Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

unknown — Vulnerabilities & Security Advisories 4151

Browse all 4151 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24597 You Shang <= 1.0.1 - Authenticated Stored Cross-Site Scripting — 有赏 You ShangCWE-79 5.4 -2021-09-20
CVE-2021-24596 youForms for WordPress <= 1.0.5 - Authenticated Stored Cross-Site Scripting — youForms for WordPress – Creating Forms for CopeCartCWE-79 4.8 -2021-09-20
CVE-2021-24587 Splash Header < 1.20.8 - Authenticated Stored Cross-Site Scripting (XSS) — Splash HeaderCWE-79 5.4 -2021-09-20
CVE-2021-24585 Timetable and Event Schedule by MotoPress < 2.4.0 - Arbitrary User's Hashed Password/Email/Username Disclosure — Timetable and Event Schedule by MotoPressCWE-200 6.5 -2021-09-20
CVE-2021-24584 Timetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot Update — Timetable and Event Schedule by MotoPressCWE-352 5.4 -2021-09-20
CVE-2021-24583 Timetable and Event Schedule by MotoPress < 2.4.2 - Unauthorised Event TimeSlot Deletion — Timetable and Event Schedule by MotoPressCWE-284 3.5 -2021-09-20
CVE-2021-24582 ThinkTwit < 1.7.1 - Authenticated Stored Cross-Site Scripting (XSS) — ThinkTwitCWE-79 5.4 -2021-09-20
CVE-2021-24530 Alojapro Widget <= 1.1.15 - Authenticated Stored Cross-Site Scripting (XSS) — Alojapro WidgetCWE-79 4.8 -2021-09-20
CVE-2021-24525 Shortcodes Ultimate < 5.10.2 - Contributor+ Stored XSS — WordPress Shortcodes Plugin — Shortcodes UltimateCWE-79 5.4 -2021-09-20
CVE-2021-24511 Create WooCommerce Product Feeds For 40+ Merchants < 3.3.1.0 - Authenticated SQL Injection — Product Feed on WooCommerce for Google, Awin, Shareasale, Bing, and MoreCWE-89 7.2 -2021-09-20
CVE-2021-24404 WP-Board <= 1.1 (beta) - Unauthenticated SQL Injection — WP-BoardCWE-89 7.2 -2021-09-20
CVE-2021-24403 WordPress Page Contact <= 1.0 - Authenticated (editor+) SQL Injection — WordPress Page ContactCWE-89 7.2 -2021-09-20
CVE-2021-24402 WP iCommerce <= 1.1.1 - Authenticated (contributor+) SQL Injection — WP iCommerce – the first interactive ecommerce for wordpressCWE-89 7.2 -2021-09-20
CVE-2021-24401 WP Domain Redirect <= 1.0 - Authenticated SQL Injection — WP Domain RedirectCWE-89 7.2 -2021-09-20
CVE-2021-24400 Display users <= 2.0.0 - Authenticated SQL Injection — Display UsersCWE-89 7.2 -2021-09-20
CVE-2021-24399 The Sorter <= 1.0 - Authenticated SQL Injection — The SorterCWE-89 7.2 -2021-09-20
CVE-2021-24398 Responsive 3D Slider <= 1.2 - Authenticated SQL Injection — RESPONSIVE 3D SLIDERCWE-89 7.2 -2021-09-20
CVE-2021-24397 MicroCopy <= 1.1.0 - Authenticated SQL Injection — MicroCopyCWE-89 7.2 -2021-09-20
CVE-2021-24396 GSEOR <= 1.3 - Authenticated SQL Injection — GSEOR – WordPress SEO PluginCWE-89 7.2 -2021-09-20
CVE-2021-24728 Paid Member Subscriptions < 2.4.2 - Authenticated SQL Injection — Membership & Content Restriction – Paid Member SubscriptionsCWE-89 8.8 -2021-09-13
CVE-2021-24727 Block and Stop Bad Bots < 6.60 - Authenticated SQL Injections — WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBotsCWE-89 8.8 -2021-09-13
CVE-2021-24726 WP Simple Booking Calendar <= 2.0.6 (before 07/12/2021) - Authenticated SQL Injection — WP Simple Booking CalendarCWE-89 7.2 -2021-09-13
CVE-2021-24725 Comment Link Remove and Other Comment Tools < 2.1.6 - Arbitrary Comment Deletion via CSRF — Comment Link Remove and Other Comment ToolsCWE-352 6.5 -2021-09-13
CVE-2021-24724 Timetable and Event Schedule by MotoPress < 2.3.19 - Author+ Stored Cross-Site Scripting — Timetable and Event Schedule by MotoPressCWE-79 5.4 -2021-09-13
CVE-2021-24623 WordPress Advanced Ticket System < 1.0.64 - Authenticated Stored Cross-Site Scripting (XSS) — WordPress Advanced Ticket System, Elite Support HelpdeskCWE-79 4.8 -2021-09-13
CVE-2021-24621 WP Courses LMS < 2.0.44 - Authenticated Stored XSS via Video Embed Code — WP Courses LMSCWE-79 6.9 -2021-09-13
CVE-2021-24620 Simple eCommerce <= 2.2.5 - Arbitrary File Upload — WordPress Simple Ecommerce Shopping Cart Plugin- Sell products through PaypalCWE-434 9.8 -2021-09-13
CVE-2021-24619 Per Page Add to Head <= 1.4.4 - Authenticated Stored XSS — Per page add to headCWE-79 4.8 -2021-09-13
CVE-2021-24614 Book appointment Online < 1.39 - Authenticated Stored Cross-Site Scripting (XSS) — Book appointment onlineCWE-79 4.8 -2021-09-13
CVE-2021-24605 Custom Post View Generator <= 0.4.6 - Reflected Cross-Site Scripting — Custom Post View GeneratorCWE-79 5.4 -2021-09-13

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.