Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.51% | — | Tencent MedicalnetAI | 23/12/2025 | 17/6/2026 | Tencent MedicalNet generate_model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent MedicalNet. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.8) | 0.52% | — | Tencent Hunyuan3d-1AI | 23/12/2025 | 17/6/2026 | Tencent Hunyuan3D-1 load_pretrained Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent Hunyuan3D-1. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.8) | 0.51% | — | Tencent HunyuanditAI | 23/12/2025 | 17/6/2026 | Tencent HunyuanDiT merge Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent HunyuanDiT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Alta (7.8) | 0.51% | — | Tencent Tface | 23/12/2025 | 17/6/2026 | Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Aplazada | Alta (7.8) | 0.51% | — | Tencent HunyuanvideoAI | 23/12/2025 | 17/6/2026 | Tencent HunyuanVideo load_vae Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent HunyuanVideo. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.51% | — | Tencent Tface | 23/12/2025 | 17/6/2026 | Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Aplazada | Alta (7.8) | 0.51% | — | Tencent Neuralnlp-neuralclassifierAI | 23/12/2025 | 17/6/2026 | Tencent NeuralNLP-NeuralClassifier _load_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent NeuralNLP-NeuralClassifier. User interaction is required to exploit this vulnerability in… | |
| Aplazada | Alta (7.8) | 0.51% | — | Tencent HunyuanditAI | 23/12/2025 | 17/6/2026 | Tencent HunyuanDiT model_resume Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent HunyuanDiT. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Aplazada | Alta (7.8) | 0.51% | — | Tencent PatrickstarAI | 23/12/2025 | 17/6/2026 | Tencent PatrickStar merge_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent PatrickStar. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.5) | 0.23% | — | Tencent Docs | 4/11/2025 | 17/6/2026 | Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component. | |
| Analizada | Media (5.5) | 0.47% | — | Tencent Weknora | 26/9/2025 | 17/6/2026 | A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery. The attack can be launched remotely. The exploit has been released to the public… | |
| Aplazada | Baja (2.1) | 0.27% | — | Tencent WblogAI | 24/8/2025 | 17/6/2026 | A vulnerability was identified in wangsongyan wblog 0.0.1. This affects the function RestorePost of the file backup.go. Such manipulation of the argument fileName leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was… | |
| Aplazada | Alta (7.2) | 0.39% | — | Cocotais BOTAITencent Qq-bot-sdkAI | 17/5/2025 | 17/6/2026 | Cocotais Bot is a QQ official robot framework based on qq-bot-sdk. Starting in version 1.5.0-test2-hotfix and prior to version 1.6.2, command echoing feature in the framework allows users to indirectly trigger privileged behavior by injecting special platform tags. Specifically, an unauthorized user can use the `/echo… | |
| Analizada | Media (5.1) | 0.69% | — | Tencentmusic Supersonic | 3/4/2025 | 17/6/2026 | A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may… | |
| Aplazada | Media (5.5) | 0.19% | — | Tencent Technology Beijing Company Limited Tencent Microvision IOSAI | 27/2/2025 | 17/6/2026 | An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Tencent WesingAI | 27/1/2025 | 17/6/2026 | An issue in Tencent Technology (Shanghai) Co., Ltd WeSing iOS v9.3.39 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (6.5) | 0.32% | — | Tencent Technology Qqmail IOSAI | 27/1/2025 | 17/6/2026 | An issue in Tencent Technology (Shenzhen) Company Limited QQMail iOS 6.6.4 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Media (5.4) | 0.45% | — | Tencentcloud-cosAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects tencentcloud-cos: from n/a through 1.0.7. | |
| Analizada | Alta (8.8) | 1.2% | — | Tencent Wechat | 26/7/2024 | 17/6/2026 | Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component. | |
| Aplazada | Alta (7.8) | 0.42% | — | Tencent RapidjsonAI | 9/7/2024 | 17/6/2026 | Tencent RapidJSON is vulnerable to privilege escalation due to an integer overflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer overflow… | |
| Aplazada | Alta (7.8) | 0.38% | — | Tencent RapidjsonAI | 9/7/2024 | 17/6/2026 | Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow… | |
| Analizada | Media (5.3) | 0.24% | — | Tencent Libpag | 3/5/2024 | 17/6/2026 | Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file. | |
| Analizada | Crítica (9.8) | 1.1% | — | Tencent Libpag | 1/5/2024 | 17/6/2026 | Tencent Libpag v4.3 is vulnerable to Buffer Overflow. A user can send a crafted image to trigger a overflow leading to remote code execution. | |
| Modificada | Alta (8.1) | 0.55% | — | Tencent Blueking Configuration Management Database | 26/2/2024 | 9/7/2026 | Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request. | |
| Modificada | Alta (7.5) | 0.82% | — | Tencent Distributed SQL | 31/12/2023 | 17/6/2026 | Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387. |