📦

qt

Vendor: qt

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 7 Remote Access
Total CVEs 128 Total Indexed
Avg. EPSS 1.79% Exploit Prob.
Latest CVE CVE-2025-5683 Jun 05

Security Vulnerability Index

Page 3 / 13
7.5 CVSS

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

EPSS: 0.45%
7.8 CVSS

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

EPSS: 0.09%
7.5 CVSS

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

EPSS: 0.83%
7.8 CVSS

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

EPSS: 0.84%
5.7 CVSS

Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

EPSS: 0.33%
7.3 CVSS

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

EPSS: 0.33%
5.3 CVSS

An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.

EPSS: 7.13%
7.5 CVSS

Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)

EPSS: 1.57%
9.8 CVSS

setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

EPSS: 0.47%
7.5 CVSS

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

EPSS: 0.47%