Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

unspecified — Vulnerabilities & Security Advisories 259

Browse all 259 CVE security advisories affecting unspecified. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The term "unspecified" in cybersecurity contexts typically refers to software components, libraries, or hardware modules where the vendor or manufacturer has not been publicly identified or disclosed. This anonymity often complicates vulnerability tracking, resulting in a significant backlog of assigned CVEs, currently totaling 259. Historically, these unidentified assets frequently exhibit critical flaws such as remote code execution, cross-site scripting, and privilege escalation vulnerabilities, stemming from a lack of standardized security development lifecycles. The absence of clear attribution hinders coordinated patching efforts and incident response, leaving downstream users exposed to prolonged risk. Notable incidents involving unspecified components often involve supply chain attacks or zero-day exploits where the origin remains obscure until forensic analysis reveals the underlying architecture. This opacity creates a persistent threat landscape, as defenders cannot implement targeted mitigations without knowing the specific software stack or vendor context associated with the vulnerability.

CVE ID Title CVSS Severity Published
CVE-2021-4240 phpservermon User.php generatePasswordResetToken predictable algorithm in random number generator — phpservermon CWE-331 2.6 Low 2022-11-15
CVE-2022-3988 Frappe Search navbar_search.html cross site scripting — Frappe CWE-707 3.5 Low 2022-11-14
CVE-2022-3964 ffmpeg QuickTime RPZA Video Encoder rpzaenc.c out-of-bounds — ffmpeg CWE-119 4.3 Medium 2022-11-13
CVE-2022-3978 NodeBB abort cross-site request forgery — NodeBB CWE-863 4.3 Medium 2022-11-13
CVE-2022-3971 matrix-appservice-irc PgDataStore.ts sql injection — matrix-appservice-irc CWE-707 4.6 Medium 2022-11-13
CVE-2022-3970 LibTIFF tif_getimage.c TIFFReadRGBATileExt integer overflow — LibTIFF CWE-189 6.3 Medium 2022-11-13
CVE-2022-3969 OpenKM FileUtils.java getFileExtension temp file — OpenKM CWE-377 2.6 Low 2022-11-13
CVE-2022-3968 emlog article_save.php cross site scripting — emlog CWE-707 3.5 Low 2022-11-13
CVE-2022-3967 Vesta Control Panel sed main.sh argument injection — Vesta Control Panel CWE-707 5.3 Medium 2022-11-13
CVE-2022-3966 Ultimate Member Plugin Template class-shortcodes.php load_template pathname traversal — Ultimate Member Plugin CWE-22 4.3 Medium 2022-11-13
CVE-2022-3965 ffmpeg QuickTime Graphics Video Encoder smcenc.c smc_encode_stream out-of-bounds — ffmpeg CWE-119 4.3 Medium 2022-11-13
CVE-2022-3963 gnuboard5 FAQ Key ID faq.php cross site scripting — gnuboard5 CWE-707 3.5 Low 2022-11-12
CVE-2022-3959 drogon Session Hash small space of random values — drogon CWE-330 3.1 Low 2022-11-11
CVE-2022-3957 GPAC SVG Parser svg_attributes.c svg_parse_preserveaspectratio memory leak — GPAC CWE-404 4.3 Medium 2022-11-11
CVE-2022-3941 Activity Log Plugin HTTP Header neutralization for logs — Activity Log Plugin CWE-707 5.3 Medium 2022-11-11
CVE-2022-3845 phpipam Import Preview import-load-data.php cross site scripting — phpipam CWE-707 2.4 Low 2022-11-02
CVE-2022-3827 centreon Contact Groups Form formContactGroup.php sql injection — centreon CWE-707 6.3 Medium 2022-11-02
CVE-2022-3783 node-red-dashboard ui_text Format ui-component-ctrl.js cross site scripting — node-red-dashboard CWE-707 3.5 Low 2022-10-31
CVE-2022-3734 Redis on Windows dbghelp.dll uncontrolled search path — Redis CWE-426 6.3 Medium 2022-10-28
CVE-2022-3705 vim autocmd quickfix.c qf_update_buffer use after free — vim CWE-119 5.0 Medium 2022-10-26
CVE-2022-3704 Ruby on Rails _table.html.erb cross site scripting — Ruby on Rails CWE-707 3.5 Low 2022-10-26
CVE-2022-3620 Exim DMARC dmarc.c dmarc_dns_lookup use after free — Exim CWE-119 5.6 Medium 2022-10-20
CVE-2022-3559 Exim Regex use after free — Exim CWE-119 4.6 Medium 2022-10-17
CVE-2022-3502 Human Resource Management System Leave cross site scripting — Human Resource Management System CWE-707 3.5 Low 2022-10-14
CVE-2022-3464 puppyCMS settings.php cross site scripting — puppyCMS CWE-707 4.3 Medium 2022-10-12
CVE-2022-3354 Open5GS UDP Packet ogs-tlv-msg.c denial of service — Open5GS CWE-404 3.5 Low 2022-09-28
CVE-2022-3299 Open5GS AMF client.c denial of service — Open5GS CWE-404 4.3 Medium 2022-09-26
CVE-2022-2886 Laravel deserialization — Laravel CWE-502 5.0 Medium 2022-08-19
CVE-2022-2870 laravel deserialization — laravel CWE-502 4.1 Medium 2022-08-17
CVE-2022-2726 SEMCMS Ant_Check.php sql injection — SEMCMS CWE-89 6.3 Medium 2022-08-09

This page lists every published CVE security advisory associated with unspecified. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.