Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4143

Browse all 4143 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1956 WPB Show Core < 2.7 - Reflected XSS — wpb-show-core 6.1AIMediumAI2024-04-08
CVE-2024-1292 WPB Show Core < 2.6 - Reflected XSS — wpb-show-core 6.1AIMediumAI2024-04-08
CVE-2024-1588 SendPress Newsletters <= 1.23.11.6 - Admin+ Stored XSS via Settings — SendPress Newsletters 4.8AIMediumAI2024-04-08
CVE-2024-2444 Inline Related Posts < 3.5.0 - Admin+ Stored XSS — Inline Related Posts 4.8 -2024-04-06
CVE-2024-2509 Gutenberg Blocks by Kadence Blocks < 3.2.26 - Contributor+ Stored XSS — Gutenberg Blocks by Kadence Blocks 5.4 -2024-04-05
CVE-2024-2322 WooCommerce Cart Abandonment Recovery < 1.2.27 - Templates/Abandoned Orders Deletion via CSRF — WooCommerce Cart Abandonment Recovery 6.5 -2024-04-03
CVE-2024-1274 My Calendar < 3.4.24 - Authenticated Stored XSS — My Calendar 5.4AIMediumAI2024-04-02
CVE-2024-2369 Page Builder Gutenberg Blocks < 3.1.7 - Contributor+ Stored XSS — Page Builder Gutenberg Blocks 5.4AIMediumAI2024-04-02
CVE-2024-2278 WooCommerce Product Filter < 1.4.4 - Admin+ Stored XSS — Themify 4.8 -2024-04-01
CVE-2024-2262 WooCommerce Product Filter < 1.4.4 - Filter Deletion via CSRF — Themify 6.5 -2024-04-01
CVE-2024-2263 WooCommerce Product Filter < 1.4.4 - Reflected XSS — Themify 6.1 -2024-04-01
CVE-2024-1526 Hubbub Lite < 1.33.1 - Unauthenticated Password Protected Posts Access — Hubbub Lite 6.5 -2024-04-01
CVE-2024-0677 Pz-LinkCard <= 2.5.1 - Contributor+ SSRF — Pz-LinkCard 6.5AIMediumAI2024-03-28
CVE-2024-0672 Pz-LinkCard <= 2.5.1 - Reflected XSS — Pz-LinkCard 6.1AIMediumAI2024-03-28
CVE-2024-0673 Pz-LinkCard <= 2.5.1 - Admin+ Stored XSS — Pz-LinkCard 4.8AIMediumAI2024-03-28
CVE-2023-7232 Backup and Restore WordPress <= 1.45 - Unauthenticated Sensitive Data Exposure — Backup and Restore WordPress 7.5AIHighAI2024-03-26
CVE-2024-1745 Testimonial Slider < 2.3.7 - Author+ Settings Update — Testimonial Slider 4.3AIMediumAI2024-03-26
CVE-2024-1564 Schema Pro < 2.7.16 - Contributor+ Custom Field Access — wp-schema-pro 5.4AIMediumAI2024-03-25
CVE-2024-1962 CM Download and File Manager < 2.9.1 - Download Edit via CSRF — CM Download Manager 4.3AIMediumAI2024-03-25
CVE-2024-1231 CM Download and File Manager < 2.9.0 - Download Unpublish via CSRF — CM Download Manager 4.3AIMediumAI2024-03-25
CVE-2024-1232 CM Download Manager < 2.9.0 - Download Deletion via CSRF — CM Download Manager 4.3AIMediumAI2024-03-25
CVE-2024-0856 Booking Calendar < 1.3.83 - CSRF appointment scheduling — Appointment Booking Calendar 4.3AIMediumAI2024-03-20
CVE-2024-1983 Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS — Simple Ajax Chat 4.3AIMediumAI2024-03-20
CVE-2024-0337 Travelpayouts <= 1.1.15 - Open Redirect — Travelpayouts: All Travel Brands in One Place 6.1AIMediumAI2024-03-20
CVE-2023-7246 System Dashboard < 2.8.10 - XSS via Header Injection — System Dashboard 4.8AIMediumAI2024-03-20
CVE-2024-1401 Profile Box Shortcode And Widget < 1.2.1 Admin+ Stored XSS — Profile Box Shortcode And Widget 4.8AIMediumAI2024-03-19
CVE-2023-7236 Backup Bolt <= 1.3.0 - Sensitive Data Exposure — Backup Bolt 5.3 -2024-03-18
CVE-2024-0951 Advanced Social Feeds Widget & Shortcode <= 1.7 - Admin+ Stored XSS — Advanced Social Feeds Widget & Shortcode 4.8 -2024-03-18
CVE-2024-0711 Buttons Shortcode and Widget <= 1.16 - Stored XSS via shortcode — Buttons Shortcode and Widget 5.4 -2024-03-18
CVE-2023-7085 Scalable Vector Graphics (SVG) <= 3.4 - Author+ Stored XSS via SVG — Scalable Vector Graphics (SVG) 5.4 -2024-03-18

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.