Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4787

Browse all 4787 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-25061 WP Booking System – Booking Calendar < 2.0.15 - Authenticated Reflected Cross-Site Scripting (XSS) — WP Booking System – Booking CalendarCWE-79 5.4 -2022-01-17
CVE-2021-25046 Modern Events Calendar Lite < 6.2.0 - Subscriber+ Category Add Leading to Stored XSS — Modern Events Calendar LiteCWE-79 5.4 -2022-01-17
CVE-2021-25037 All In One SEO < 4.1.5.3 - Authenticated SQL Injection — All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase TrafficCWE-89 6.5 -2022-01-17
CVE-2021-25036 All In One SEO < 4.1.5.3 - Authenticated Privilege Escalation — All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase TrafficCWE-287 8.8 -2022-01-17
CVE-2021-25024 Event Calendar < 1.1.51 - Reflected Cross-Site Scripting — EventCalendarCWE-79 6.1 -2022-01-17
CVE-2021-25005 SEUR Oficial < 1.7.0 - Admin+ Stored Cross-Site Scripting — SEUR OficialCWE-79 4.8 -2022-01-17
CVE-2021-24909 ACF Photo Gallery Field < 1.7.5 - Reflected Cross-Site Scripting — ACF Photo Gallery FieldCWE-79 6.1 -2022-01-17
CVE-2021-24838 AnyComment < 0.3.5 - Open Redirect — AnyCommentCWE-601 6.1 -2022-01-17
CVE-2021-25025 Event Calendar < 1.1.51 - Subscriber+ Event Creation — EventCalendarCWE-352 4.3 -2022-01-17
CVE-2021-25054 WPcalc <= 2.1 - Authenticated SQL Injection — WPcalc – create any online calculatorsCWE-89 7.2 -2022-01-10
CVE-2021-25052 Button Generator < 2.3.3 - RFI leading to RCE via CSRF — Button Generator – easily Button BuilderCWE-352 8.8 -2022-01-10
CVE-2021-25053 WP Coder < 2.5.2 - RFI leading to RCE via CSRF — WP Coder – add custom html, css and js codeCWE-352 8.8 -2022-01-10
CVE-2021-25051 Modal Window < 5.2.2 - RFI leading to RCE via CSRF — Modal Window – create popup modal windowCWE-352 8.8 -2022-01-10
CVE-2021-25047 10Web Social Photo Feed < 1.4.29 - Reflected Cross-Site Scripting (XSS) — 10Web Social Photo FeedCWE-79 6.1 -2022-01-10
CVE-2021-25043 WOOCS < 1.3.7.3 - Reflected Cross-Site Scripting — WOOCS – Currency Switcher for WooCommerce. Professional and Free multi currency plugin – Pay in selected currencyCWE-79 6.1 -2022-01-10
CVE-2021-24948 The Plus Addons for Elementor Pro < 5.0.7 - Sensitive Data Disclosure — The Plus Addons for Elementor - ProCWE-200 7.5 -2022-01-10
CVE-2021-24949 The Plus Addons for Elementor Pro < 5.0.7 - Unauthenticated SQL Injection — The Plus Addons for Elementor - ProCWE-89 7.2 -2022-01-10
CVE-2021-24862 RegistrationMagic < 5.0.1.6 - Admin+ SQL Injection — RegistrationMagic – Custom Registration Forms, User Registration and User Login PluginCWE-89 7.2 -2022-01-10
CVE-2021-25032 PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise — PublishPress Capabilities – User Role Access, Editor Permissions, Admin MenusCWE-352 9.8 -2022-01-10
CVE-2021-25040 Booking Calendar < 8.9.2 - Reflected Cross-Site Scripting — Booking CalendarCWE-79 6.1 -2022-01-03
CVE-2021-25030 Events Made Easy < 2.2.36 - Subscriber+ SQL Injection — Events Made EasyCWE-89 8.8 -2022-01-03
CVE-2021-25027 PowerPack Addons for Elementor < 2.6.2 - Reflected Cross-Site Scripting — PowerPack Addons for ElementorCWE-79 6.1 -2022-01-03
CVE-2021-25022 UpdraftPlus < 1.16.66 - Reflected Cross-Site Scripting — UpdraftPlus WordPress Backup PluginCWE-79 6.1 -2022-01-03
CVE-2021-25023 Speed Booster Pack < 4.3.3.1 - Admin+ SQL Injection — Speed Booster Pack ⚡ PageSpeed Optimization SuiteCWE-89 7.2 -2022-01-03
CVE-2021-25021 OMGF < 4.5.12 - Admin+ Arbitrary Folder Deletion via Path Traversal — OMGF | Host Google Fonts LocallyCWE-22 4.9 -2022-01-03
CVE-2021-25020 CAOS < 4.1.9 - Admin+ Arbitrary Folder Deletion via Path Traversal — CAOS | Host Google Analytics LocallyCWE-22 4.9 -2022-01-03
CVE-2021-25001 Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in Product XML Feeds Module — Booster for WooCommerceCWE-79 6.1 -2022-01-03
CVE-2021-25016 Chaty < 2.8.3 - Reflected Cross-Site Scripting — Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – ChatyCWE-79 6.1 -2022-01-03
CVE-2021-25000 Booster for WooCommerce < 5.4.9 - Reflected Cross-Site Scripting in General Module — Booster for WooCommerceCWE-79 6.1 -2022-01-03
CVE-2021-24991 WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site Scripting — WooCommerce PDF Invoices & Packing SlipsCWE-79 6.1 -2022-01-03

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.