Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

unknown — Vulnerabilities & Security Advisories 4151

Browse all 4151 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-2628 KiviCare Management System < 3.2.1 - Multiple CSRF — KiviCare 8.1 -2023-06-27
CVE-2023-1166 USM Premium < 16.3 - Admin+ Stored XSS — Ultimate-Premium-Plugin 4.8 -2023-06-27
CVE-2023-2623 KiviCare Management System < 3.2.1 - Subscriber+ Sensitive Information Disclosure — KiviCare 6.5 -2023-06-27
CVE-2023-2592 FormCraft Premium < 3.9.7 - Admin+ SQLi — FormCraft 7.2 -2023-06-27
CVE-2023-2068 File Manager Advanced Shortcode <= 2.3.2 - Unauthenticated Remote Code Execution through shortcode — file-manager-advanced-shortcode 9.8 -2023-06-27
CVE-2023-2711 Ultimate Product Catalog < 5.2.6 - Admin+ Stored XSS — Ultimate Product Catalog 4.8 -2023-06-27
CVE-2023-2842 WP Inventory Manager < 2.1.0.14 - Inventory Items Deletion via CSRF — WP Inventory Manager 4.3 -2023-06-27
CVE-2023-1891 Accordion & FAQ < 1.9.9 - Reflected XSS — Accordion & FAQ 6.1 -2023-06-27
CVE-2023-0873 Kanban Boards for WordPress < 2.5.21 - Admin+ Stored XSS — Kanban Boards for WordPress 4.8 -2023-06-27
CVE-2022-4115 Editorial Calendar < 3.8.3 - Contributor+ Stored XSS — Editorial Calendar 5.4 -2023-06-27
CVE-2023-2032 Custom 404 Pro < 3.8.1 - Multiple SQL Injection — Custom 404 Pro 9.8 -2023-06-27
CVE-2023-2877 Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution — Formidable Forms 8.8 -2023-06-27
CVE-2023-2601 WP Brutal AI < 2.0.0 - SQL Injection via CSRF — wpbrutalai 7.2 -2023-06-27
CVE-2023-2744 WP ERP < 1.12.4 - Admin+ SQL Injection — WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 7.2 -2023-06-27
CVE-2023-2482 Responsive CSS EDITOR <= 1.0 - Admin+ SQLi — Responsive CSS EDITOR 7.2 -2023-06-27
CVE-2023-2178 Aajoda Testimonials < 2.2.2 - Admin+ Stored XSS — Aajoda Testimonials 4.8 -2023-06-27
CVE-2023-2580 AI-Engine < 1.6.83 - Admin+ Stored XSS — AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable 4.8 -2023-06-27
CVE-2023-2996 Jetpack < 12.1.1 - Author+ Arbitrary File Manipulation via API — Jetpack 8.8 -2023-06-27
CVE-2023-2627 KiviCare Management System < 3.2.1 - Subscriber+ Unauthorised AJAX Calls — KiviCare 6.5 -2023-06-27
CVE-2023-2743 WP ERP < 1.12.4 - Reflected Cross-Site Scripting — WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting 6.1 -2023-06-27
CVE-2023-2812 Ultimate Dashboard < 3.7.6 - Admin+ Stored XSS — Ultimate Dashboard 4.8 -2023-06-19
CVE-2023-2805 SupportCandy < 3.1.7 - Admin+ SQLi — SupportCandy 7.2 -2023-06-19
CVE-2023-2654 Conditional Menus < 1.2.1 - Reflected XSS — Conditional Menus 6.1 -2023-06-19
CVE-2023-2399 qubotchat < 1.1.6 - Unauthenticated Stored XSS — QuBot 6.5 -2023-06-19
CVE-2023-2751 Upload Resume <= 1.2.0 - Captcha Bypass — Upload Resume 7.5 -2023-06-19
CVE-2023-2527 Integration for Contact Form 7 and Zoho CRM, Bigin < 1.2.4 - Admin+ SQLi — Integration for Contact Form 7 and Zoho CRM, Bigin 4.8 -2023-06-19
CVE-2023-0489 SlideOnline <= 1.2.1 - Contributor+ Stored XSS — SlideOnline 5.4 -2023-06-19
CVE-2023-2359 Revolution Slider <= 6.6.12 - Author+ Remote Code Execution — Slider Revolution 9.8 -2023-06-19
CVE-2023-0368 Responsive Tabs For WPBakery Page Builder <= 1.1 - Contributor+ Stored XSS — Responsive Tabs For WPBakery Page Builder (formerly Visual Composer) 5.4 -2023-06-19
CVE-2023-2600 Custom Base Terms < 1.0.3 - Admin+ Stored XSS — Custom Base Terms 4.8 -2023-06-19

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.