İçeriğe atla
Noroxi

Tencent kayıtları

tencent üreticisine ait 47 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%23,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

47 kayıt
  • CVE-2021-27439
    39İzleyin

    TencentOS-tiny Integer Overflow or Wraparound

    KritikCVSS 9,8İstismar yokEPSS %2

    tencent · tencentos-tiny3 May 2022

  • CVE-2024-33078
    39İzleyin

    Tencent Libpag v4.3 is vulnerable to Buffer Overflow.

    KritikCVSS 9,8İstismar yokEPSS %1

    tencent · libpag1 May 2024

  • CVE-2023-30363
    39İzleyin

    vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.

    KritikCVSS 9,8İstismar yokEPSS %1

    tencent · vconsole26 Nis 2023

  • CVE-2026-30860
    39İzleyin

    WeKnora: Remote Code Execution via SQL Injection Bypass in AI Database Query Tool

    KritikCVSS 9,8İstismar yokEPSS %1

    tencent · weknora7 Mar 2026

  • CVE-2026-22687
    39İzleyin

    WeKnora vulnerable to SQL Injection

    KritikCVSS 9,8İstismar yokEPSS %0

    tencent · weknora10 Oca 2026

  • CVE-2018-11616
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.

    YüksekCVSS 8,8İstismar yokEPSS %5

    tencent · foxmail30 Ağu 2018

  • CVE-2026-30861
    36İzleyin

    WeKnora: Remote Code Execution (RCE) via Command Injection in MCP Stdio Configuration Validation

    YüksekCVSS 8,8İstismar yokEPSS %2

    tencent · weknora7 Mar 2026

  • CVE-2020-27874
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18.

    YüksekCVSS 8,8İstismar yokEPSS %2

    tencent · wechat10 Şub 2021

  • CVE-2026-22688
    36İzleyin

    WeKnora has Command Injection in MCP stdio test

    YüksekCVSS 8,8İstismar yokEPSS %2

    tencent · weknora10 Oca 2026

  • CVE-2024-40433
    35İzleyin

    Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

    YüksekCVSS 8,8İstismar yokEPSS %1

    tencent · wechat26 Tem 2024

  • CVE-2026-30855
    35İzleyin

    WeKnora: Broken Access Control in Tenant Management

    YüksekCVSS 8,8İstismar yokEPSS %0

    tencent · weknora7 Mar 2026

  • CVE-2021-33879
    32İzleyin

    Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection.

    YüksekCVSS 8,1Kavram kanıtıEPSS %1

    tencent · gameloop6 Haz 2021

  • CVE-2024-22873
    32İzleyin

    Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/

    YüksekCVSS 8,1İstismar yokEPSS %1

    tencent · blueking configuration management database26 Şub 2024

  • CVE-2018-13439
    31İzleyin

    WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.

    YüksekCVSS 7,5İstismar yokEPSS %2

    tencent · wechat pay8 Tem 2018

  • CVE-2020-10551
    31İzleyin

    QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    tencent · qqbrowser9 Nis 2020

  • CVE-2019-13125
    31İzleyin

    HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.

    YüksekCVSS 7,8İstismar yokEPSS %1

    tencent · habomalhunter1 Tem 2019

  • CVE-2023-34312
    31İzleyin

    In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-pro

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    tencent · qq31 May 2023

  • CVE-2025-13711
    31İzleyin

    Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %1

    tencent · tface23 Ara 2025

  • CVE-2025-13709
    31İzleyin

    Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %1

    tencent · tface23 Ara 2025

  • CVE-2020-24160
    31İzleyin

    Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious

    YüksekCVSS 7,8İstismar yokEPSS %0

    tencent · tim3 Eyl 2020

  • CVE-2024-39684
    31İzleyin

    Tencent RapidJSON include/rapidjson/reader.h GenericReader::ParseNumber() Function Template Exponent Parsing Integer Overflow

    YüksekCVSS 7,8İstismar yokEPSS %0

    tencent · rapidjson9 Tem 2024

  • CVE-2020-24162
    31İzleyin

    The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability.

    YüksekCVSS 7,8İstismar yokEPSS %0

    tencent · tencent3 Eyl 2020

  • CVE-2021-40180
    30İzleyin

    In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.sear

    YüksekCVSS 7,5İstismar yokEPSS %1

    tencent · wechat26 Tem 2022

  • CVE-2021-33057
    30İzleyin

    The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) fo

    YüksekCVSS 7,5İstismar yokEPSS %1

    tencent · qq26 Tem 2022

  • CVE-2022-35158
    30İzleyin

    A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.

    YüksekCVSS 7,5İstismar yokEPSS %1

    tencent · tscancode3 Ağu 2022