Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

unknown — Vulnerabilities & Security Advisories 4151

Browse all 4151 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-3986 SportsPress < 2.7.22 - Admin+ Stored XSS — SportsPress 4.8AIMediumAI2024-07-30
CVE-2024-4096 Responsive Tabs <= 4.0.8 - Contributor+ Stored XSS — Responsive Tabs 4.8AIMediumAI2024-07-30
CVE-2024-5807 Business Card <= 1.0.0 - Admin+ File Upload — Business Card 7.2AIHighAI2024-07-30
CVE-2024-5765 WpStickyBar <= 2.1.0 - Unauthenticated SQLi — WpStickyBar 9.8AICriticalAI2024-07-30
CVE-2024-3669 Web Directory Free < 1.7.2 - Reflected XSS — Web Directory Free 6.1AIMediumAI2024-07-30
CVE-2024-3113 FormFlow < 2.12.2 - Admin+ Stored XSS — FormFlow: WhatsApp Social and Advanced Form Builder with Easy Lead Collection 4.8AIMediumAI2024-07-30
CVE-2024-1287 Paid Memberships Pro - Member Directory Add On < 1.2.6 - Contributor+ Sensitive Information Disclosure via SQLi — pmpro-member-directory 6.5AIMediumAI2024-07-30
CVE-2024-1286 Paid Memberships Pro - Membership Maps Add On < 0.7 - Contributor+ Sensitive Information Disclosure — pmpro-membership-maps 4.3AIMediumAI2024-07-30
CVE-2024-6487 Inline Related Posts < 3.8.0 - Admin+ Stored XSS — Inline Related Posts 4.8AIMediumAI2024-07-29
CVE-2024-6366 User Profile Builder < 3.11.8 - Unauthenticated Media Upload — User Profile Builder 7.5AIHighAI2024-07-29
CVE-2024-6362 Ultimate Blocks < 3.2.0 - Contributor+ Stored XSS — Ultimate Blocks 5.4AIMediumAI2024-07-29
CVE-2024-5883 Ultimate Classified Listings < 1.3 - Reflected XSS — Ultimate Classified Listings 6.1AIMediumAI2024-07-29
CVE-2024-5882 Ultimate Classified Listings < 1.3 - Unauthenticated LFI — Ultimate Classified Listings 7.5AIHighAI2024-07-29
CVE-2024-5285 WP Affiliate Platform < 6.5.2 - Affiliate Deletion via CSRF — wp-affiliate-platform 4.3AIMediumAI2024-07-29
CVE-2024-4483 Email Encoder < 2.2.2 - Admin+ Stored XSS — Email Encoder 5.4AIMediumAI2024-07-29
CVE-2024-6490 Master Slider – Responsive Touch Slider <= 3.9.10 - CSRF to slider deletion — Master Slider 7.1 -2024-07-26
CVE-2024-6094 WP ULike < 4.7.1 - Admin+ Stored XSS — WP ULike 4.8AIMediumAI2024-07-24
CVE-2024-6420 Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure — Hide My WP Ghost 6.1AIMediumAI2024-07-23
CVE-2024-6231 Request a Quote < 2.4.1 - Admin+ Stored XSS — Request a Quote 4.8AIMediumAI2024-07-23
CVE-2024-4260 CoBlocks < 3.1.12 - Contributor+ SSRF — Page Builder Gutenberg Blocks 4.9AIMediumAI2024-07-23
CVE-2024-6271 Community Events < 1.5 - Event Deletion via CSRF — Community Events 4.3AIMediumAI2024-07-22
CVE-2024-6243 HTML Forms < 1.3.33 - Admin+ Stored XSS — HTML Forms 4.8AIMediumAI2024-07-22
CVE-2024-5973 MasterStudy LMS < 3.3.24 - Privilege Escalation to Instructor — MasterStudy LMS WordPress Plugin 8.1AIHighAI2024-07-22
CVE-2024-6244 pz-frontend-manager < 1.0.6 - CSRF change user profile picture — PZ Frontend Manager 8.8AIHighAI2024-07-22
CVE-2024-5529 WP QuickLaTeX < 3.8.8 - Admin+ Stored XSS — WP QuickLaTeX 4.8AIMediumAI2024-07-22
CVE-2024-5004 CM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSS — CM Popup Plugin for WordPress 4.8AIMediumAI2024-07-22
CVE-2024-5604 Bug Library < 2.1.2 - Admin+ Stored XSS — Bug Library 4.8 -2024-07-19
CVE-2024-6205 PayPlus Payment Gateway < 6.6.9 - Unauthenticated SQLi — PayPlus Payment Gateway 9.8 -2024-07-19
CVE-2023-7269 ArtPlacer Widget < 2.21.2 - Stored XSS via CSRF — ArtPlacer Widget 6.1 -2024-07-19
CVE-2023-7268 ArtPlacer Widget < 2.21.2 - Subscriber+ Arbitrary Widget Deletion — ArtPlacer Widget 4.3 -2024-07-19

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.