call Now Accessibility Button < 1.1 - Admin+ Stored Cross Site Scripting — Call Now Accessibility Button 4.8 -2023-07-10
CVE-2023-3175 AI ChatBot < 4.6.1 - Admin+ Stored Cross-Site Scripting — AI ChatBot 4.8 -2023-07-10
CVE-2023-2709 AN_GradeBook <= 5.0.1 - Admin+ XSS — AN_GradeBook 4.8 -2023-07-10
CVE-2023-3118 Export All URLs < 4.6 - Reflected XSS — Export All URLs 6.1 -2023-07-10
CVE-2023-2529 Enable SVG Uploads <= 2.1.5 - Author+ Stored XSS via SVG — Enable SVG Uploads 5.4 -2023-07-10

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.