Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4789

Browse all 4789 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-25004 SEUR Oficial < 1.7.2 - Admin+ Arbitrary File Download — SEUR OficialCWE-552 4.9 -2022-02-07
CVE-2021-24947 RVM - Responsive Vector Maps < 6.4.2 - Subscriber+ Arbitrary File Read — RVM – Responsive Vector MapsCWE-863 6.5 -2022-02-07
CVE-2021-24993 Ultimate Product Catalog < 5.0.26 - Subscriber+ Arbitrary Product Creation & Settings Update — Ultimate Product Catalog – WordPress Catalog PluginCWE-862 4.3 -2022-02-07
CVE-2021-24928 Rearrange Woocommerce Products < 3.0.8 - Subscriber+ SQL Injection — Rearrange Woocommerce ProductsCWE-89 7.1 -2022-02-07
CVE-2021-24880 SupportCandy < 2.2.7 - Contributor+ Stored Cross-Site Scripting — SupportCandy – Helpdesk & Support Ticket SystemCWE-79 5.4 -2022-02-07
CVE-2021-24879 SupportCandy < 2.2.7 - CSRF to Cross-Site Scripting — SupportCandy – Helpdesk & Support Ticket SystemCWE-352 7.3 -2022-02-07
CVE-2021-24843 SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF — SupportCandy – Helpdesk & Support Ticket SystemCWE-352 6.5 -2022-02-07
CVE-2021-24878 SupportCandy < 2.2.7 - Reflected Cross-Site Scripting — SupportCandy – Helpdesk & Support Ticket SystemCWE-79 6.1 -2022-02-07
CVE-2021-24839 SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletion — SupportCandy – Helpdesk & Support Ticket SystemCWE-862 7.5 -2022-02-07
CVE-2021-25095 IP2Location Country Blocker < 2.26.5 - Subscriber+ Arbitrary Country Ban — IP2Location Country BlockerCWE-352 5.4 -2022-02-07
CVE-2022-0320 Essential Addons for Elementor < 5.0.5 - Unauthenticated LFI — Essential Addons for ElementorCWE-22 9.8 -2022-02-01
CVE-2022-0220 WordPress GDPR & CCPA < 1.9.27 - Unauthenticated Reflected Cross-Site Scripting — WordPress GDPR 4.7 -2022-02-01
CVE-2021-25092 Link Library < 7.2.8 - Library Settings Reset via CSRF — Link LibraryCWE-352 6.5 -2022-02-01
CVE-2021-25093 Link Library < 7.2.8 - Unauthenticated Arbitrary Links Deletion — Link LibraryCWE-862 7.5 -2022-02-01
CVE-2021-25091 Link Library < 7.2.9 - Reflected Cross-Site Scripting — Link LibraryCWE-79 6.1 -2022-02-01
CVE-2021-25089 UpdraftPlus < 1.16.69 - Reflected Cross-Site Scripting — UpdraftPlus WordPress Backup PluginCWE-79 6.1 -2022-02-01
CVE-2021-25085 WOOF - Products Filter for WooCommerce < 1.2.6.3 - Reflected Cross-Site Scripting — WOOF – Products Filter for WooCommerceCWE-79 6.1 -2022-02-01
CVE-2021-25063 Contact Form 7 Skins < 2.5.1 - Reflected Cross-Site Scripting (XSS) — Skins for Contact Form 7CWE-79 6.1 -2022-02-01
CVE-2021-25072 NextScripts: Social Networks Auto-Poster < 4.3.25 - Arbitrary Post Deletion via CSRF — NextScripts: Social Networks Auto-PosterCWE-352 6.5 -2022-02-01
CVE-2021-24983 Asset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting via AJAX Action — Asset CleanUp: Page Speed BoosterCWE-79 6.1 -2022-02-01
CVE-2021-24944 Custom Dashboard & Login Page < 7.0 - Admin+ Stored Cross-Site Scripting — Custom Dashboard & Login Page – AGCACWE-79 4.8 -2022-02-01
CVE-2021-24975 NextScripts: Social Networks Auto-Poster < 4.3.24 - Unauthenticated Stored XSS — NextScripts: Social Networks Auto-PosterCWE-79 6.1 -2022-02-01
CVE-2021-24937 Asset CleanUp < 1.3.8.5 - Reflected Cross-Site Scripting — Asset CleanUp: Page Speed BoosterCWE-79 6.1 -2022-02-01
CVE-2021-24934 Visual CSS Style Editor < 7.5.4 - Reflected Cross-Site Scripting — Visual CSS Style EditorCWE-79 6.1 -2022-02-01
CVE-2021-24900 Ninja Tables < 4.1.8 - Admin+ Stored Cross-Site Cross-Site Scripting — Ninja Tables – Best WP DataTables Plugin for WordPressCWE-79 4.8 -2022-02-01
CVE-2021-24762 Perfect Survey < 1.5.2 - Unauthenticated SQL Injection — Perfect SurveyCWE-89 9.8 -2022-02-01
CVE-2021-24761 Error Log Viewer < 1.1.2 - Arbitrary Text File Deletion via CSRF — Error Log Viewer by BestWebSoftCWE-352 6.5 -2022-02-01
CVE-2021-25097 LabTools <= 1.0 - Subscriber+ Arbitrary Publication Deletion — LabToolsCWE-352 6.5 -2022-02-01
CVE-2021-25083 Registrations for the Events Calendar < 2.7.10 - Reflected Cross-Site Scripting — Registrations for the Events Calendar – Event Registration PluginCWE-79 6.1 -2022-01-24
CVE-2021-25080 Contact Form Entries < 1.1.7 - Unauthenticated Stored Cross-Site Scripting — Contact Form Entries – Contact Form 7, WPforms and moreCWE-79 6.1 -2022-01-24

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.