Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4789

Browse all 4789 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2023-6030 LogDash Activity Log < 1.1.4 - Unauthenticated SQLi — LogDash Activity Log 9.8AICriticalAI2025-05-15
CVE-2023-5932 Travelpayouts < 1.1.14 - Reflected XSS — Travelpayouts: All Travel Brands in One Place 6.1AIMediumAI2025-05-15
CVE-2023-5934 Travelpayouts < 1.1.13 - Settings Update via CSRF — Travelpayouts: All Travel Brands in One Place 4.3AIMediumAI2025-05-15
CVE-2023-5529 Advanced Page Visit Counter <= 8.0.6 - Admin+ Stored XSS — Advanced Page Visit Counter 4.8AIMediumAI2025-05-15
CVE-2023-2334 Easy Digital Downloads Google Sheet Connector < 1.6.6 - Access Code Update via CSRF — edd-google-sheet-connector-pro 6.5AIMediumAI2025-05-15
CVE-2025-2247 WP-PManager <= 1.2 - Category Deletion via CSRF — WP-PManager 4.3AIMediumAI2025-05-15
CVE-2025-2248 WP-PManager <= 1.2 - Admin+ SQL Injection — WP-PManager 7.2AIHighAI2025-05-15
CVE-2025-1303 Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Unauthenticated Reflected XSS — Plugin Oficial 6.1AIMediumAI2025-05-15
CVE-2025-2203 WooCommerce Checkout & Funnel Builder by FunnelKit < 3.10.2 - Admin+ SQL Injection — FunnelKit 7.2AIHighAI2025-05-15
CVE-2025-1454 Ninja Pages <= 1.4.2 - Admin+ Stored XSS — Ninja Pages 4.8AIMediumAI2025-05-15
CVE-2025-1289 Plugin Oficial – Getnet para WooCommerce <= 1.7.3 - Admin+ Stored XSS — Plugin Oficial 4.8AIMediumAI2025-05-15
CVE-2025-1288 wooexim <= 5.0.0 - CSRF to Reflected XSS — WOOEXIM 6.1AIMediumAI2025-05-15
CVE-2025-1033 Badgearoo <= 1.0.14 - Admin+ Stored XSS — Badgearoo 4.8AIMediumAI2025-05-15
CVE-2025-0688 Spiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS — Spiritual Gifts Survey (and optional S.H.A.P.E survey) 6.1AIMediumAI2025-05-15
CVE-2025-1286 Download HTML TinyMCE Button <= 1.2 - Reflected XSS — Download HTML TinyMCE Button 6.1AIMediumAI2025-05-15
CVE-2025-0329 AI ChatBot for WordPress – WPBot < 6.2.4 - Admin+ Stored XSS — AI ChatBot for WordPress 4.8AIMediumAI2025-05-15
CVE-2025-0687 Spiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSS — Spiritual Gifts Survey (and optional S.H.A.P.E survey) 6.1AIMediumAI2025-05-15
CVE-2024-9882 Salon Booking System < 10.9.4 - Admin+ Stored XSS — Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses 4.8AIMediumAI2025-05-15
CVE-2024-9838 Auto Affiliate Links < 6.4.7 - Admin+ SQL Injection — Auto Affiliate Links 7.2AIHighAI2025-05-15
CVE-2024-9879 Website File Changes < 2.1.1 - Authenticated SQL Injection — Melapress File Monitor 7.2AIHighAI2025-05-15
CVE-2024-9831 Taskbuilder < 3.0.9 - Admin+ SQL Injection — Taskbuilder 7.2AIHighAI2025-05-15
CVE-2024-9711 EKC Tournament Manager < 2.2.2 - Delete Tournaments via CSRF — EKC Tournament Manager 4.3AIMediumAI2025-05-15
CVE-2024-9709 EKC Tournament Manager < 2.2.2 - Create Tournaments/Teams via CSRF — EKC Tournament Manager 4.3AIMediumAI2025-05-15
CVE-2024-9765 EKC Tournament Manager < 2.2.2 - Local File Download Vulnerability — EKC Tournament Manager 4.9AIMediumAI2025-05-15
CVE-2024-9599 Popup Box < 4.7.8 - Admin+ Stored XSS — Popup Box 4.8AIMediumAI2025-05-15
CVE-2024-9663 CYAN Backup < 2.5.3 - Admin+ Stored XSS via Remote Storage Settings — CYAN Backup 4.8AIMediumAI2025-05-15
CVE-2024-9645 Post Grid and Gutenberg Blocks < 2.2.93 - Contributor+ Stored XSS — Post Grid, Posts Slider, Posts Carousel, Post Filter, Post Masonry 5.4AIMediumAI2025-05-15
CVE-2024-9662 CYAN Backup < 2.5.3 - Admin+ Stored XSS via General Settings — CYAN Backup 4.8AIMediumAI2025-05-15
CVE-2024-9238 AVIF & SVG Uploader <= 1.1.0 - Author+ Stored XSS via SVG Uplaod — AVIF Uploader 5.4AIMediumAI2025-05-15
CVE-2024-9450 Free Booking Plugin for Hotels, Restaurants and Car Rentals – eaSYNC Booking < 1.3.15 - Subscriber+ PayPal Settings Update — Free Booking Plugin for Hotels, Restaurants and Car Rentals 4.3AIMediumAI2025-05-15

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.