Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-6719 Offload Videos – Bunny.net, AWS S3 <= 1.0.1 Subscriber+ CSRF — Offload Videos 3.5AILowAI2025-05-15
CVE-2024-6798 DL Verification <= 1.2 - Admin+ Stored XSS — DL Verification 4.8AIMediumAI2025-05-15
CVE-2024-6718 PVN Auth Popup <= 1.0.0 - Contributor+ XSS via Shortcode — PVN Auth Popup 5.4AIMediumAI2025-05-15
CVE-2024-6713 PVN Auth Popup <= 1.0.0 - Admin+ Stored XSS — PVN Auth Popup 4.8AIMediumAI2025-05-15
CVE-2024-6693 WP Content Copy Protection & No Right Click (premium) <= 15.0 - Admin+ Stored XSS — wccp-pro 4.8AIMediumAI2025-05-15
CVE-2024-6668 profilepro <= 1.3 - Subscriber+ Stored Cross Site Scripting — ProfilePro 5.4AIMediumAI2025-05-15
CVE-2024-6708 Profile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting — User Profile Builder 4.8AIMediumAI2025-05-15
CVE-2024-6712 MapFig Studio <= 0.2.1 - Stored XSS via CSRF — MapFig Studio 6.1AIMediumAI2025-05-15
CVE-2024-6690 WP Content Copy Protection & No Right Click (premium) < 15.3 - Open Redirect — wccp-pro 6.1AIMediumAI2025-05-15
CVE-2024-6584 Jetpack Boost < 3.4.7 - Admin+ SSRF — Jetpack Boost 4.9AIMediumAI2025-05-15
CVE-2024-6665 kbucket < 4.1.6 - Admin+ Stored XSS — KBucket: Your Curated Content in WordPress 4.8AIMediumAI2025-05-15
CVE-2024-6667 kbucket < 4.1.5 - Reflected XSS — KBucket: Your Curated Content in WordPress 6.1AIMediumAI2025-05-15
CVE-2024-6486 ImageMagick Engine < 1.7.11 - Administrator+ OS Command Injection — ImageMagick Engine 7.2AIHighAI2025-05-15
CVE-2024-6335 Tracking Code Manager < 2.3.0- Admin+ Stored Cross-Site Scripting — Tracking Code Manager 4.8AIMediumAI2025-05-15
CVE-2024-6159 Push Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLi — Push Notification for Post and BuddyPress 9.8AICriticalAI2025-05-15
CVE-2024-6462 DL Yandex Metrika <= 1.2 - Admin+ Stored XSS — DL Yandex Metrika 4.8AIMediumAI2025-05-15
CVE-2024-6478 CTT Expresso para WooCommerce < 3.2.13 - Admin+ Stored XSS — CTT Expresso para WooCommerce 4.8AIMediumAI2025-05-15
CVE-2024-5440 If-So Dynamic Content Personalization < 1.8.0.3 - Contributor+ Shortcode Stored XSS — If-So Dynamic Content Personalization 5.4AIMediumAI2025-05-15
CVE-2024-5026 CM Tooltip Glossary < 4.3.4 - Admin+ Stored XSS — CM Tooltip Glossary 4.8AIMediumAI2025-05-15
CVE-2024-13828 Badgearoo <= 1.0.14 - Reflected XSS — Badgearoo 6.1AIMediumAI2025-05-15
CVE-2024-13823 360 Product Rotation <= 1.5.8 - Reflected XSS — 360 Product Rotation 6.1AIMediumAI2025-05-15
CVE-2024-13865 drm-protected-video-streaming <= 4.2.1 - Reflected XSS — S3Player 6.1AIMediumAI2025-05-15
CVE-2024-13729 Podlove Podcast Publisher < 4.1.24 - Admin+ Stored XSS — Podlove Podcast Publisher 4.8AIMediumAI2025-05-15
CVE-2024-13621 The GDPR Framework By Data443 < 2.2.0 - Admin+ Stored XSS — The GDPR Framework By Data443 4.8AIMediumAI2025-05-15
CVE-2024-13727 MemberSpace – Membership Plugin and Paid Subscriptions < 2.1.14 - Reflected XSS — MemberSpace 6.1AIMediumAI2025-05-15
CVE-2024-13730 Podlove Podcast Publisher < 4.2.1 - Admin+ Stored XSS — Podlove Podcast Publisher 4.8AIMediumAI2025-05-15
CVE-2024-13619 LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes < 8.0.1 - Reflected XSS — LifterLMS 6.1AIMediumAI2025-05-15
CVE-2024-13616 VikBooking < 1.7.2 - Admin+ Stored XSS — VikBooking Hotel Booking Engine & PMS 4.8AIMediumAI2025-05-15
CVE-2024-13486 Icegram Engage < 3.1.32 - Admin+ Stored XSS — Icegram Engage 4.8AIMediumAI2025-05-15
CVE-2024-13482 Icegram Engage < 3.1.32 - Admin+ Stored XSS — Icegram Engage 4.8AIMediumAI2025-05-15

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.