VYPR

Vendor CVEs

Tencent

All CVEs

62 total · sorted by risk
  • CVE-2026-30859MedMar 7, 2026
    risk 0.34cvss 5.3epss 0.00

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.12, a broken access control vulnerability in the database query tool allows any authenticated tenant to read sensitive data belonging to other tenants,…

  • CVE-2026-30857MedMar 7, 2026
    risk 0.34cvss 5.3epss 0.00

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.3.0, a cross-tenant authorization bypass in the knowledge base copy endpoint allows any authenticated user to clone (duplicate) another tenant’s knowledge…

  • CVE-2026-22687MedJan 10, 2026
    risk 0.29cvss 5.6epss 0.00

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, after WeKnora enables the Agent service, it allows users to call the database query tool. Due to insufficient backend validation, an attacker can use…

  • CVE-2026-50144HigJul 15, 2026
    risk 0.00cvss 7.1epss 0.00

    ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434e1d844ea0551b880a1cfb079ce1 and earlier, ncnn allows an out-of-bounds heap write in ncnn::ParamDict::load_param() when Net::load_param() loads a malicious…

  • CVE-2026-15515HigJul 13, 2026
    risk 0.00cvss 7.0epss 0.00

    A security vulnerability has been detected in Tencent PC Manager 18.1.30242.301. This issue affects some unknown processing in the library qmudisk64.sys of the component QMUDisk Driver. The manipulation leads to uncontrolled search path. The attack must be carried out locally.…

  • CVE-2025-13711HigDec 23, 2025
    risk 0.00cvss 7.8epss 0.01

    Tencent TFace eval Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in that the…

  • CVE-2025-13709HigDec 23, 2025
    risk 0.00cvss 7.8epss 0.01

    Tencent TFace restore_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent TFace. User interaction is required to exploit this vulnerability in…

  • CVE-2024-34408MedMay 3, 2024
    risk 0.00cvss 5.3epss 0.00

    Tencent libpag through 4.3.51 has an integer overflow in DecodeStream::checkEndOfFile() in codec/utils/DecodeStream.cpp via a crafted PAG (Portable Animated Graphics) file.

  • CVE-2011-4867Jan 25, 2012
    risk 0.00cvss —epss 0.01

    The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a crafted application.

  • CVE-2011-4865Jan 25, 2012
    risk 0.00cvss —epss 0.01

    The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.

  • CVE-2011-4864Jan 25, 2012
    risk 0.00cvss —epss 0.01

    The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application.

  • CVE-2011-4863Jan 25, 2012
    risk 0.00cvss —epss 0.01

    The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS/MMS messages and a contact list via a crafted application.

Page 2 of 2