Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-53867

Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement_CVE-2026-53867

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can acce...

Cap-go capgo CVE
MEDIUM 6 CVE-2026-53839

OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation_CVE-2026-53839

OpenClaw before 2026.5.7 contains a hostname validation vulnerability in retry endpoint checks that allows matching hostname prefixes instead of ex...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53838

OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection_CVE-2026-53838

OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes to confuse approval scope d...

OpenClaw OpenClaw CVE
MEDIUM 6.3 CVE-2026-53837

OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers_CVE-2026-53837

OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to validate channel type metadat...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53830

OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload_CVE-2026-53830

OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and Zalo webhook secrets to rem...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53827

OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action Forwarding_CVE-2026-53827

OpenClaw before 2026.5.2 contains a credential exposure vulnerability in message.action forwarding that allows model-controlled metadata to forward...

OpenClaw OpenClaw CVE
MEDIUM 6 CVE-2026-53824

Mattermost < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay_CVE-2026-53824

OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to continue executing commands durin...

OpenClaw OpenClaw CVE
MEDIUM 6.9 CVE-2026-53820

OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn_CVE-2026-53820

OpenClaw before 2026.5.12 contains an exec denylist bypass vulnerability in the bundle MCP loopback session-spawn path that allows authenticated ca...

OpenClaw OpenClaw CVE
MEDIUM 5.5 CVE-2025-7019

Avast antivirus stack overflow when scanning a malformed Office Open XML file_CVE-2025-7019

Stack overflow vulnerability in Avast Antivirus when scanning a malformed Office Open XML file may allow Denial-of-Service of the antivirus process...

Gen Digital Avast Antivirus CVE
MEDIUM 5.5 CVE-2025-7018

Avira antivirus engine null pointer dereference when scanning a malformed PE file_CVE-2025-7018

Null pointer dereference vulnerability in Avira Antivirus engine when scanning a malformed Windows PE file may allow Denial-of-Service of the antiv...

Gen Digital Avira Antivirus CVE