Записи Tencent
47 опубликованных записей вендора tencent.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 23,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-190 Integer Overflow or Wraparound2
- CWE-284 Improper Access Control2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
47 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2021-27439Эксплойта нет | TencentOS-tiny Integer Overflow or Wraparoundtencent · tencentos-tiny · CWE-190 | Критическая9,8 | — | 1,6 % | 3 мая 2022 г. |
39Наблюдать | CVE-2024-33078Эксплойта нет | Tencent Libpag v4.3 is vulnerable to Buffer Overflow.tencent · libpag · CWE-680 | Критическая9,8 | — | 1,1 % | 1 мая 2024 г. |
39Наблюдать | CVE-2023-30363Эксплойта нет | vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.tencent · vconsole · CWE-1321 | Критическая9,8 | — | 1,0 % | 26 апр. 2023 г. |
39Наблюдать | CVE-2026-30860Эксплойта нет | WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tooltencent · weknora · CWE-89 | Критическая9,8 | — | 0,7 % | 7 мар. 2026 г. |
39Наблюдать | CVE-2026-22687Эксплойта нет | WeKnora vulnerable to SQL Injectiontencent · weknora · CWE-89 | Критическая9,8 | — | 0,4 % | 10 янв. 2026 г. |
36Наблюдать | CVE-2018-11616Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.tencent · foxmail · CWE-78 | Высокая8,8 | — | 4,9 % | 30 авг. 2018 г. |
36Наблюдать | CVE-2026-30861Эксплойта нет | WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validationtencent · weknora · CWE-78 | Высокая8,8 | — | 2,5 % | 7 мар. 2026 г. |
36Наблюдать | CVE-2020-27874Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18.tencent · wechat · CWE-119 | Высокая8,8 | — | 2,1 % | 10 февр. 2021 г. |
36Наблюдать | CVE-2026-22688Эксплойта нет | WeKnora has Command Injection in MCP stdio testtencent · weknora · CWE-77 | Высокая8,8 | — | 2,0 % | 10 янв. 2026 г. |
35Наблюдать | CVE-2024-40433Эксплойта нет | Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.tencent · wechat · CWE-266 | Высокая8,8 | — | 1,2 % | 26 июл. 2024 г. |
35Наблюдать | CVE-2026-30855Эксплойта нет | WeKnora: Broken Access Control in Tenant Managementtencent · weknora · CWE-284 | Высокая8,8 | — | 0,5 % | 7 мар. 2026 г. |
32Наблюдать | CVE-2021-33879Proof of concept | Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection.tencent · gameloop · CWE-494 | Высокая8,1 | — | 1,0 % | 6 июн. 2021 г. |
32Наблюдать | CVE-2024-22873Эксплойта нет | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/tencent · blueking configuration management database · CWE-918 | Высокая8,1 | — | 0,5 % | 26 февр. 2024 г. |
31Наблюдать | CVE-2018-13439Эксплойта нет | WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.tencent · wechat pay · CWE-611 | Высокая7,5 | — | 1,9 % | 8 июл. 2018 г. |
31Наблюдать | CVE-2020-10551Proof of concept | QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.tencent · qqbrowser · CWE-732 | Высокая7,8 | — | 1,4 % | 9 апр. 2020 г. |
31Наблюдать | CVE-2019-13125Эксплойта нет | HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.tencent · habomalhunter · CWE-264 | Высокая7,8 | — | 1,0 % | 1 июл. 2019 г. |
31Наблюдать | CVE-2023-34312Proof of concept | In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-protencent · qq · CWE-763 | Высокая7,8 | — | 0,6 % | 31 мая 2023 г. |
31Наблюдать | CVE-2025-13711Эксплойта нет | Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerabilitytencent · tface · CWE-502 | Высокая7,8 | — | 0,5 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2025-13709Эксплойта нет | Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerabilitytencent · tface · CWE-502 | Высокая7,8 | — | 0,5 % | 23 дек. 2025 г. |
31Наблюдать | CVE-2020-24160Эксплойта нет | Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious tencent · tim · CWE-427 | Высокая7,8 | — | 0,5 % | 3 сент. 2020 г. |
31Наблюдать | CVE-2024-39684Эксплойта нет | Tencent RapidJSON include/rapidjson/reader.h GenericReader::ParseNumber() Function Template Exponent Parsing Integer Overflowtencent · rapidjson · CWE-190 | Высокая7,8 | — | 0,4 % | 9 июл. 2024 г. |
31Наблюдать | CVE-2020-24162Эксплойта нет | The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability.tencent · tencent · CWE-427 | Высокая7,8 | — | 0,4 % | 3 сент. 2020 г. |
30Наблюдать | CVE-2021-40180Эксплойта нет | In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.seartencent · wechat · CWE-200 | Высокая7,5 | — | 1,4 % | 26 июл. 2022 г. |
30Наблюдать | CVE-2021-33057Эксплойта нет | The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) fotencent · qq · CWE-862 | Высокая7,5 | — | 1,3 % | 26 июл. 2022 г. |
30Наблюдать | CVE-2022-35158Эксплойта нет | A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.tencent · tscancode | Высокая7,5 | — | 0,9 % | 3 авг. 2022 г. |
- CVE-2021-2743939Наблюдать
TencentOS-tiny Integer Overflow or Wraparound
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %tencent · tencentos-tiny3 мая 2022 г.
- CVE-2024-3307839Наблюдать
Tencent Libpag v4.3 is vulnerable to Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tencent · libpag1 мая 2024 г.
- CVE-2023-3036339Наблюдать
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tencent · vconsole26 апр. 2023 г.
- CVE-2026-3086039Наблюдать
WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tencent · weknora7 мар. 2026 г.
- CVE-2026-2268739Наблюдать
WeKnora vulnerable to SQL Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %tencent · weknora10 янв. 2026 г.
- CVE-2018-1161636Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %tencent · foxmail30 авг. 2018 г.
- CVE-2026-3086136Наблюдать
WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %tencent · weknora7 мар. 2026 г.
- CVE-2020-2787436Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %tencent · wechat10 февр. 2021 г.
- CVE-2026-2268836Наблюдать
WeKnora has Command Injection in MCP stdio test
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %tencent · weknora10 янв. 2026 г.
- CVE-2024-4043335Наблюдать
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %tencent · wechat26 июл. 2024 г.
- CVE-2026-3085535Наблюдать
WeKnora: Broken Access Control in Tenant Management
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %tencent · weknora7 мар. 2026 г.
- CVE-2021-3387932Наблюдать
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection.
ВысокаяCVSS 8,1Proof of conceptEPSS 1 %tencent · gameloop6 июн. 2021 г.
- CVE-2024-2287332Наблюдать
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %tencent · blueking configuration management database26 февр. 2024 г.
- CVE-2018-1343931Наблюдать
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %tencent · wechat pay8 июл. 2018 г.
- CVE-2020-1055131Наблюдать
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %tencent · qqbrowser9 апр. 2020 г.
- CVE-2019-1312531Наблюдать
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %tencent · habomalhunter1 июл. 2019 г.
- CVE-2023-3431231Наблюдать
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-pro
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %tencent · qq31 мая 2023 г.
- CVE-2025-1371131Наблюдать
Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %tencent · tface23 дек. 2025 г.
- CVE-2025-1370931Наблюдать
Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %tencent · tface23 дек. 2025 г.
- CVE-2020-2416031Наблюдать
Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %tencent · tim3 сент. 2020 г.
- CVE-2024-3968431Наблюдать
Tencent RapidJSON include/rapidjson/reader.h GenericReader::ParseNumber() Function Template Exponent Parsing Integer Overflow
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %tencent · rapidjson9 июл. 2024 г.
- CVE-2020-2416231Наблюдать
The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %tencent · tencent3 сент. 2020 г.
- CVE-2021-4018030Наблюдать
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.sear
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %tencent · wechat26 июл. 2022 г.
- CVE-2021-3305730Наблюдать
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) fo
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %tencent · qq26 июл. 2022 г.
- CVE-2022-3515830Наблюдать
A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %tencent · tscancode3 авг. 2022 г.