CVEs we hold for Qt
Records whose assigning authority named Qt as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-76151Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework…qt
CVE-2026-6210Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crashQt
CVE-2026-15037XML injection vulnerability in QDom comment, CDATA and processing-instruction serializationQt
CVE-2026-13326Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC moduleqt
CVE-2026-12593Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystemQt Axivion
CVE-2026-12379URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of AxivionQt Axivion
CVE-2026-11573Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml)qt
CVE-2025-6338Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backendQt
CVE-2025-5992Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of serviceQt
CVE-2025-14575Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingQt
CVE-2025-10729Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVGQt
CVE-2015-10092Qtranslate Slug Plugin class-qtranslate-slug.php add_slug_meta_box cross site scriptingn/a Qtranslate Slug Plugin
30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.