Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-48029: CWE-125: Out-of-bounds Read in strukturag libheifCVE-2026-48029 0 libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue. Join the discussion | CVE Database V5 | 07/22/2026, 14:13:27 UTC Added: 07/22/2026, 14:52:46 UTC |
CVE-2026-47709: CWE-476: NULL Pointer Dereference in strukturag libheifCVE-2026-47709 0 libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API `heif_image_handle_get_image_tiling()` when a malformed uncompressed HEIF image item has an associated `uncC` property but no associated `ispe` property. In debug builds this trips the `ispe && uncC` assertion in `ImageItem_uncompressed::get_heif_image_tiling()`. In a release/NDEBUG ASan build, the same file causes a null pointer read at address `0xa8`. Version 1.22.0 fixes the issue. Join the discussion | CVE Database V5 | 07/21/2026, 21:31:14 UTC Added: 07/21/2026, 21:38:26 UTC |
CVE-2026-47254: CWE-125: Out-of-bounds Read in strukturag libheifCVE-2026-47254 0 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, `Track::init_sample_timing_table()` in `libheif/sequences/track.cc` stores an out-of-bounds chunk index (`m_chunks.size()`) into `m_presentation_timeline` when the number of chunks defined in the `stco` box is less than the number of samples in `stsz`. A subsequent call to `heif_track_get_next_raw_sequence_sample()` reads `m_chunks[chunk_idx]` with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue. Join the discussion | CVE Database V5 | 07/21/2026, 21:21:41 UTC Added: 07/21/2026, 21:38:26 UTC |
CVE-2026-47251: CWE-125: Out-of-bounds Read in strukturag libheifCVE-2026-47251 0 libheif is a HEIF and AVIF file format decoder and encoder. The fix for CVE-2026-3949 (commit `b97c8b5`, PR #1712) introduced an integer overflow in the very security check it added. The check itself can be bypassed, allowing a crafted HEIF file with a VVC track to trigger the same out-of-bounds heap read that CVE-2026-3949 was meant to prevent. This is a separate, currently-unpatched vulnerability. Issue #1712 was closed as fixed without testing the edge case where `size` is near `UINT32_MAX`. Version 1.22.0 patches the issue. Join the discussion | CVE Database V5 | 07/21/2026, 21:18:56 UTC Added: 07/21/2026, 21:38:24 UTC |
CVE-2026-47247: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in strukturag libheifCVE-2026-47247 0 libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue. Join the discussion | CVE Database V5 | 07/21/2026, 21:16:59 UTC Added: 07/21/2026, 21:38:24 UTC |
CVE-2026-47178: CWE-787: Out-of-bounds Write in strukturag libheifCVE-2026-47178 0 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed `unci` codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent `unc_decoder_component_interleave` object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue. Join the discussion | CVE Database V5 | 07/21/2026, 21:09:10 UTC Added: 07/21/2026, 21:38:24 UTC |
CVE-2026-47714: CWE-190: Integer Overflow or Wraparound in strukturag libheifCVE-2026-47714 0 libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can exceed `UINT32_MAX`, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to out-of-bounds memory access when the mask data is later interpreted as a `width x height` bitmap. Version 1.22.0 patches the issue. Join the discussion | CVE Database V5 | 07/21/2026, 21:04:06 UTC Added: 07/21/2026, 21:07:51 UTC |
Showing 1 to 7 of 7 results