Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.7 CVE-2026-53811

OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFrom_CVE-2026-53811

OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authenticated accounts to match ...

OpenClaw OpenClaw CVE
HIGH 7.7 CVE-2026-53810

OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension Metadata_CVE-2026-53810

OpenClaw before 2026.5.18 contains a code execution vulnerability where marketplace runtime extension metadata can redirect loading toward unscanne...

OpenClaw OpenClaw CVE
HIGH 7.7 CVE-2026-53807

OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom_CVE-2026-53807

OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in Telegram interactive callbacks that allows authenticated users to skip c...

OpenClaw OpenClaw CVE
HIGH 7.7 CVE-2026-53806

OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation_CVE-2026-53806

OpenClaw before 2026.5.12 contains a shell option parsing vulnerability that allows combined POSIX shell flags to bypass exec revalidation checks. ...

OpenClaw OpenClaw CVE
HIGH 7.7 CVE-2026-50245

Brickcom Cameras Missing Authentication for Critical Function_CVE-2026-50245

Brickcom cameras allow unauthenticated access to live snapshot images via the /ONVIF endpoint and no authentication is required to retrieve still i...

Brickcom Cube 3.2.3.5.6 CVE
HIGH 7.7 CVE-2026-50005

Brickcom Cameras Use of Default Credentials_CVE-2026-50005

Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.

Brickcom Cube 3.2.3.5.6 CVE
HIGH 8.5 CVE-2026-48546

KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs_CVE-2026-48546

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing...

lingdojo kana-dojo CVE
HIGH 7.5 CVE-2026-46697

Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endpoint_CVE-2026-46697

Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/m...

stefanbohacek fediverse-embeds-wordpress-plugin < 1.5.8 CVE
HIGH 8.7 CVE-2026-3329

Nexus Repository Manager – Improper Restriction of Excessive Authentication Attempts_CVE-2026-3329

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authent...

Sonatype Nexus Repository Manager 3.0.0 CVE
HIGH 7.5 CVE-2026-52860

Vim: Arbitrary Code Execution via Python Omni-Completion_CVE-2026-52860

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class ...

vim vim < 9.2.0597 CVE