Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-42216Critical· 9.1PoCOpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDM…
CVE-2026-41142High· 8.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, the…
CVE-2026-34589Medium· 5.0OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
CVE-2025-64182High· 7.8OpenEXR has buffer overflow in PyOpenEXR_old's channels() and channel()
CVE-2026-26981Medium· 6.5OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
CVE-2025-64183High· 7.5OpenEXR has use after free in PyObject_StealAttrString
CVE-2025-64181High· 7.5OpenEXR Makes Use of Uninitialized Memory
CVE-2026-34543HighOpenEXR: Heap information disclosure in PXR24 decompression via unchecked decompressed size (undo_pxr24_impl)
CVE-2026-34544HighOpenEXR: integer overflow to OOB write in uncompress_b44_impl()
CVE-2025-48074MediumOpenEXR Out-Of-Memory via Unbounded File Header Values
CVE-2025-48073MediumOpenEXR ScanLineProcess::run_fill NULL Pointer Write In "reduceMemory" Mode
CVE-2025-48071High· 7.8OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size
CVE-2025-48072MediumOpenEXR Out of Bounds Heap Read due to Bad Pointer Arithmetic in LossyDctDecoder_execute
CVE-2017-9111High· 8.8OpenEXR invalid write
CVE-2017-9112Medium· 6.5OpenEXR invalid read
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.