Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4151

Browse all 4151 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-0763 Clock In Portal <= 2.1 - Holidays Deletion via CSRF — Clock In Portal- Staff & Attendance Management 4.3 -2023-05-15
CVE-2023-1596 tagDiv Composer < 4.0 - Reflected Cross-site Scripting — tagDiv Composer 6.1 -2023-05-15
CVE-2023-2179 WooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status Update — WooCommerce Order Status Change Notifier 4.3 -2023-05-15
CVE-2023-2180 KIWIZ Invoices Certification & PDF System <= 2.1.3 - Unauthenticated Arbitrary File Download — KIWIZ Invoices Certification & PDF System 9.8 -2023-05-15
CVE-2023-0892 BizLibrary <= 1.1 - Admin+ Stored XSS — BizLibrary 4.8 -2023-05-15
CVE-2023-0762 Clock In Portal <= 2.1 - Designation Deletion via CSRF — Clock In Portal- Staff & Attendance Management 6.5 -2023-05-15
CVE-2023-1915 Thumbnail carousel slider < 1.1.10 - Reflected XSS — Thumbnail carousel slider 6.1 -2023-05-15
CVE-2023-0600 WP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi — WP Visitor Statistics (Real Time Traffic) 9.8 -2023-05-15
CVE-2023-1549 Ad Inserter < 2.7.27 - Admin+ PHP Object Injection — Ad Inserter 7.2 -2023-05-15
CVE-2023-1207 HTTP Headers < 1.18.8 - Admin+ SQL Injection — HTTP Headers 9.8 -2023-05-15
CVE-2023-0268 Mega Addons For WPBakery Page Builder < 4.3.0 - Contributor+ Stored XSS — Mega Addons For WPBakery Page Builder 5.4 -2023-05-08
CVE-2023-0526 Post Shortcode <= 2.0.9 - Contributor+ Stored Cross-Site Scripting — Post Shortcode 5.4 -2023-05-08
CVE-2023-0603 Sloth Logo Customizer <= 2.0.2 - Stored XSS via CSRF — Sloth Logo Customizer 6.1 -2023-05-08
CVE-2023-0537 Product Slider For WooCommerce Lite <= 1.1.7 - Contributor+ Stored XSS — Product Slider For WooCommerce Lite 5.4 -2023-05-08
CVE-2023-1408 Video List Manager <= 1.7 - Admin+ SQL Injection — Video List Manager 7.2 -2023-05-08
CVE-2022-4118 Bitcoin / AltCoin Payment Gateway <= 1.7.1 - Unauthenticated SQLi — Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop 7.2 -2023-05-08
CVE-2023-1347 Customizer Export/Import < 0.9.6 - Admin+ PHP Object Injection — Customizer Export/Import 7.2 -2023-05-08
CVE-2023-0280 Ultimate Carousel For Elementor <= 2.1.7 - Contributor+ Stored XSS — Ultimate Carousel For Elementor 5.4 -2023-05-08
CVE-2023-0536 Wp-D3 <= 2.4.1 - Contributor+ Stored XSS — Wp-D3 5.4 -2023-05-08
CVE-2023-1649 ChatBot < 4.5.1 - Admin+ Stored XSS — AI ChatBot 4.8 -2023-05-08
CVE-2023-1806 WP Inventory Manager < 2.1.0.12 - Reflected XSS — WP Inventory Manager 6.1 -2023-05-08
CVE-2023-1650 ChatBot < 4.4.7 - Unauthenticated PHP Object Injection — AI ChatBot 9.8 -2023-05-08
CVE-2023-0542 Custom Post Type List Shortcode <= 1.4.4 - Contributor+ Stored XSS — Custom Post Type List Shortcode 5.4 -2023-05-08
CVE-2023-0514 Membership Database <= 1.0 - Reflected XSS — Membership Database 6.1 -2023-05-08
CVE-2023-1651 ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSS — AI ChatBot 6.4 -2023-05-08
CVE-2023-2114 NEX-Forms < 8.4 - Admin+ SQL Injection — NEX-Forms 9.8 -2023-05-08
CVE-2023-0522 Enable/Disable Auto Login when Register <= 1.1.0 - Settings Update via CSRF — Enable/Disable Auto Login when Register 4.3 -2023-05-08
CVE-2023-1011 ChatBot < 4.4.5 - Stored XSS via CSRF — AI ChatBot 8.2 -2023-05-08
CVE-2023-0544 WP Login Box <= 2.0.2 - Admin+ Stored XSS — WP Login Box 4.8 -2023-05-08
CVE-2023-1660 ChatBot < 4.4.9 - Unauthenticated Stored XSS — AI ChatBot 6.1 -2023-05-08

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.