Vendor
Kde vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 7 vulnerabilities in Kde: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-25710, was published on 13 May 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About Kde
KDE is an international free software community that develops open-source software for desktop and portable computing.
Kde technologies
- Kde3
Latest Kde vulnerabilities
- CVE-2026-25710: KDE plasma-login-manager privilege escalation in plasmaloginauthhelperinfoCVSS 7
- CVE-2026-45184: KDE Kdenlive remote code execution via malicious project filemediumCVSS 6.5EPSS 0.1%
- CVE-2026-41525: KDE Dolphin sandbox escape via FileManager1 protocolmediumCVSS 6.5EPSS 0.0%
- CVE-1999-1096: Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental…highCVSS 7.2
- CVE-1999-1106: KDE kppp buffer overflow in account_name argumenthighCVSS 7.2
- CVE-1999-1269: KDE Beta 3 arbitrary file overwrite via symlink in screen saverlowCVSS 2.1
- CVE-1999-1267: KDE kfm arbitrary file modification via insecure TCP servermediumCVSS 5
Most severe Kde vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-1999-1096: Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental…highCVSS 7.2
- CVE-1999-1106: KDE kppp buffer overflow in account_name argumenthighCVSS 7.2
- CVE-2026-45184: KDE Kdenlive remote code execution via malicious project filemediumCVSS 6.5EPSS 0.1%
- CVE-2026-41525: KDE Dolphin sandbox escape via FileManager1 protocolmediumCVSS 6.5EPSS 0.0%
- CVE-1999-1267: KDE kfm arbitrary file modification via insecure TCP servermediumCVSS 5
- CVE-1999-1269: KDE Beta 3 arbitrary file overwrite via symlink in screen saverlowCVSS 2.1
- CVE-2026-25710: KDE plasma-login-manager privilege escalation in plasmaloginauthhelperinfoCVSS 7
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/kde.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Kde vulnerabilities", https://junglewise.ai/threats/vendors/kde, 26 September 2026.