Tencent kayıtları
tencent üreticisine ait 47 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %23,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-59 Improper Link Resolution Before File Access ('Link Following')2
- CWE-190 Integer Overflow or Wraparound2
- CWE-284 Improper Access Control2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
47 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2021-27439İstismar yok | TencentOS-tiny Integer Overflow or Wraparoundtencent · tencentos-tiny · CWE-190 | Kritik9,8 | — | %1,6 | 3 May 2022 |
39İzleyin | CVE-2024-33078İstismar yok | Tencent Libpag v4.3 is vulnerable to Buffer Overflow.tencent · libpag · CWE-680 | Kritik9,8 | — | %1,1 | 1 May 2024 |
39İzleyin | CVE-2023-30363İstismar yok | vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.tencent · vconsole · CWE-1321 | Kritik9,8 | — | %1,0 | 26 Nis 2023 |
39İzleyin | CVE-2026-30860İstismar yok | WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tooltencent · weknora · CWE-89 | Kritik9,8 | — | %0,7 | 7 Mar 2026 |
39İzleyin | CVE-2026-22687İstismar yok | WeKnora vulnerable to SQL Injectiontencent · weknora · CWE-89 | Kritik9,8 | — | %0,4 | 10 Oca 2026 |
36İzleyin | CVE-2018-11616İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.tencent · foxmail · CWE-78 | Yüksek8,8 | — | %4,9 | 30 Ağu 2018 |
36İzleyin | CVE-2026-30861İstismar yok | WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validationtencent · weknora · CWE-78 | Yüksek8,8 | — | %2,5 | 7 Mar 2026 |
36İzleyin | CVE-2020-27874İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18.tencent · wechat · CWE-119 | Yüksek8,8 | — | %2,1 | 10 Şub 2021 |
36İzleyin | CVE-2026-22688İstismar yok | WeKnora has Command Injection in MCP stdio testtencent · weknora · CWE-77 | Yüksek8,8 | — | %2,0 | 10 Oca 2026 |
35İzleyin | CVE-2024-40433İstismar yok | Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.tencent · wechat · CWE-266 | Yüksek8,8 | — | %1,2 | 26 Tem 2024 |
35İzleyin | CVE-2026-30855İstismar yok | WeKnora: Broken Access Control in Tenant Managementtencent · weknora · CWE-284 | Yüksek8,8 | — | %0,5 | 7 Mar 2026 |
32İzleyin | CVE-2021-33879Kavram kanıtı | Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection.tencent · gameloop · CWE-494 | Yüksek8,1 | — | %1,0 | 6 Haz 2021 |
32İzleyin | CVE-2024-22873İstismar yok | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/tencent · blueking configuration management database · CWE-918 | Yüksek8,1 | — | %0,5 | 26 Şub 2024 |
31İzleyin | CVE-2018-13439İstismar yok | WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.tencent · wechat pay · CWE-611 | Yüksek7,5 | — | %1,9 | 8 Tem 2018 |
31İzleyin | CVE-2020-10551Kavram kanıtı | QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.tencent · qqbrowser · CWE-732 | Yüksek7,8 | — | %1,4 | 9 Nis 2020 |
31İzleyin | CVE-2019-13125İstismar yok | HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.tencent · habomalhunter · CWE-264 | Yüksek7,8 | — | %1,0 | 1 Tem 2019 |
31İzleyin | CVE-2023-34312Kavram kanıtı | In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-protencent · qq · CWE-763 | Yüksek7,8 | — | %0,6 | 31 May 2023 |
31İzleyin | CVE-2025-13711İstismar yok | Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerabilitytencent · tface · CWE-502 | Yüksek7,8 | — | %0,5 | 23 Ara 2025 |
31İzleyin | CVE-2025-13709İstismar yok | Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerabilitytencent · tface · CWE-502 | Yüksek7,8 | — | %0,5 | 23 Ara 2025 |
31İzleyin | CVE-2020-24160İstismar yok | Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious tencent · tim · CWE-427 | Yüksek7,8 | — | %0,5 | 3 Eyl 2020 |
31İzleyin | CVE-2024-39684İstismar yok | Tencent RapidJSON include/rapidjson/reader.h GenericReader::ParseNumber() Function Template Exponent Parsing Integer Overflowtencent · rapidjson · CWE-190 | Yüksek7,8 | — | %0,4 | 9 Tem 2024 |
31İzleyin | CVE-2020-24162İstismar yok | The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability.tencent · tencent · CWE-427 | Yüksek7,8 | — | %0,4 | 3 Eyl 2020 |
30İzleyin | CVE-2021-40180İstismar yok | In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.seartencent · wechat · CWE-200 | Yüksek7,5 | — | %1,4 | 26 Tem 2022 |
30İzleyin | CVE-2021-33057İstismar yok | The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) fotencent · qq · CWE-862 | Yüksek7,5 | — | %1,3 | 26 Tem 2022 |
30İzleyin | CVE-2022-35158İstismar yok | A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.tencent · tscancode | Yüksek7,5 | — | %0,9 | 3 Ağu 2022 |
- CVE-2021-2743939İzleyin
TencentOS-tiny Integer Overflow or Wraparound
KritikCVSS 9,8İstismar yokEPSS %2tencent · tencentos-tiny3 May 2022
- CVE-2024-3307839İzleyin
Tencent Libpag v4.3 is vulnerable to Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %1tencent · libpag1 May 2024
- CVE-2023-3036339İzleyin
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
KritikCVSS 9,8İstismar yokEPSS %1tencent · vconsole26 Nis 2023
- CVE-2026-3086039İzleyin
WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool
KritikCVSS 9,8İstismar yokEPSS %1tencent · weknora7 Mar 2026
- CVE-2026-2268739İzleyin
WeKnora vulnerable to SQL Injection
KritikCVSS 9,8İstismar yokEPSS %0tencent · weknora10 Oca 2026
- CVE-2018-1161636İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.
YüksekCVSS 8,8İstismar yokEPSS %5tencent · foxmail30 Ağu 2018
- CVE-2026-3086136İzleyin
WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation
YüksekCVSS 8,8İstismar yokEPSS %2tencent · weknora7 Mar 2026
- CVE-2020-2787436İzleyin
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18.
YüksekCVSS 8,8İstismar yokEPSS %2tencent · wechat10 Şub 2021
- CVE-2026-2268836İzleyin
WeKnora has Command Injection in MCP stdio test
YüksekCVSS 8,8İstismar yokEPSS %2tencent · weknora10 Oca 2026
- CVE-2024-4043335İzleyin
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.
YüksekCVSS 8,8İstismar yokEPSS %1tencent · wechat26 Tem 2024
- CVE-2026-3085535İzleyin
WeKnora: Broken Access Control in Tenant Management
YüksekCVSS 8,8İstismar yokEPSS %0tencent · weknora7 Mar 2026
- CVE-2021-3387932İzleyin
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection.
YüksekCVSS 8,1Kavram kanıtıEPSS %1tencent · gameloop6 Haz 2021
- CVE-2024-2287332İzleyin
Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/
YüksekCVSS 8,1İstismar yokEPSS %1tencent · blueking configuration management database26 Şub 2024
- CVE-2018-1343931İzleyin
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
YüksekCVSS 7,5İstismar yokEPSS %2tencent · wechat pay8 Tem 2018
- CVE-2020-1055131İzleyin
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.
YüksekCVSS 7,8Kavram kanıtıEPSS %1tencent · qqbrowser9 Nis 2020
- CVE-2019-1312531İzleyin
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
YüksekCVSS 7,8İstismar yokEPSS %1tencent · habomalhunter1 Tem 2019
- CVE-2023-3431231İzleyin
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-pro
YüksekCVSS 7,8Kavram kanıtıEPSS %1tencent · qq31 May 2023
- CVE-2025-1371131İzleyin
Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %1tencent · tface23 Ara 2025
- CVE-2025-1370931İzleyin
Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %1tencent · tface23 Ara 2025
- CVE-2020-2416031İzleyin
Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious
YüksekCVSS 7,8İstismar yokEPSS %0tencent · tim3 Eyl 2020
- CVE-2024-3968431İzleyin
Tencent RapidJSON include/rapidjson/reader.h GenericReader::ParseNumber() Function Template Exponent Parsing Integer Overflow
YüksekCVSS 7,8İstismar yokEPSS %0tencent · rapidjson9 Tem 2024
- CVE-2020-2416231İzleyin
The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability.
YüksekCVSS 7,8İstismar yokEPSS %0tencent · tencent3 Eyl 2020
- CVE-2021-4018030İzleyin
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.sear
YüksekCVSS 7,5İstismar yokEPSS %1tencent · wechat26 Tem 2022
- CVE-2021-3305730İzleyin
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) fo
YüksekCVSS 7,5İstismar yokEPSS %1tencent · qq26 Tem 2022
- CVE-2022-3515830İzleyin
A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.
YüksekCVSS 7,5İstismar yokEPSS %1tencent · tscancode3 Ağu 2022