The Qt Company
First CVE: Apr 11, 2025Active for: 1 year
17
CVEs Published
More CVEs Published than 36% of tracked CNAs
8.5
Avg CVEs / Year
More Avg CVEs / Year than 49% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by The Qt Company over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2025
15 months ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by The Qt Company as a CNA, regardless of affected vendor or product.
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12593HIGH The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token for another u | Jul 9, 2026 | 8.7 | 37 | NO | NO |
CVE-2025-14576HIGH Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. | Apr 30, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-10729CRITICAL The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free. | Oct 3, 2025 | 9.4 | 32 | NO | NO |
CVE-2025-10728CRITICAL When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS | Oct 3, 2025 | 9.4 | 31 | NO | NO |
CVE-2026-6210HIGH A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image.
When processing SVG marker references, the renderer retrieves | May 6, 2026 | 8.7 | 30 | NO | NO |
CVE-2025-6338CRITICAL There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period.This issue affects Qt from 5.15.0 | Oct 16, 2025 | 9.2 | 29 | NO | NO |
CVE-2026-12379MEDIUM An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authenti | Jul 16, 2026 | 6.8 | 28 | NO | NO |
CVE-2025-12385HIGH Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, | Dec 3, 2025 | 8.7 | 28 | NO | NO |
CVE-2026-9499MEDIUM An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for exa | Jul 21, 2026 | 6.3 | 27 | NO | NO |
CVE-2025-5455HIGH An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.
If the function was ca | Jun 2, 2025 | 8.4 | 26 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA17 CVEs
24%
24%
35%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (52.9%)
Network8 (47.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High3 (17.6%)
Unknown0 (0.0%)
User Interaction
None10 (58.8%)
Unknown0 (0.0%)
Required2 (11.8%)
Privileges Required
Low2 (11.8%)
High1 (5.9%)
None14 (82.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by The Qt Company as a CNA.
Media Mentions
Media articles that mention a CVE ID published by The Qt Company as a CNA — matched by CVE ID, not by organization name.