Vulnerability index

Browse CVEs

46 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Weknora MEDIUM 6.3
CVE-2026-8786

A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file i…

Fix: after 0.3.6
Fix from $1,600 2026-05-18
Ai Infra Guard HIGH 7.5
CVE-2026-5585

A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of …

No fix yet
Fix from $1,950 2026-04-05
Weknora CRITICAL 9.8
CVE-2026-30860

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution…

Fix: 0.2.12+
Fix from $2,300 2026-03-07
Weknora HIGH 8.8
CVE-2026-30855

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass …

Fix: 0.3.2+
Fix from $1,950 2026-03-07
Weknora HIGH 8.8
CVE-2026-30861

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an …

Fix: 0.2.10+
Fix from $1,950 2026-03-07
Weknora HIGH 7.6
CVE-2026-30856

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involvi…

Fix: 0.3.0+
Fix from $1,950 2026-03-07
Weknora HIGH 7.5
CVE-2026-30858

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerab…

Fix: 0.3.0+
Fix from $1,950 2026-03-07
Weknora MEDIUM 6.5
CVE-2026-30859

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control…

Fix: 0.2.12+
Fix from $1,600 2026-03-07
Weknora MEDIUM 5.3
CVE-2026-30857

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authoriza…

Fix: 0.3.0+
Fix from $1,600 2026-03-07
Weknora HIGH 7.5
CVE-2026-30247

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Impo…

Fix: 0.2.12+
Fix from $1,950 2026-03-07
Pcmanager HIGH 7.4
CVE-2025-63946

A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute progr…

Fix: after 17.10.28554.205
Fix from $1,950 2026-02-23
Ioa HIGH 7.4
CVE-2025-63945

A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs …

Fix: 210.9.28693.62001+
Fix from $1,950 2026-02-23
Weknora CRITICAL 9.8
CVE-2026-22687

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables th…

Fix: 0.2.5+
Fix from $2,300 2026-01-10
Weknora HIGH 8.8
CVE-2026-22688

WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injec…

Fix: 0.2.5+
Fix from $1,950 2026-01-10
Tface HIGH 7.8
CVE-2025-13709

Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to…

Fix: 2025-09-29+
Fix from $1,950 2025-12-23
Tface HIGH 7.8
CVE-2025-13711

Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbit…

Fix: 2025-09-29+
Fix from $1,950 2025-12-23
Docs HIGH 7.5
CVE-2025-56230

Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component.

Fix: after 3.9.20
Fix from $1,950 2025-11-04
Weknora CRITICAL 9.8
CVE-2025-11046

A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embeddi…

Mitigation only
Fix from $2,300 2025-09-26
Wechat HIGH 8.8
CVE-2024-40433

Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.

No fix yet
Fix from $1,950 2024-07-26
Libpag MEDIUM 5.3
CVE-2024-34408

Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable A…

Fix: after 4.3.51
Fix from $1,600 2024-05-03
Libpag CRITICAL 9.8
CVE-2024-33078

Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution.

Mitigation only
Fix from $2,300 2024-05-01
Blueking Configuration Management Database HIGH 8.1
CVE-2024-22873

Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/s…

Fix: after 3.9.47
Fix from $1,950 2024-02-26
Tencent Distributed Sql HIGH 7.5
CVE-2023-52286

Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info r…

Fix: after 1.8.5
Fix from $1,950 2023-12-31
Enterprise Wechat Privatization HIGH 7.5
CVE-2023-40829

There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.

Mitigation only
Fix from $1,950 2023-10-12
Wxsync MEDIUM 5.4
CVE-2023-39988

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 标准云(std.Cloud) WxSync plugin <= 2.7.23 versions.

Fix: after 2.7.23
Fix from $1,600 2023-09-04
Qq HIGH 7.8
CVE-2023-34312

In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process comm…

Fix: after 9.7.8.29039
Fix from $1,950 2023-06-01
Vconsole CRITICAL 9.8
CVE-2023-30363

vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.

No fix yet
Fix from $2,300 2023-04-26
Tscancode HIGH 7.5
CVE-2022-35158

A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.

No fix yet
Fix from $1,950 2022-08-03
Wechat HIGH 7.5
CVE-2021-40180

In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContact…

No fix yet
Fix from $1,950 2022-07-26
Qq HIGH 7.5
CVE-2021-33057

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determi…

No fix yet
Fix from $1,950 2022-07-26