Vulnerabilities
Summary — last 7 days
New vulnerabilities2,806▲ 5 vs. last week
Critical / high1,465▲ 246 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)77▼ 441 vs. last week
74 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (0.9) | 0.14% | — | Tencent Ai-infra-guardAI | 9/28/2026 | 9/28/2026 | A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit is publicly available and might… | |
| Deferred | Medium (6.9) | 0.14% | — | Tencent BrowserskillAI | 9/20/2026 | 9/22/2026 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicious extension as a browser client to intercept and manipulate page content, DOM,… | |
| Awaiting Analysis | Critical (9.3) | 1.1% | — | Tencent Mass Service EngineAI | 9/15/2026 | 9/22/2026 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root. | |
| Deferred | High (7.1) | 0.44% | — | Tencent WeknoraAI | 9/14/2026 | 9/23/2026 | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation by supplying a public URL that redirects to internal network addresses, allowing… | |
| Deferred | High (7.1) | 0.57% | — | Tencent Ai-infra-guardAI | 9/2/2026 | 9/24/2026 | Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can distribute skills with benign Python source files alongside malicious compiled… | |
| Deferred | Critical (9.8) | 0.68% | — | Tencent ApijsonAI | 8/10/2026 | 8/28/2026 | A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read arbitrary database tables via the Map-form @having operator. | |
| Deferred | Medium (6.4) | 0.16% | — | Tencent PC ManagerAI | 7/13/2026 | 7/15/2026 | A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally. The attack is considered to have high… | |
| Deferred | Medium (5.1) | 0.15% | — | Tencent WifisecurityAI | 7/10/2026 | 7/10/2026 | Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings. | |
| Analyzed | Low (2.1) | 0.42% | — | Tencent Weknora | 5/18/2026 | 6/17/2026 | A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component Config API Endpoint. The manipulation of the argument kbId leads to authorization bypass. It is possible to initiate… | |
| Deferred | Medium (5.5) | 0.51% | — | Tencentcloud Cloudbase-mcpAI | 4/28/2026 | 7/24/2026 | A vulnerability was found in TencentCloudBase CloudBase-MCP up to 2.17.0. Affected is the function openUrl of the file mcp/src/interactive-server.ts of the component open-url API Endpoint. The manipulation of the argument req.body.url results in server-side request forgery. It is possible to launch the attack… | |
| Analyzed | Medium (5.5) | 0.77% | — | Tencent Ai-infra-guard | 4/5/2026 | 7/24/2026 | A vulnerability was found in Tencent AI-Infra-Guard 4.0. The affected element is an unknown function of the file common/websocket/task_manager.go of the component Task Detail Endpoint. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public… | |
| Analyzed | High (8.8) | 2.5% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5 to before version 0.2.10, an unauthenticated remote code execution (RCE) vulnerability exists in the MCP stdio configuration validation. The application allows unrestricted user registration, meaning… | |
| Analyzed | Critical (9.8) | 0.74% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a remote code execution (RCE) vulnerability exists in the application's database query functionality. The validation system fails to recursively inspect child nodes within PostgreSQL array… | |
| Analyzed | Medium (6.5) | 0.36% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated tenant to read sensitive data belonging to other tenants, including API keys, model configurations, and… | |
| Analyzed | High (7.5) | 0.48% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a DNS rebinding vulnerability in the web_fetch tool allows an unauthenticated attacker to bypass URL validation and access internal resources on the server, including private IP addresses (e.g.,… | |
| Analyzed | Medium (5.3) | 0.28% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any authenticated user to clone (duplicate) another tenant’s knowledge base into their own tenant by… | |
| Analyzed | High (7.6) | 0.29% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a vulnerability involving tool name collision and indirect prompt injection allows a malicious remote MCP server to hijack tool execution. By exploiting an ambiguous naming convention in the MCP… | |
| Analyzed | High (8.8) | 0.46% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.2, an authorization bypass in tenant management endpoints of WeKnora application allows any authenticated user to read, modify, or delete any tenant by ID. Since account registration is open to the… | |
| Analyzed | High (7.5) | 0.35% | — | Tencent Weknora | 3/7/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, the application's "Import document via URL" feature is vulnerable to Server-Side Request Forgery (SSRF) through HTTP redirects. While the backend implements comprehensive URL validation… | |
| Analyzed | High (7.4) | 0.19% | — | Tencent Pcmanager | 2/23/2026 | 6/17/2026 | A privilege escalation (PE) vulnerability in the Tencent PC Manager app thru 17.10.28554.205 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition. | |
| Analyzed | High (7.4) | 0.19% | — | Tencent IOA | 2/23/2026 | 6/17/2026 | A privilege escalation (PE) vulnerability in the Tencent iOA app thru 210.9.28693.621001 on Windows devices enables a local user to execute programs with elevated privileges. However, execution requires that the local user is able to successfully exploit a race condition. | |
| Analyzed | High (8.8) | 2.0% | — | Tencent Weknora | 1/10/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server to execute subprocesses using these… | |
| Modified | Critical (9.8) | 0.39% | — | Tencent Weknora | 1/10/2026 | 6/17/2026 | WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use prompt‑based bypass techniques to evade… | |
| Deferred | High (7.8) | 0.51% | — | Tencent MimicmotionAI | 12/23/2025 | 6/17/2026 | Tencent MimicMotion create_pipeline Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent MimicMotion. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Deferred | High (7.8) | 0.43% | — | Tencent Facedetection-dsfdAI | 12/23/2025 | 6/17/2026 | Tencent FaceDetection-DSFD resnet Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent FaceDetection-DSFD. User interaction is required to exploit this vulnerability in that the target must visit… |