Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-3236 Easy Notify Lite < 1.1.33 - Contributor+ Stored XSS — Popup Builder 5.4AIMediumAI2024-06-17
CVE-2024-4305 PostX < 4.1.0 - Contributor+ Stored XSS — Post Grid Gutenberg Blocks and WordPress Blog Plugin 5.4AIMediumAI2024-06-17
CVE-2024-4751 WP Prayer II <= 2.4.7 - Settings Update via CSRF — WP Prayer II 4.3AIMediumAI2024-06-14
CVE-2024-4480 WP Prayer II <= 2.4.7 - Email Settings Update via CSRF — WP Prayer II 4.3AIMediumAI2024-06-14
CVE-2024-5155 Inquiry Cart <= 3.4.2 - Stored XSS via CSRF — Inquiry cart 6.1AIMediumAI2024-06-14
CVE-2024-4271 SVGator <= 1.2.6 - Stored XSS via SVG Upload — SVGator 5.4AIMediumAI2024-06-14
CVE-2024-3992 Amen <= 3.3.1 - Admin+ Stored XSS — Amen 4.8AIMediumAI2024-06-14
CVE-2024-4005 Social Pixel <= 2.1 - Admin+ Stored XSS — Social Pixel 4.8AIMediumAI2024-06-14
CVE-2024-3993 AZAN Plugin <= 0.6 - Stored XSS via CSRF — AZAN Plugin 6.1AIMediumAI2024-06-14
CVE-2024-3978 WordPress Jitsi Shortcode <= 0.1 - Contributor+ Stored XSS via Shortcode — WordPress Jitsi Shortcode 5.4AIMediumAI2024-06-14
CVE-2024-3977 WordPress Jitsi Shortcode <= 0.1 - Admin+ Stored XSS — WordPress Jitsi Shortcode 4.8AIMediumAI2024-06-14
CVE-2024-4270 SVGMagic <= 1.1 - Stored XSS via SVG Upload — SVGMagic 5.4AIMediumAI2024-06-14
CVE-2024-3972 Similarity <= 3.0 - Stored XSS via CSRF — Similarity 6.1AIMediumAI2024-06-14
CVE-2024-3754 Alemha Watermarker <= 1.3.1 - Author+ Stored XSS — Alemha watermarker 4.8AIMediumAI2024-06-14
CVE-2024-3971 Similarity <= 3.0 - Plugin Reset via CSRF — Similarity 4.3AIMediumAI2024-06-14
CVE-2024-3965 Pray For Me <= 1.0.4 - Settings Update via CSRF — Pray For Me 4.3AIMediumAI2024-06-14
CVE-2024-3966 Pray For Me <= 1.0.4 - Unauthenticated Stored XSS — Pray For Me 6.1AIMediumAI2024-06-14
CVE-2024-1295 The Events Calendar (Free < 6.4.0.1, Pro < 6.4.0.1) - Contributor+ Arbitrary Events Access — events-calendar-pro 4.3AIMediumAI2024-06-14
CVE-2024-2218 LuckyWP Table of Contents <= 2.1.4 - Admin+ Stored XSS — LuckyWP Table of Contents 4.8AIMediumAI2024-06-14
CVE-2024-3032 Themify Builder < 7.5.8 - Open Redirect — Themify Builder 6.1AIMediumAI2024-06-13
CVE-2024-3552 Web Directory Free < 1.7.0 - Unauthenticated SQL Injection — Web Directory Free 9.8AICriticalAI2024-06-13
CVE-2024-4149 Floating Chat Widget < 3.2.3 - Admin+ Stored XSS — Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button 4.8AIMediumAI2024-06-13
CVE-2024-4145 Search & Replace < 3.2.2 - Admin+ SQL injection — Search & Replace 7.2AIHighAI2024-06-13
CVE-2024-2762 FooGallery < 2.4.15 - Author+ Stored XSS — FooGallery 5.4AIMediumAI2024-06-13
CVE-2024-0427 Arforms < 6.4.1 - Reflected XSS — ARForms - Premium WordPress Form Builder Plugin 9.3AICriticalAI2024-06-12
CVE-2024-4924 Sassy social share < 3.3.63 Admin+ Stored Cross-Site scripting — Social Sharing Plugin 4.8AIMediumAI2024-06-12
CVE-2024-4621 ArForms < 6.6 - Admin+ Stored XSS — ARForms - Premium WordPress Form Builder Plugin 4.8 -2024-06-07
CVE-2024-5003 WP Stacker <= 1.8.5 - Stored XSS via CSRF — WP Stacker 6.1 -2024-06-07
CVE-2024-4756 WP Backpack <= 2.1 - Admin+ Stored XSS — WP Backpack 4.8 -2024-06-07
CVE-2024-3288 Logo Slider < 4.0.0 - Contributor+ Stored XSS — Logo Slider 5.4 -2024-06-07

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.