Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4372 Carousel Slider < 2.2.11 - Editor+ Stored XSS — Carousel Slider 5.4AIMediumAI2024-05-21
CVE-2024-4061 Survey Maker < 4.2.9 - Admin+ Stored XSS via Plugin Settings — Survey Maker 4.8AIMediumAI2024-05-21
CVE-2024-4290 Sailthru Triggermail <= 1.1 - Admin+ Stored XSS — Sailthru Triggermail 4.8AIMediumAI2024-05-21
CVE-2024-4289 Sailthru Triggermail <= 1.1 - Reflected XSS — Sailthru Triggermail 6.1AIMediumAI2024-05-21
CVE-2024-2189 Social Icons Widget & Block < 4.2.18 - Admin+ Stored XSS — Social Icons Widget & Block by WPZOOM 4.8AIMediumAI2024-05-21
CVE-2024-3368 All in One SEO < 4.6.1.1 - Contributor+ Stored XSS — All in One SEO 5.4AIMediumAI2024-05-20
CVE-2024-3580 Popup4Phone <= 1.3.2 - Editor+ Stored XSS — Popup4Phone 4.8 -2024-05-17
CVE-2024-2697 Swift Framework < 2024.0.0 - Contributor+ Stored XSS via Shortcode — socialdriver-framework 5.4 -2024-05-17
CVE-2024-3231 Popup4Phone <= 1.3.2 - Unauthenticated Stored XSS — Popup4Phone 6.1 -2024-05-17
CVE-2024-2744 Nextgen Gallery < 3.59.1 - Admin+ Stored XSS — NextGEN Gallery 4.8 -2024-05-17
CVE-2024-3643 Newsletter Popup <= 1.2 - List Deletion via CSRF — Newsletter Popup 4.3AIMediumAI2024-05-16
CVE-2024-3642 Newsletter Popup <= 1.2 - Subscriber Deletion via CSRF — Newsletter Popup 4.3AIMediumAI2024-05-16
CVE-2024-3644 Newsletter Popup <= 1.2 - Admin+ Stored XSS — Newsletter Popup 4.8AIMediumAI2024-05-16
CVE-2024-3641 Newsletter Popup <= 1.2 - Unauthenticated Stored XSS — Newsletter Popup 6.1AIMediumAI2024-05-16
CVE-2024-3823 Base64 Encoder/Decoder <= 0.9.2 - Stored XSS via CSRF — Base64 Encoder/Decoder 6.1AIMediumAI2024-05-15
CVE-2024-3749 SP Project & Document Manager <= 4.71 - Subscriber+ File Download via IDOR — SP Project & Document Manager 6.5AIMediumAI2024-05-15
CVE-2024-3824 Base64 Encoder/Decoder <= 0.9.2 - Settings Reset via CSRF — Base64 Encoder/Decoder 4.3AIMediumAI2024-05-15
CVE-2024-3822 Base64 Encoder/Decoder <= 0.9.2 - Reflected XSS — Base64 Encoder/Decoder 6.1AIMediumAI2024-05-15
CVE-2024-3634 month name translation benaceur < 2.3.8 - Admin+ Stored XSS — month name translation benaceur 4.8AIMediumAI2024-05-15
CVE-2024-3631 HL Twitter <= 2014.1.18 - Unlink Twitter Account via CSRF — HL Twitter 8.1AIHighAI2024-05-15
CVE-2024-3630 HL Twitter <= 2014.1.18 - Admin+ Stored XSS via Widget — HL Twitter 4.8AIMediumAI2024-05-15
CVE-2024-3748 SP Project & Document Manager <= 4.71 - Data Update via IDOR — SP Project & Document Manager 4.3AIMediumAI2024-05-15
CVE-2024-3629 HL Twitter <= 2014.1.18 - Settings Update via CSRF — HL Twitter 4.3AIMediumAI2024-05-15
CVE-2024-3406 WP Prayer <= 2.0.9 - Email Settings Update via CSRF — WP Prayer 4.3AIMediumAI2024-05-15
CVE-2024-3407 WP Prayer <= 2.0.9 - Arbitrary Prayer Deletion via CSRF — WP Prayer 8.1AIHighAI2024-05-15
CVE-2024-3548 Shortcodes Ultimate < 7.1.2 - Contributor+ Stored XSS — WP Shortcodes Plugin — Shortcodes Ultimate 6.1AIMediumAI2024-05-15
CVE-2024-3405 WP Prayer <= 2.0.9 - Settings Update via CSRF — WP Prayer 4.3AIMediumAI2024-05-15
CVE-2024-3241 Ultimate Blocks < 3.1.7 - Contributor+ Stored XSS — Ultimate Blocks 5.4 -2024-05-14
CVE-2024-3239 PostX < 4.0.2 - Contributor+ Stored XSS — Post Grid Gutenberg Blocks and WordPress Blog Plugin 5.4 -2024-05-13
CVE-2024-3940 reCAPTCHA Jetpack <= 0.2.2 - Settings Update via CSRF — reCAPTCHA Jetpack 4.3 -2024-05-10

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.