Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13925 Klarna Checkout for WooCommerce < 2.13.5 - DoS via Excessive Logging — Klarna Checkout for WooCommerce 7.5AIHighAI2025-04-17
CVE-2024-11924 Email Subscribers < 5.7.52 - Admin+ Stored XSS — Icegram Express formerly known as Email Subscribers 4.8 -2025-04-17
CVE-2024-10680 Form Maker by 10Web < 1.15.32 - Admin+ Stored XSS — Form Maker by 10Web 4.8AIMediumAI2025-04-16
CVE-2024-13610 Simple Social Media Share Buttons < 6.0.0 - Admin+ Stored XSS — Simple Social Media Share Buttons 4.8AIMediumAI2025-04-15
CVE-2024-13207 Widget for Social Page Feeds < 6.4.2 - Admin+ Stored XSS — Widget for Social Page Feeds 4.8AIMediumAI2025-04-15
CVE-2025-2563 User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation — User Registration & Membership 9.8AICriticalAI2025-04-14
CVE-2024-9230 PowerPress Podcasting < 11.9.18 - Author+ XSS via Podcast URL — PowerPress Podcasting plugin by Blubrry 5.4AIMediumAI2025-04-14
CVE-2024-13896 WP-GeSHi-Highlight <= 1.4.3 - Author+ ReDoS — WP-GeSHi-Highlight — rock-solid syntax highlighting for 259 languages 7.5AIHighAI2025-04-10
CVE-2024-13874 Feedify – Web Push Notifications < 2.4.6 - Reflected XSS — Feedify 6.1AIMediumAI2025-04-10
CVE-2024-8243 Plugin Upgrade Time Out <= 1.0 - Stored XSS via CSRF — WordPress/Plugin Upgrade Time Out Plugin 6.1AIMediumAI2025-04-09
CVE-2024-6860 WP MultiTasking <= 0.1.12 - Permalink Suffix Update via CSRF — WP MultiTasking 7.1AIHighAI2025-04-09
CVE-2024-6857 WP MultiTasking <= 0.1.12 - Header/Footer/Body Script Update via CSRF — WP MultiTasking 8.3AIHighAI2025-04-09
CVE-2025-2279 Maps - Google Maps <= 1.0.6 - Contributor+ Stored XSS — Maps 5.4AIMediumAI2025-04-04
CVE-2025-2055 MapPress Maps for WordPress < 2.94.9 - Contributor+ Stored XSS — MapPress Maps for WordPress 5.4AIMediumAI2025-04-03
CVE-2025-2048 Lana Downloads Manager < 1.10.0 - Admin+ Arbitrary File Download via Path Traversal — Lana Downloads Manager 4.9 -2025-04-01
CVE-2025-1986 Gutentor < 3.4.7 - Admin+ SQL Injection — Gutentor 7.2 -2025-04-01
CVE-2025-0613 Photo Gallery < 1.8.34 - Unauthenticated Stored XSS — Photo Gallery by 10Web 6.1 -2025-03-31
CVE-2025-1762 Event Tickets with Ticket Scanner < 2.5.4 - Arbitrary Tickets Deletion via CSRF — Event Tickets with Ticket Scanner 4.3 -2025-03-28
CVE-2024-13146 Booknetic < 4.1.5 - Staff Creation via CSRF — Booknetic 6.5AIMediumAI2025-03-26
CVE-2024-12683 Smart Maintenance Mode < 1.5.2 - Admin+ Stored XSS — Smart Maintenance Mode 4.8AIMediumAI2025-03-26
CVE-2024-11847 WP SVG Upload <= 1.0.0 - Author+ Stored XSS via SVG — wp-svg-upload 5.4AIMediumAI2025-03-26
CVE-2025-1798 Design Comuni Italia < 1.1.2 - Unauthenticated Stored XSS — design-comuni-wordpress-theme 6.1 -2025-03-25
CVE-2024-9770 WP-Recall < 16.26.12 - Admin+ SQL Injection — WP-Recall 7.2 -2025-03-25
CVE-2025-1452 Favorites < 2.3.5 - Admin+ Stored XSS — Favorites 4.8 -2025-03-25
CVE-2025-0717 Social Slider Feed < 2.2.9 - Admin+ Stored XSS — Social Slider Feed 9.3 -2025-03-25
CVE-2024-13863 Stylish Google Sheet Reader < 4.1 - Reflected XSS — Stylish Google Sheet Reader 4.0 6.1 -2025-03-25
CVE-2024-13122 AFI < 1.100.0 - Admin+ Stored XSS — AFI 4.8 -2025-03-25
CVE-2024-13123 AFI < 1.100.0 - Admin+ Stored XSS — AFI 4.8 -2025-03-25
CVE-2024-13618 Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated SSRF — aoa-downloadable 7.5 -2025-03-25
CVE-2024-13617 Downloable by American Osteopathic Association <= 0.1.0 - Unauthenticated Arbitrary File Download — aoa-downloadable 7.5 -2025-03-25

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.