VulnSea

tencent has 6 CVEs on record between 2025 and 2026. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: AI-Infra-Guard (2), WeKnora (2), BrowserSkill (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • AI-Infra-Guard 2
  • WeKnora 2
  • BrowserSkill 1
  • Mass Service Engine in Cluster (MSEC) 1
6
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

tencent vulnerabilities

CVEs affecting tencent, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-101080Medium· 4.8PoC
1w ago

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2

A vulnerability was identified in Tencent AI-Infra-Guard up to 4.5.2/4.6.2. This affects the function startsWith of the file skill_scan/tools/dir/dir_actions.py of the component File Access. The manipulation leads to path traversal. The …

▾ TwilightTencent · AI-Infra-GuardEPSS 0.14%via NVD
CVE-2026-94111Medium· 6.6
2w ago

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p

Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin validation that accepts any chrome-extension origin with 32 characters in range a-p. Attackers can register a malicio…

▾ SunlitTencent · BrowserSkillEPSS 0.14%via NVD
CVE-2026-89040Critical· 9.8
3w ago

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code…

▾ MidnightTencent · Mass Service Engine in Cluster (MSEC)EPSS 1.1%via NVD
CVE-2026-91750Medium· 6.5PoC
3w ago

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…

▾ TwilightTencent · WeKnoraEPSS 0.44%via NVD
CVE-2026-84809Medium· 6.5PoC
1mo ago

Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces

Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pycache__ directories and .pyc/.pyo/.pyd extensions into skip lists across multiple scanning surfaces. Attackers can dist…

▾ TwilightTencent · AI-Infra-GuardEPSS 0.57%via NVD
CVE-2025-11046High· 7.3
1y ago

A security flaw has been discovered in Tencent WeKnora 0.1.0

A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /api/v1/initialization/embedding/test. The manipulation of the argument baseUrl results in server-side request forgery…

▾ Twilighttencent · weknoraEPSS 0.47%via NVD
tencent vulnerabilities (CVEs) · VulnSea