Meltytech's vulnerability footprint centers on Shotcut, an open-source video editing application, with observed weaknesses clustering around buffer-overflow conditions in input handling and improper certificate validation in network operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meltytech over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65834CRITICAL Meltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulated width and height parameters. By set | Dec 16, 2025 | 9.8 | 32 | NO | NO |
CVE-2020-24619MEDIUM In mainwindow.cpp in Shotcut before 20.09.13, the upgrade check misuses TLS because of setPeerVerifyMode(QSslSocket::VerifyNone). A man-in-the-middle attacker could offer a spoofed | Sep 22, 2020 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meltytech.
Media articles that mention a CVE ID that affects a product developed by Meltytech — matched by CVE ID, not by vendor name.