vciy

CVEs we hold for Qt

Records whose assigning authority named Qt as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9499Out-of-bounds read in QTextCodec::codecForName() in QtQt
CVE-2026-76151Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework…qt
CVE-2026-6210Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crashQt
CVE-2026-19248Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qtqt
CVE-2026-15037XML injection vulnerability in QDom comment, CDATA and processing-instruction serializationQt
CVE-2026-13326Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC moduleqt
CVE-2026-12593Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystemQt Axivion
CVE-2026-12379URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of AxivionQt Axivion
CVE-2026-11573Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml)qt
CVE-2025-6338Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backendQt
CVE-2025-5992Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of serviceQt
CVE-2025-5991Use after free in QHttp2ProtocolHandlerQt
CVE-2025-5683no title heldQt
CVE-2025-5455Possible denial of service when passing malformed data in a URL to qDecodeDataUrlQt
CVE-2025-4211Improper Link Resolution Before File Access in QFileSystemEngine on WindowsQt
CVE-2025-3512Buffer overflow in QTextMarkdownImporterQt
CVE-2025-30348no title heldQt
CVE-2025-23050no title heldQt
CVE-2025-14576Possible QML code injection in VectorImage componentQt
CVE-2025-14575Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingQt
CVE-2025-12385Improper validation of <img> tag size in Text component parserQt
CVE-2025-10729Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVGQt
CVE-2025-10728Uncontrolled recursion in Qt SVG moduleQt
CVE-2022-43591no title heldQt
CVE-2022-40983no title heldQt
CVE-2021-3481no title heldn/a qt
CVE-2020-0570no title heldn/a QT Library
CVE-2015-10092Qtranslate Slug Plugin class-qtranslate-slug.php add_slug_meta_box cross site scriptingn/a Qtranslate Slug Plugin
CVE-2014-125088qt-users-jp silk header.qml cross site scriptingqt-users-jp silk
CVE-2011-2916no title heldqtnx

30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.