Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

unknown — Vulnerabilities & Security Advisories 4154

Browse all 4154 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-1011 ChatBot < 4.4.5 - Stored XSS via CSRF — AI ChatBot 8.2 -2023-05-08
CVE-2023-0544 WP Login Box <= 2.0.2 - Admin+ Stored XSS — WP Login Box 4.8 -2023-05-08
CVE-2023-1660 ChatBot < 4.4.9 - Unauthenticated Stored XSS — AI ChatBot 6.1 -2023-05-08
CVE-2023-0421 Cloud Manager <= 1.0 - Reflected XSS — Cloud Manager 6.1 -2023-05-08
CVE-2023-0948 Japanized For WooCommerce < 2.5.8 - Reflected XSS — Japanized For WooCommerce 6.1 -2023-05-08
CVE-2023-0267 Ultimate Carousel For WPBakery Page Builder <= 2.6 - Contributor+ Stored XSS — Ultimate Carousel For WPBakery Page Builder 5.4 -2023-05-08
CVE-2023-0768 Avirato hotels online booking engine <= 5.0.5 - Subscriber+ SQLi — Avirato hotels online booking engine 8.8 -2023-05-08
CVE-2023-0894 Pickup | Delivery | Dine-in date time <= 1.0.9 - Admin+ Stored XSS — Pickup | Delivery | Dine-in date time 4.8 -2023-05-08
CVE-2023-1905 WP Popups < 2.1.5.1 - Contributor+ Stored XSS — WP Popups 5.4 -2023-05-08
CVE-2023-1196 Advanced Custom Fields - Contributor+ PHP Object Injection — Advanced Custom Fields (ACF) 8.8 -2023-05-02
CVE-2023-1730 SupportCandy < 3.1.5 - Unauthenticated SQLi — SupportCandy 9.8 -2023-05-02
CVE-2023-1546 MyCryptoCheckout < 2.124 - Reflected XSS — MyCryptoCheckout 6.1 -2023-05-02
CVE-2023-1911 Blocksy Companion < 1.8.82 - Subscriber+ Draft Post Access — Blocksy Companion 4.3 -2023-05-02
CVE-2023-1090 WP SMTP Mailing Queue < 2.0.1 - Admin+ Stored XSS — SMTP Mailing Queue 4.8 -2023-05-02
CVE-2023-1614 WP Custom Author URL < 1.0.5 - Admin+ Stored XSS — WP Custom Author URL 4.8 -2023-05-02
CVE-2023-1804 Product Catalog Feed by PixelYourSite < 2.1.1 - Reflected XSS — Product Catalog Feed by PixelYourSite 6.1 -2023-05-02
CVE-2023-0891 Stagtools < 2.3.7 - Contributor+ Stored XSS — StagTools 5.4 -2023-05-02
CVE-2023-1669 SEOPress < 6.5.0.3 - Admin+ PHP Object Injection — SEOPress 7.2 -2023-05-02
CVE-2023-1809 Download Manager Pro < 6.3.0 - Unauthenticated Sensitive Information Disclosure — Download Manager 7.5 -2023-05-02
CVE-2023-1805 Product Catalog Feed by PixelYourSite < 2.1.1 - Reflected XSS — Product Catalog Feed by PixelYourSite 6.1 -2023-05-02
CVE-2023-1125 Ruby Help Desk < 1.3.4 - Subscriber+ Ticket Update via IDOR — Ruby Help Desk 7.5 -2023-05-02
CVE-2023-1021 Amr Ical Events Lists <= 6.6 - Admin+ Stored XSS — amr ical events lists 4.8 -2023-05-02
CVE-2023-1554 Quick Paypal Payments < 5.7.26.4 - Admin+ Stored XSS — Quick Paypal Payments 4.8 -2023-05-02
CVE-2023-1861 Limit Login Attempts < 1.7.2 - Subscriber+ Stored XSS — Limit Login Attempts 5.4 -2023-05-02
CVE-2023-0924 Zyrex Popup <= 1.0 - Admin+ Arbitrary File Upload — ZYREX POPUP 7.2 -2023-05-02
CVE-2023-1525 Site Reviews < 6.7.1 - Admin+ Stored XSS — Site Reviews 4.8 -2023-05-02
CVE-2023-1414 WP VR < 8.3.0 - Subscriber+ Arbitrary Tour Update — WP VR 4.3 -2023-04-24
CVE-2023-1623 Custom Post Type UI < 1.13.5 - Debug Info Sending via CSRF — Custom Post Type UI 6.5 -2023-04-24
CVE-2023-0418 Video Central for WordPress <= 1.3.0 - Contributor+ Stored XSS — Video Central for WordPress 5.4 -2023-04-24
CVE-2023-1435 Ajax Search Lite Pro < 4.26.2 - Multiple Reflected Cross-Site Scripting — Ajax Search Pro 6.1 -2023-04-24

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.