Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4789

Browse all 4789 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2021-24739 Logo Carousel < 3.4.2 - Unauthorised Private Post Access — Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo GalleryCWE-639 8.1 -2021-12-21
CVE-2021-24738 Logo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scripting — Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo GalleryCWE-79 5.4 -2021-12-21
CVE-2021-24578 SportsPress < 2.7.9 - Reflected Cross-Site Scripting — SportsPress – Sports Club & League ManagerCWE-79 6.1 -2021-12-21
CVE-2021-24972 Pixel Cat Lite < 2.6.3 - Admin+ Stored Cross-Site Scripting — Pixel Cat – Conversion Pixel ManagerCWE-79 4.8 -2021-12-13
CVE-2021-24970 All-In-One-Gallery < 2.5.0 - Admin+ Local File Inclusion — All-in-One Video GalleryCWE-22 7.2 -2021-12-13
CVE-2021-24955 ProfilePress < 3.2.3 - Reflected Cross-Site Scripting — User Registration, Login Form, User Profile & Membership – ProfilePress (Formerly WP User Avatar)CWE-79 6.1 -2021-12-13
CVE-2021-24954 ProfilePress < 3.2.3 - Reflected Cross-Site Scripting — User Registration, Login Form, User Profile & Membership – ProfilePress (Formerly WP User Avatar)CWE-79 6.1 -2021-12-13
CVE-2021-24951 LearnPress < 4.1.4 - Admin+ SQL Injection — LearnPress – WordPress LMS PluginCWE-89 7.2 -2021-12-13
CVE-2021-24946 Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL Injection — Modern Events Calendar LiteCWE-89 9.8 -2021-12-13
CVE-2021-24945 Like Button Rating < 2.6.38 - Unauthorised Vote Export to Email & IP Addresses Disclosure — Like Button Rating ♥ LikeBtnCWE-200 6.5 -2021-12-13
CVE-2021-24932 Auto Featured Image < 3.9.3 - Reflected Cross-Site Scripting — Auto Featured Image (Auto Post Thumbnail)CWE-79 6.1 -2021-12-13
CVE-2021-24925 Modern Events Calendar Lite < 6.1.5 - Reflected Cross-Site Scripting — Modern Events Calendar LiteCWE-79 6.1 -2021-12-13
CVE-2021-24922 Pixel Cat Lite < 2.6.2 - CSRF to Stored Cross-Site Scripting — Pixel Cat – Conversion Pixel ManagerCWE-352 8.2 -2021-12-13
CVE-2021-24896 Caldera forms < 1.9.5 - Admin+ Stored Cross-Site Scripting — Caldera Forms – More Than Contact FormsCWE-79 4.8 -2021-12-13
CVE-2021-24872 Get Custom Field Values < 4.0 - Contributors+ Arbitrary Post Metadata Access — Get Custom Field ValuesCWE-863 6.5 -2021-12-13
CVE-2021-24871 Get Custom Field Values < 4.0.1 - Contributor+ Stored Cross-Site Scripting — Get Custom Field ValuesCWE-79 5.4 -2021-12-13
CVE-2021-24863 StopBadBots < 6.67 - Unauthenticated SQL Injection — WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBotsCWE-89 7.2 -2021-12-13
CVE-2021-24861 Quotes Collection <= 2.5.2 - Admin+ SQL Injection — Quotes CollectionCWE-89 7.2 -2021-12-13
CVE-2021-24859 User Meta Shortcodes <= 0.5 - Contributor+ Unauthorized Arbitrary User Metadata Access — User meta shortcodesCWE-284 4.3 -2021-12-13
CVE-2021-24857 ToTop Link <= 1.7.1 - Unauthenticated PHP Object Injection — ToTop LinkCWE-502 9.8 -2021-12-13
CVE-2021-24855 Display Post Metadata < 1.5.0 - Contributor+ Stored Cross-Site Scripting — Display Post MetadataCWE-79 5.4 -2021-12-13
CVE-2021-24848 Mediamatic < 2.8.1 - Subscriber+ SQL Injection — Mediamatic – Media Library FoldersCWE-89 8.8 -2021-12-13
CVE-2021-24845 Improved Include Page <= 1.2 - Contributor+ Arbitrary Posts/Pages Access — Improved Include PageCWE-284 6.5 -2021-12-13
CVE-2021-24836 Temporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings Update — Temporary Login Without PasswordCWE-862 4.3 -2021-12-13
CVE-2021-24819 Page/Post Content Shortcode <= 1.0 - Contributor+ Arbitrary Posts/Pages Access — Page/Post Content ShortcodeCWE-863 4.3 -2021-12-13
CVE-2021-24818 WP Limits <= 1.0 - Plugin's Settings Update via CSRF — Wp LimitsCWE-352 4.3 -2021-12-13
CVE-2021-24817 Ultimate NoFollow <= 1.4.8 - Contributor+ Stored Cross-Site Scripting — Ultimate NofollowCWE-79 5.4 -2021-12-13
CVE-2021-24795 Filter Portfolio Gallery <= 1.5 - Arbitrary Gallery Deletion via CSRF — Filter Portfolio GalleryCWE-352 6.5 -2021-12-13
CVE-2021-24792 Shiny Buttons <= 1.1.0 - Unauthenticated Stored Cross-Site Scripting — Shiny Buttons – CSS3 Button Generator for WordPressCWE-79 5.4 -2021-12-13
CVE-2021-24790 Contact Form Advanced Database <= 1.0.8 - Unauthorised AJAX Calls — Contact Form Advanced DatabaseCWE-862 4.3 -2021-12-13

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.