Перейти к содержимому
Noroxi

Записи Tencent

47 опубликованных записей вендора tencent.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
23,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

47 записей
  • CVE-2021-27439
    39Наблюдать

    TencentOS-tiny Integer Overflow or Wraparound

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    tencent · tencentos-tiny3 мая 2022 г.

  • CVE-2024-33078
    39Наблюдать

    Tencent Libpag v4.3 is vulnerable to Buffer Overflow.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tencent · libpag1 мая 2024 г.

  • CVE-2023-30363
    39Наблюдать

    vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tencent · vconsole26 апр. 2023 г.

  • CVE-2026-30860
    39Наблюдать

    WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tencent · weknora7 мар. 2026 г.

  • CVE-2026-22687
    39Наблюдать

    WeKnora vulnerable to SQL Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    tencent · weknora10 янв. 2026 г.

  • CVE-2018-11616
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    tencent · foxmail30 авг. 2018 г.

  • CVE-2026-30861
    36Наблюдать

    WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    tencent · weknora7 мар. 2026 г.

  • CVE-2020-27874
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    tencent · wechat10 февр. 2021 г.

  • CVE-2026-22688
    36Наблюдать

    WeKnora has Command Injection in MCP stdio test

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    tencent · weknora10 янв. 2026 г.

  • CVE-2024-40433
    35Наблюдать

    Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    tencent · wechat26 июл. 2024 г.

  • CVE-2026-30855
    35Наблюдать

    WeKnora: Broken Access Control in Tenant Management

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    tencent · weknora7 мар. 2026 г.

  • CVE-2021-33879
    32Наблюдать

    Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection.

    ВысокаяCVSS 8,1Proof of conceptEPSS 1 %

    tencent · gameloop6 июн. 2021 г.

  • CVE-2024-22873
    32Наблюдать

    Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    tencent · blueking configuration management database26 февр. 2024 г.

  • CVE-2018-13439
    31Наблюдать

    WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    tencent · wechat pay8 июл. 2018 г.

  • CVE-2020-10551
    31Наблюдать

    QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    tencent · qqbrowser9 апр. 2020 г.

  • CVE-2019-13125
    31Наблюдать

    HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    tencent · habomalhunter1 июл. 2019 г.

  • CVE-2023-34312
    31Наблюдать

    In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-pro

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    tencent · qq31 мая 2023 г.

  • CVE-2025-13711
    31Наблюдать

    Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    tencent · tface23 дек. 2025 г.

  • CVE-2025-13709
    31Наблюдать

    Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    tencent · tface23 дек. 2025 г.

  • CVE-2020-24160
    31Наблюдать

    Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    tencent · tim3 сент. 2020 г.

  • CVE-2024-39684
    31Наблюдать

    Tencent RapidJSON include/rapidjson/reader.h GenericReader::ParseNumber() Function Template Exponent Parsing Integer Overflow

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    tencent · rapidjson9 июл. 2024 г.

  • CVE-2020-24162
    31Наблюдать

    The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    tencent · tencent3 сент. 2020 г.

  • CVE-2021-40180
    30Наблюдать

    In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.sear

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    tencent · wechat26 июл. 2022 г.

  • CVE-2021-33057
    30Наблюдать

    The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) fo

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    tencent · qq26 июл. 2022 г.

  • CVE-2022-35158
    30Наблюдать

    A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    tencent · tscancode3 авг. 2022 г.