tencent has 6 CVEs on record between 2025 and 2026. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: AI-Infra-Guard (2), WeKnora (2), BrowserSkill (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Products
- AI-Infra-Guard 2
- WeKnora 2
- BrowserSkill 1
- Mass Service Engine in Cluster (MSEC) 1
Worst active — by depth score
CVE-2026-89040Critical· 9.8Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device54CVE-2026-91750Medium· 6.5WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs48CVE-2026-84809Medium· 6.5Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces48CVE-2025-11046High· 7.3A security flaw has been discovered in Tencent WeKnora 0.1.040CVE-2026-101080Medium· 4.8A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.238
tencent vulnerabilities
CVEs affecting tencent, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-101080Medium· 4.8PoCA vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2
A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The …
CVE-2026-94111Medium· 6.6Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p
Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicio…
CVE-2026-89040Critical· 9.8Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code…
CVE-2026-91750Medium· 6.5PoCWeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs
WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…
CVE-2026-84809Medium· 6.5PoCTencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces
Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can dist…
CVE-2025-11046High· 7.3A security flaw has been discovered in Tencent WeKnora 0.1.0
A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery…