Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

unknown — Vulnerabilities & Security Advisories 4154

Browse all 4154 CVE security advisories affecting unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2022-2532 Feed Them Social < 3.0.1 - Reflected Cross-Site Scripting — Feed Them Social – for Twitter feed, Youtube and moreCWE-79 6.1 -2022-08-22
CVE-2022-2407 WP phpMyAdmin < 5.2.0.4 - Admin+ Stored Cross-Site Scripting — WP phpMyAdminCWE-79 4.8 -2022-08-22
CVE-2022-2392 Lana Downloads Manager < 1.8.0 - Contributor+ Arbitrary File Download — Lana Downloads ManagerCWE-552 6.5 -2022-08-22
CVE-2022-2389 Automations By Autonami < 2.1.2 - Subscriber+ Automation Creation — Abandoned Cart Recovery for WooCommerce, Follow Up Emails, Newsletter Builder & Marketing Automation By AutonamiCWE-862 4.3 -2022-08-22
CVE-2022-2388 WP Coder < 2.5.3 - Code Deletion via CSRF — WP Coder – add custom html, css and js codeCWE-352 6.5 -2022-08-22
CVE-2022-2383 Feed Them Social < 3.0.1 - Reflected Cross-Site Scripting — Feed Them Social – for Twitter feed, Youtube and moreCWE-79 6.1 -2022-08-22
CVE-2022-2382 Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options Deletion — Product Slider for WooCommerceCWE-862 4.3 -2022-08-22
CVE-2022-2377 Directorist < 7.3.0 - Subscriber+ Arbitrary E-mail Sending — Directorist – WordPress Business Directory Plugin with Classified Ads ListingsCWE-862 4.3 -2022-08-22
CVE-2022-2375 WP Sticky Button < 1.4.1 - Unauthenticated Arbitrary Settings Update to Stored XSS — WP Sticky Button – Click to ChatCWE-79 6.1 -2022-08-22
CVE-2022-2362 Download Manager < 3.2.50 - Bypass IP Address Blocking Restriction — Download ManagerCWE-79 9.1 -2022-08-22
CVE-2022-2361 Social Chat < 6.0.5 - Admin+ Stored Cross-Site Scripting — WP Social Chat – Click To Chat AppCWE-79 4.8 -2022-08-22
CVE-2022-2312 Student Result or Employee Database < 1.7.5 - Stored Cross Site Scripting via CSRF — Student Result or Employee DatabaseCWE-639 5.4 -2022-08-22
CVE-2022-2276 WP Edit Menu < 1.5.0 - Unauthenticated Arbitrary Post Deletion — WP Edit MenuCWE-862 4.3 -2022-08-22
CVE-2022-2275 WP Edit Menu <= 1.5.0 - Arbitrary Post Deletion via CSRF — WP Edit MenuCWE-352 4.3 -2022-08-22
CVE-2022-2198 WPQA < 5.7 - Subscriber+ Private Message Disclosure via IDOR — WPQA BuilderCWE-639 4.3 -2022-08-22
CVE-2022-2172 LinkWorth Plugin < 3.3.4 - Arbitrary Setting Update via CSRF — LinkWorth PluginCWE-352 6.5 -2022-08-22
CVE-2022-25812 Transposh WordPress Translation < 1.0.8 - Admin+ RCE — Transposh WordPress TranslationCWE-94 7.2 -2022-08-22
CVE-2022-25811 Transposh WordPress Translation <= 1.0.8 - Admin+ SQL Injection — Transposh WordPress TranslationCWE-89 7.2 -2022-08-22
CVE-2022-25810 Transposh WordPress Translation <= 1.0.8 - Subscriber+ Unauthorised Calls — Transposh WordPress TranslationCWE-862 8.1 -2022-08-22
CVE-2022-1932 Rezgo Online Booking < 4.1.8 - Reflected Cross-Site-Scripting — Rezgo Online BookingCWE-79 6.1 -2022-08-22
CVE-2022-1322 Coming Soon - Under Construction <= 1.1.9 - Admin+ Stored Cross-Site Scripting — Coming Soon – Under ConstructionCWE-79 4.8 -2022-08-22
CVE-2022-1251 Ask Me < 6.8.4 - CSRF in Edit Profile — Ask meCWE-352 6.5 -2022-08-22
CVE-2022-0446 Simple Banner < 2.12.0 - Admin+ Stored Cross Site Scripting — Simple BannerCWE-79 4.8 -2022-08-22
CVE-2021-24912 Transposh WordPress Translation < 1.0.8 - CSRF to Stored XSS — Transposh WordPress TranslationCWE-352 5.4 -2022-08-22
CVE-2021-24911 Transposh WordPress Translation < 1.0.8 - Stored Cross-Site Scripting — Transposh WordPress TranslationCWE-79 5.4 -2022-08-22
CVE-2021-24910 Transposh WordPress Translation < 1.0.8 - Reflected Cross-Site Scripting — Transposh WordPress TranslationCWE-79 6.1 -2022-08-22
CVE-2022-2846 Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS — Calendar Event Multi ViewCWE-862 4.3 -2022-08-16
CVE-2022-2535 SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title Disclosure — SearchWP Live Ajax SearchCWE-639 5.3 -2022-08-15
CVE-2022-2384 Digital Publications by Supsystic < 1.7.4 - Admin+ Stored Cross-Site Scripting — Digital Publications by SupsysticCWE-79 4.8 -2022-08-15
CVE-2022-2381 E Unlocked - Student Result <= 1.0.4 - Arbitrary File Upload via CSRF — E Unlocked – Student ResultCWE-352 8.8 -2022-08-15

This page lists every published CVE security advisory associated with unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.