Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

unknown — Vulnerabilities & Security Advisories 4151

Browse all 4151 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24755 myCred < 2.3 - Subscriber+ SQL Injection — myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty PluginCWE-89 8.8 -2021-11-29
CVE-2021-24751 GenerateBlocks < 1.4.0 - Contributor+ Stored Cross-Site Scripting — GenerateBlocksCWE-79 5.4 -2021-11-29
CVE-2021-24749 URL Shortify < 1.5.1 - Arbitrary Link/Group Deletion via CSRF — URL Shortify – Simple, Powerful and Easy URL Shortener Plugin For WordPressCWE-352 6.5 -2021-11-29
CVE-2021-24748 Email Before Download < 6.8 - Admin+ SQL Injection — Email Before DownloadCWE-89 8.8 -2021-11-29
CVE-2021-24745 About Author Box < 1.0.2 - Contributor+ Stored Cross-Site Scripting — About Author BoxCWE-79 5.4 -2021-11-29
CVE-2017-20008 myCRED < 1.7.8 - Reflected Cross-Site Scripting — myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty PluginCWE-79 6.1 -2021-11-29
CVE-2021-24894 Reviews Plus < 1.2.14 - Subscriber+ Reviews DoS — Reviews PlusCWE-191 6.5 -2021-11-23
CVE-2021-24891 Elementor < 3.4.8 - DOM Cross-Site-Scripting — Elementor Website BuilderCWE-79 6.1 -2021-11-23
CVE-2021-24888 ImageBoss < 3.0.6 - Admin+ Stored Cross-Site Scripting — ImageBoss – Images Up To 60% Smaller & CDNCWE-79 4.8 -2021-11-23
CVE-2021-24882 Slideshow Gallery < 1.7.4 - Admin+ Stored Cross-Site Scripting — Slideshow GalleryCWE-79 4.8 -2021-11-23
CVE-2021-24877 MainWP Child < 4.1.8 - Admin+ SQL Injection — MainWP Child - Securely connects sites to the MainWP WordPress Manager DashboardCWE-89 7.2 -2021-11-23
CVE-2021-24875 eCommerce Product Catalog for WordPress < 3.0.39 - Reflected Cross-Site Scripting — eCommerce Product Catalog Plugin for WordPressCWE-79 6.1 -2021-11-23
CVE-2021-24873 Tutor LMS < 1.9.11 - Reflected Cross-Site Scripting — Tutor LMS – eLearning and online course solutionCWE-79 6.1 -2021-11-23
CVE-2021-24830 Advanced Access Manager < 6.8.0 - Admin+ Stored Cross-Site Scripting — Advanced Access ManagerCWE-79 4.8 -2021-11-23
CVE-2021-24812 BetterLinks < 1.2.6 - Admin+ Stored Cross-Site Scripting — BetterLinks – Shorten, Track and Manage any URLCWE-79 5.4 -2021-11-23
CVE-2021-24729 Logo Showcase with Slick Slider < 1.2.4 - Author+ Stored Cross Site Scripting — Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo GridCWE-79 5.4 -2021-11-23
CVE-2021-24703 Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin Activation — Download PluginCWE-732 6.5 -2021-11-23
CVE-2021-24700 Forminator < 1.15.4 - Admin+ Stored Cross-Site Scripting — Forminator – Contact Form, Payment Form & Custom Form BuilderCWE-79 4.8 -2021-11-23
CVE-2021-24668 MAZ Loader < 1.4.1 - Arbitrary Loader Deletion via CSRF — MAZ Loader – Preloader Builder for WordPressCWE-352 6.5 -2021-11-23
CVE-2021-24644 Images to WebP < 1.9 - Authenticated Local File Inclusion — Images to WebPCWE-22 7.5 -2021-11-23
CVE-2021-24641 Images to WebP < 1.9 - Multiple Cross Site Request Forgery (CSRF) — Images to WebPCWE-352 8.1 -2021-11-23
CVE-2021-24856 Shared Files < 1.6.61 - Admin+ Stored Cross-Site Scripting — Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File UploadCWE-79 4.8 -2021-11-17
CVE-2021-24854 QR Redirector < 1.6.1 - Contributor+ Stored Cross-Site Scripting — QR RedirectorCWE-79 5.4 -2021-11-17
CVE-2021-24853 QR Redirector < 1.6 - Subscriber+ Arbitrary QR Redirect Response Status Update — QR RedirectorCWE-284 3.5 -2021-11-17
CVE-2021-24852 MouseWheel Smooth Scroll < 5.7 - Plugin's Setting Update via CSRF — MouseWheel Smooth ScrollCWE-352 6.5 -2021-11-17
CVE-2021-24851 Insert Pages < 3.7.0 - Contributor+ Arbitrary Posts/Pages Access — Insert PagesCWE-863 4.3 -2021-11-17
CVE-2021-24850 Insert Pages < 3.7.0 - Contributor+ Stored Cross-Site Scripting — Insert PagesCWE-79 5.4 -2021-11-17
CVE-2021-24847 SEO Redirection < 8.2 - Subscriber+ SQL Injection — SEO Redirection Plugin – 301 Redirect ManagerCWE-89 8.8 -2021-11-17
CVE-2021-24841 Helpful < 4.4.59 - Admin+ Stored Cross-Site Scripting — HelpfulCWE-79 4.8 -2021-11-17
CVE-2021-24834 YOP Poll < 6.3.1 - Author+ Stored Cross-Site Scripting via Options Module — YOP PollCWE-79 5.4 -2021-11-17

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.