Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/canva/affinity

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2025-66342 is a high-severity type confusion vulnerability in the EMF processing functionality of Canva Affinity version 3.0.1.3808. An attacker can craft a malicious EMF file that, when opened or processed by the vulnerable software, triggers memory corruption leading to arbitrary code execution. Exploitation requires local access and user interaction, but no privileges are needed. The vulnerability impacts confidentiality, integrity, and availability due to potential full system compromise. No known exploits are currently in the wild, and no patches have been released yet. Organizations using Canva Affinity for graphic design should be cautious when handling EMF files from untrusted sources. Mitigation involves restricting EMF file handling, applying vendor patches once available, and employing endpoint protection with behavior monitoring.

Join the discussion

CVE-2025-62500 is an out-of-bounds read vulnerability in the EMF processing functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that, when opened, causes the application to read memory outside its intended bounds. This can lead to disclosure of sensitive information from the process memory. The vulnerability requires local access and user interaction to open the malicious file but does not require privileges or authentication. The CVSS score is 6.1, indicating a medium severity level. No known exploits are currently reported in the wild.

Join the discussion

CVE-2025-61979 is an out-of-bounds read vulnerability in the EMF (Enhanced Metafile) processing functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers an out-of-bounds read, potentially leaking sensitive information from memory. The vulnerability requires local access and user interaction to open the malicious file but does not require privileges or authentication. The CVSS score of 6.1 reflects a medium severity, primarily due to the confidentiality impact and limited attack vector. No known exploits are currently reported in the wild, and no patches have been published yet. Organizations using Canva Affinity for graphic design should be cautious when handling untrusted EMF files.

Join the discussion

CVE-2025-64733 is an out-of-bounds read vulnerability in the EMF processing functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers the vulnerability, potentially leading to disclosure of sensitive information. The vulnerability requires local access and user interaction to open the malicious file. It does not allow code execution or system integrity compromise but can leak confidential data. No known exploits are currently in the wild. The CVSS score is 6.1 (medium severity), reflecting the moderate impact and exploitation complexity.

Join the discussion

CVE-2025-66000 is an out-of-bounds read vulnerability in the EMF (Enhanced Metafile) processing functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers the vulnerability, potentially causing disclosure of sensitive information from memory. The vulnerability requires local access and user interaction to open the malicious file, but does not require privileges or authentication. The CVSS score is 6.1 (medium severity), reflecting high confidentiality impact with limited integrity and availability impact. No known exploits are currently reported in the wild. Organizations using Canva Affinity for graphic design should be aware of this risk and apply mitigations to prevent sensitive data leakage.

Join the discussion

CVE-2025-64301 is a high-severity out-of-bounds write vulnerability in the EMF functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers an out-of-bounds write, potentially leading to arbitrary code execution. The vulnerability requires local access and user interaction to open the malicious file but does not require privileges or authentication. This flaw impacts confidentiality, integrity, and availability, making it critical for affected users to apply mitigations promptly. No known exploits are currently in the wild, but the risk remains significant due to the potential for remote code execution. Organizations using Canva Affinity in creative and design workflows should prioritize patching once available and implement strict file handling policies. Countries with significant usage of Canva Affinity and high-value creative industries are at greater risk.

Join the discussion

CVE-2025-64776 is an out-of-bounds read vulnerability in the EMF functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers the vulnerability, potentially leading to disclosure of sensitive information. The vulnerability requires local access and user interaction to open the malicious file. It does not allow code execution or system integrity compromise but can leak confidential data. No known exploits are currently in the wild, and no patches have been released yet. The CVSS score is 6.1 (medium severity), reflecting the moderate risk due to required user interaction and local attack vector.

Join the discussion

CVE-2025-64735 is an out-of-bounds read vulnerability in the EMF (Enhanced Metafile) processing functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that, when opened or processed by the affected software, causes an out-of-bounds read. This can lead to the disclosure of sensitive information from the application's memory. The vulnerability requires local access (attack vector: local), no privileges, and user interaction to trigger. It does not allow code execution or integrity compromise but can leak confidential data. No known exploits are currently in the wild, and no patches have been published yet. The CVSS score is 6.

Join the discussion

CVE-2025-66617 is an out-of-bounds read vulnerability in the EMF functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers the vulnerability, potentially leading to the disclosure of sensitive information. The vulnerability requires local access and user interaction to open the malicious file. It does not allow code execution or system integrity compromise but can leak confidential data. No known exploits are currently reported in the wild. The CVSS score is 6.1 (medium severity), reflecting the moderate impact and exploitation complexity.

Join the discussion

CVE-2025-47873 is an out-of-bounds read vulnerability in the EMF processing functionality of Canva Affinity version 3.0.1.3808. An attacker can exploit this by crafting a malicious EMF file that triggers the vulnerability, potentially leading to unauthorized disclosure of sensitive information. The vulnerability requires local access and user interaction to open the malicious file but does not require privileges or authentication. The CVSS score is 6.1 (medium severity), reflecting high confidentiality impact but limited integrity and availability impact. No known exploits are currently reported in the wild. Organizations using Canva Affinity for graphic design should be aware of this vulnerability and apply patches once available or implement mitigations to reduce risk.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Package: pkg:github/canva/affinity
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses