VulnSea

Tencent has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.6 (medium), with 1 rated critical.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.6
Publish → KEV
Last 90 days
3 prev 0

Products

  • BrowserSkill 1
  • Mass Service Engine in Cluster (MSEC) 1
  • WeKnora 1
3
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Tencent vulnerabilities

CVEs affecting Tencent, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-94111Medium· 6.6
2d ago

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicio…

SunlitTencent · BrowserSkillEPSS 0.10%via NVD
CVE-2026-89040Critical· 9.8
1w ago

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code…

MidnightTencent · Mass Service Engine in Cluster (MSEC)EPSS 0.93%via NVD
CVE-2026-91750Medium· 6.5PoC
1w ago

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…

TwilightTencent · WeKnoraEPSS 0.27%via NVD
Tencent vulnerabilities (CVEs) · VulnSea