Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.2 CVE-2026-46977

CVE-2026-46977_CVE-2026-46977

{“lastseen”:””,”description”:””,”published”:”2026-06-16T19:28:07.889Z”,&#82...

Oracle Corporation Oracle VM VirtualBox 7.2.8 CVE
LOW 3.2 CVE-2026-46874

CVE-2026-46874_CVE-2026-46874

{“lastseen”:””,”description”:””,”published”:”2026-06-16T19:27:39.346Z”,&#82...

Oracle Corporation Oracle VM VirtualBox 7.2.8 CVE
LOW 3.2 CVE-2026-46816

CVE-2026-46816_CVE-2026-46816

{“lastseen”:””,”description”:””,”published”:”2026-06-16T19:27:28.757Z”,&#82...

Oracle Corporation Oracle VM VirtualBox 7.2.8 CVE
LOW 3.2 CVE-2026-46815

CVE-2026-46815_CVE-2026-46815

{“lastseen”:””,”description”:””,”published”:”2026-06-16T19:27:28.450Z”,&#82...

Oracle Corporation Oracle VM VirtualBox 7.2.8 CVE
LOW 2.3 CVE-2026-53862

OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening_CVE-2026-53862

OpenClaw before 2026.5.12 contains a bootstrap token replay vulnerability allowing callers with pending token access to reuse tokens with broader r...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53860

OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles_CVE-2026-53860

OpenClaw before 2026.5.7 contains a sender policy bypass vulnerability in BlueBubbles that allows participants to match allowlist entries through c...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53852

OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing_CVE-2026-53852

OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticated operators to restore bro...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53848

OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers_CVE-2026-53848

OpenClaw before 2026.5.26 contains an exec allowlist bypass vulnerability allowing authenticated operators to execute wrapper-level side effects ou...

OpenClaw OpenClaw CVE
LOW 2.3 CVE-2026-53845

OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook Skipping_CVE-2026-53845

OpenClaw before 2026.5.6 contains a hook bypass vulnerability where skill commands routed through the affected dispatch path skip before-tool-call ...

OpenClaw OpenClaw CVE
LOW 2.1 CVE-2026-53841

OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML_CVE-2026-53841

OpenClaw before 2026.5.12 contains a cross-site scripting vulnerability in exported session HTML that preserves unsafe javascript: and data: links ...

OpenClaw OpenClaw CVE