Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

unknown — Vulnerabilities & Security Advisories 4427

Browse all 4427 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-0420 RegistrationMagic < 5.0.2.2 - Admin+ SQL Injection — RegistrationMagic – Custom Registration Forms, User Registration and User Login PluginCWE-89 7.2 -2022-03-07
CVE-2022-0410 WP Visitor Statistics (Real Time Traffic) < 5.6 - Subscriber+ SQL Injection — WP Visitor Statistics (Real Time Traffic)CWE-89 8.8 -2022-03-07
CVE-2022-0389 WP Time Slots Booking Form < 1.1.63 - Admin+ Stored Cross-Site Scripting — WP Time Slots Booking FormCWE-79 4.8 -2022-03-07
CVE-2022-0384 Video Conferencing with Zoom < 3.8.17 - E-mail Address Disclosure — Video Conferencing with ZoomCWE-200 4.3 -2022-03-07
CVE-2022-0349 NotificationX < 2.3.9 - Unauthenticated Blind SQL Injection — NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With ElementorCWE-89 9.8 -2022-03-07
CVE-2022-0347 LoginPress < 1.5.12 - Reflected Cross-Site Scripting — LoginPress | Custom Login Page CustomizerCWE-79 6.1 -2022-03-07
CVE-2022-0267 AdRotate < 5.8.22 - Admin+ SQL Injection — AdRotate – Ad manager & AdSense AdsCWE-89 7.2 -2022-03-07
CVE-2022-0205 YOP Poll < 6.3.5 - Author+ Stored Cross-Site Scripting — YOP PollCWE-79 5.4 -2022-03-07
CVE-2022-0163 Smart Forms < 2.6.71 - Subscriber+ Form Data Download — Smart Forms – when you need more than just a contact formCWE-862 6.5 -2022-03-07
CVE-2021-25098 Easy Pricing Tables < 3.1.3 - Arbitrary Post Removal via CSRF — Pricing Tables WordPress Plugin – Easy Pricing TablesCWE-352 6.5 -2022-03-07
CVE-2021-25087 Wordpress Download Manager < 3.2.25 - Sensitive Information Disclosure — Download ManagerCWE-862 7.5 -2022-03-07
CVE-2021-25039 Multisite Content Copier/Updater < 2.1.0 - Reflected Cross-Site Scripting — WordPress Multisite Content Copier/UpdaterCWE-79 6.1 -2022-03-07
CVE-2021-25038 Multisite User Sync/Unsync < 2.1.2 - Reflected Cross-Site Scripting — WordPress Multisite User Sync/UnsyncCWE-79 6.1 -2022-03-07
CVE-2021-25009 CorreosExpress <= 2.6.0 - Sensitive Information Disclosure — CorreosExpress – Shipping Management – TagsCWE-532 5.3 -2022-03-07
CVE-2021-24961 WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Shortcode — WordPress File UploadCWE-79 5.4 -2022-03-07
CVE-2021-24960 WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Malicious SVG — WordPress File UploadCWE-434 5.4 -2022-03-07
CVE-2021-24953 Advanced iFrame < 2022 - Reflected Cross-Site Scripting — Advanced iFrameCWE-79 6.1 -2022-03-07
CVE-2021-24952 Conversios.io < 4.6.2 - Subscriber+ SQL Injection — Conversios.io – Google Analytics and Google Shopping plugin for WooCommerceCWE-89 8.8 -2022-03-07
CVE-2021-24826 Custom Content Shortcode < 4.0.2 - Authenticated Stored Cross-Site Scripting — Custom Content ShortcodeCWE-79 5.4 -2022-03-07
CVE-2021-24825 Custom Content Shortcode < 4.0.2 - Authenticated Arbitrary File Access / LFI — Custom Content ShortcodeCWE-345 4.3 -2022-03-07
CVE-2021-24824 Custom Content Shortcode < 4.0.1 - Unauthorised Arbitrary Post Metadata Access — Custom Content ShortcodeCWE-863 4.3 -2022-03-07
CVE-2021-24821 Cost Calculator < 1.6 - Contributor+ Stored Cross-Site Scripting — Cost CalculatorCWE-79 5.4 -2022-03-07
CVE-2021-24810 WP Event Manager < 3.1.23 - Admin+ Stored Cross-Site Scripting — WP Event Manager – Easily Build your Calendar of Events!CWE-79 4.8 -2022-03-07
CVE-2021-24778 Tradetracker-Store < 4.6.60 - Admin+ SQL Injection — Tradetracker-StoreCWE-89 7.2 -2022-03-07
CVE-2021-24777 Hotscot Contact Form < 1.3 - Admin+ SQL Injection — Hotscot Contact FormCWE-89 7.2 -2022-03-07
CVE-2021-24216 All-in-One WP Migration < 7.41 - Admin+ Arbitrary File Upload to RCE — All-in-One WP MigrationCWE-434 7.2 -2022-03-07
CVE-2022-23912 AP Custom Testimonial < 1.4.8 - Reflected Cross-Site Scripting — Testimonial WordPress Plugin – AP Custom TestimonialCWE-79 6.1 -2022-02-28
CVE-2022-23911 AP Custom Testimonial < 1.4.8 - Admin+ SQL Injection — Testimonial WordPress Plugin – AP Custom TestimonialCWE-89 7.2 -2022-02-28
CVE-2022-0411 Asgaros Forum < 2.0.0 - Subscriber+ Blind SQL Injection — Asgaros ForumCWE-89 8.8 -2022-02-28
CVE-2022-0385 Crazy Bone <= 0.6.0 - Unauthenticated Stored XSS — Crazy BoneCWE-79 6.1 -2022-02-28

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.