Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

unspecified — Vulnerabilities & Security Advisories 259

Browse all 259 CVE security advisories affecting unspecified. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The term "unspecified" in cybersecurity contexts typically refers to software components, libraries, or hardware modules where the vendor or manufacturer has not been publicly identified or disclosed. This anonymity often complicates vulnerability tracking, resulting in a significant backlog of assigned CVEs, currently totaling 259. Historically, these unidentified assets frequently exhibit critical flaws such as remote code execution, cross-site scripting, and privilege escalation vulnerabilities, stemming from a lack of standardized security development lifecycles. The absence of clear attribution hinders coordinated patching efforts and incident response, leaving downstream users exposed to prolonged risk. Notable incidents involving unspecified components often involve supply chain attacks or zero-day exploits where the origin remains obscure until forensic analysis reveals the underlying architecture. This opacity creates a persistent threat landscape, as defenders cannot implement targeted mitigations without knowing the specific software stack or vendor context associated with the vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2022-4523 vexim2 cross site scripting — vexim2CWE-707 3.5 Low2022-12-15
CVE-2022-4522 CalendarXP cross site scripting — CalendarXPCWE-707 3.5 Low2022-12-15
CVE-2022-4493 scifio ZIP File DefaultSampleFilesService.java downloadAndUnpackResource path traversal — scifioCWE-22 6.3 Medium2022-12-14
CVE-2019-25078 pacparser pacparser.c pacparser_find_proxy buffer overflow — pacparserCWE-119 5.3 Medium2022-12-13
CVE-2022-4456 falling-fruit cross site scripting — falling-fruitCWE-707 3.5 Low2022-12-13
CVE-2021-4244 yikes-inc-easy-mailchimp-extender Plugin add_field_to_form.php cross site scripting — yikes-inc-easy-mailchimp-extender PluginCWE-707 2.6 Low2022-12-12
CVE-2022-4377 S-CMS Contact Information Page cross site scripting — S-CMSCWE-707 3.5 Low2022-12-09
CVE-2022-4322 maku-boot Scheduled Task AbstractScheduleJob.java doExecute injection — maku-bootCWE-707 6.3 Medium2022-12-07
CVE-2022-4300 FastCMS Template edit injection — FastCMSCWE-707 6.3 Medium2022-12-06
CVE-2022-4282 SpringBootCMS Template Management injection — SpringBootCMSCWE-707 4.7 Medium2022-12-05
CVE-2022-4281 Facepay camera.php authorization — FacepayCWE-266 6.3 Medium2022-12-05
CVE-2022-4276 House Rental System POST Request tenant-engine.php unrestricted upload — House Rental SystemCWE-266 6.3 Medium2022-12-03
CVE-2022-4275 House Rental System POST Request search-property.php sql injection — House Rental SystemCWE-707 6.3 Medium2022-12-03
CVE-2022-4274 House Rental System view-property.php sql injection — House Rental SystemCWE-707 6.3 Medium2022-12-03
CVE-2022-4251 Movie Ticket Booking System editBooking.php cross site scripting — Movie Ticket Booking SystemCWE-707 2.4 Low2022-12-01
CVE-2022-4250 Movie Ticket Booking System booking.php cross site scripting — Movie Ticket Booking SystemCWE-707 3.5 Low2022-12-01
CVE-2022-4249 Movie Ticket Booking System POST Request cross site scripting — Movie Ticket Booking SystemCWE-707 3.5 Low2022-12-01
CVE-2022-4248 Movie Ticket Booking System editBooking.php sql injection — Movie Ticket Booking SystemCWE-707 5.0 Medium2022-12-01
CVE-2022-4247 Movie Ticket Booking System booking.php sql injection — Movie Ticket Booking SystemCWE-707 6.3 Medium2022-12-01
CVE-2022-4202 GPAC lsr_dec.c lsr_translate_coords integer overflow — GPACCWE-189 6.3 Medium2022-11-29
CVE-2022-4087 iPXE TLS tls.c tls_new_ciphertext information exposure — iPXECWE-284 2.6 Low2022-11-21
CVE-2022-4052 Student Attendance Management System createClass.php sql injection — Student Attendance Management SystemCWE-707 4.7 Medium2022-11-17
CVE-2022-4053 Student Attendance Management System createClass.php cross site scripting — Student Attendance Management SystemCWE-707 2.4 Low2022-11-17
CVE-2022-4051 Hostel Searching Project view-property.php sql injection — Hostel Searching ProjectCWE-707 6.3 Medium2022-11-17
CVE-2022-4015 Sports Club Management System make_payments.php sql injection — Sports Club Management SystemCWE-707 4.7 Medium2022-11-16
CVE-2022-4014 FeehiCMS Post My Comment Tab cross-site request forgery — FeehiCMSCWE-863 4.3 Medium2022-11-16
CVE-2022-4013 Hospital Management Center appointment.php cross-site request forgery — Hospital Management CenterCWE-863 4.3 Medium2022-11-16
CVE-2022-4012 Hospital Management Center patient-info.php sql injection — Hospital Management CenterCWE-707 6.3 Medium2022-11-16
CVE-2022-4011 Simple History Plugin Header neutralization for logs — Simple History PluginCWE-707 6.5 Medium2022-11-16
CVE-2021-4241 phpservermon User.php setUserLoggedIn predictable algorithm in random number generator — phpservermonCWE-331 2.6 Low2022-11-15

This page lists every published CVE security advisory associated with unspecified. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.