CVE-2026-103220Medium· 4.5▾ SunlitThe Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untruste…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing raster image data in Affinity document files, leading to an out-of-bounds read and the dereference of an untrusted pointer. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in memory corruption or an application crash.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-2008High· 8.2A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler
CVE-2026-107737NoneSumatraPDF is a multi-format reader for Windows
CVE-2026-107325Medium· 5.9Improper validation of a BSON array length in the MongoDB Go Driver can cause an out-of-bounds index and runtime panic when an application calls bson.RawArray.Validate or bsoncore.Array.Validate on a malformed four-byte array
CVE-2026-107222Medium· 6.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
CVE-2026-107225Medium· 6.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets
CVE-2026-107218Medium· 5.3Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets