Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unknown — Vulnerabilities & Security Advisories 4149

Browse all 4149 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-4355 LetsRecover < 1.2.0 - Admin+ SQLi — LetsRecover 7.2 -2023-01-02
CVE-2022-4302 White Label CMS < 2.5 - Admin+ PHP Object Injection — White Label CMS 7.2 -2023-01-02
CVE-2022-4142 WordPress Filter Gallery Plugin < 0.1.6 - Admin+ Stored XSS — WordPress Filter Gallery Plugin 4.8 -2023-01-02
CVE-2022-4356 LetsRecover < 1.2.0 - Admin+ SQLi — LetsRecover 7.2 -2023-01-02
CVE-2022-4340 BookingPress < 1.0.31 - Unauthenticated IDOR in appointment_id — BookingPress 5.3 -2023-01-02
CVE-2022-4049 WP User <= 7.0 - Unauthenticated SQLi — WP User 9.8 -2023-01-02
CVE-2022-4198 WP Social Sharing <= 2.2 - Admin+ Stored XSS — WP Social Sharing 4.8 -2023-01-02
CVE-2022-4360 WP RSS By Publishers <= 0.1 - Admin+ SQLi — WP RSS By Publishers 7.2 -2023-01-02
CVE-2022-4140 Welcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File Access — Welcart e-Commerce 7.5 -2023-01-02
CVE-2022-3241 Build App Online < 1.0.19 - Unauthenticated SQL Injection — Build App Online 9.8 -2023-01-02
CVE-2022-4357 LetsRecover < 1.2.0 - Unauthenticated SQLi — LetsRecover 9.8 -2023-01-02
CVE-2022-4059 Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi — Cryptocurrency Widgets Pack 9.8 -2023-01-02
CVE-2022-4370 Multimedial Images <= 1.0b - Admin+ SQLi — multimedial images 7.2 -2023-01-02
CVE-2022-4297 WP AutoComplete Search <= 1.0.4 - Unauthenticated SQLi — WP AutoComplete Search 9.8 -2023-01-02
CVE-2022-4351 Qe SEO Handyman <= 1.0 - Admin+ SQLi — Qe SEO Handyman 7.2 -2023-01-02
CVE-2022-4371 Web Invoice <= 2.1.3 - Authenticated SQLi — Web Invoice 7.2 -2023-01-02
CVE-2022-3922 Broken Link Checker < 1.11.20 - Admin+ Cross-Site Scripting — Broken Link Checker 4.8 -2022-12-28
CVE-2021-24942 Menu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code Execution — Menu Item Visibility Control 7.2 -2022-12-26
CVE-2022-4239 Workreap < 2.6.4 - Subscriber+ Arbitrary Posts Deletion via IDOR — Workreap 6.5 -2022-12-26
CVE-2022-4120 Stop Spammers Security < 2022.6 - Unauthenticated PHP Object Injection — Stop Spammers Security | Block Spam Users, Comments, Forms 9.8 -2022-12-26
CVE-2022-4242 WP Google Review Slider < 11.6 - Admin+ Stored XSS — WP Google Review Slider 4.8 -2022-12-26
CVE-2022-3835 Kwayy HTML Sitemap < 4.0 - Admin+ Stored XSS — Kwayy HTML Sitemap 4.8 -2022-12-26
CVE-2022-4160 Contest Gallery < 19.1.5 - Author+ SQL Injection — Contest Gallery 6.5 -2022-12-26
CVE-2022-4151 Contest Gallery < 19.1.5 - Admin+ SQL Injection — Contest Gallery 6.5 -2022-12-26
CVE-2022-4159 Contest Gallery < 19.1.5.1 - Author+ SQL Injection — Contest Gallery 6.5 -2022-12-26
CVE-2022-4152 Contest Gallery < 19.1.5 - Author+ SQL Injection — Contest Gallery 6.5 -2022-12-26
CVE-2022-4047 Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated Arbitrary File Upload — Return Refund and Exchange For WooCommerce 9.8 -2022-12-26
CVE-2022-4266 Bulk Delete Users by Email <= 1.2 - User Deletion via CSRF — Bulk Delete Users by Email 5.3 -2022-12-26
CVE-2022-4226 Simple Basic Contact Form < 20221201 - Admin+ Stored XSS — Simple Basic Contact Form 4.8 -2022-12-26
CVE-2022-4110 Eventify <= 2.1 - Admin+ Stored XSS — Eventify™ 4.8 -2022-12-26

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.