全部/科技/实时热榜

OSV.dev · 实时热榜

HISTORY2026年8月6日320 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS320 个热搜
  1. 01
    EEF-CVE-2026-66885 · Livebook Teams identity callback lacks state binding, allowing login CSRF

    Livebook Teams identity callback lacks state binding, allowing login CSRF Affected packages: Hex/livebook、github.com/livebook-dev/livebook Attributes: Fix available、Severity - 6.8 (Medium)

    最高第 103:57 达到03:57 首次观测上榜05:17 观测离榜累计约1小时20分
  2. 02
    EEF-CVE-2026-68750 · Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service

    Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service Affected packages: Hex/html_sanitize_ex、github.com/rrrene/html_sanitize_ex Attributes: Fix available、Severity - 8.2 (High)

    最高第 123:15 达到23:15 首次观测上榜当日结束时仍在榜累计约32分钟
  3. 03
    GHSA-279x-mwfv-vcqv · Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

    Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Affected packages: npm/@nuxt/devtools Attributes: Fix available、Severity - 9.6 (Critical)

    最高第 105:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分
  4. 04
    GHSA-42cj-m3vj-89wv · Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

    Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 5.3 (Medium)

    最高第 106:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分
  5. 05
    GHSA-7p4m-qxvv-g567 · rclone: Local Encoding Path Traversal

    rclone: Local Encoding Path Traversal Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 105:01 达到05:01 首次观测上榜06:21 观测离榜累计约1小时20分
  6. 06
    GHSA-945v-v9p3-v5xw · rclone local ` --metadata ` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote

    rclone local ` --metadata ` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 3.6 (Low)

    最高第 104:29 达到04:29 首次观测上榜05:17 观测离榜累计约48分钟
  7. 07
    GHSA-9f4c-93c8-jc8g · Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

    Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path Affected packages: npm/electron Attributes: Fix available、Severity - 7.2 (High)

    最高第 101:33 达到01:33 首次观测上榜03:25 观测离榜累计约1小时52分
  8. 08
    GHSA-ff2p-hmqr-hxm4 · Electron: contextBridge object copy honors prototype setters

    Electron: contextBridge object copy honors prototype setters Affected packages: npm/electron Attributes: Fix available、Severity - 5.4 (Medium)

    最高第 101:49 达到01:49 首次观测上榜03:25 观测离榜累计约1小时36分
  9. 09
    GHSA-fqj9-69pf-6pjg · rclone ` serve restic --private-repos ` authorization bypass: ` .. ` in the URL path lets an authenticated user read, overwrite and delete other users' repositories

    rclone ` serve restic --private-repos ` authorization bypass: ` .. ` in the URL path lets an authenticated user read, overwrite and delete other users' repositories Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 8.8 (High)

    最高第 104:45 达到04:45 首次观测上榜06:21 观测离榜累计约1小时36分
  10. 10
    GHSA-m55f-7gqj-fr98 · Electron: Extension tab APIs operate across session boundaries

    Electron: Extension tab APIs operate across session boundaries Affected packages: npm/electron Attributes: Fix available、Severity - 6.6 (Medium)

    最高第 100:13 达到00:13 首次观测上榜02:05 观测离榜累计约1小时52分
  11. 11
    GHSA-p2rr-rvmm-c5fp · Electron: Sandboxed iframes can launch external protocol handlers

    Electron: Sandboxed iframes can launch external protocol handlers Affected packages: npm/electron Attributes: Fix available、Severity - 5.4 (Medium)

    最高第 102:05 达到02:05 首次观测上榜03:57 观测离榜累计约1小时52分
  12. 12
    GHSA-r4w5-6pfg-jxp5 · Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

    Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)

    最高第 100:29 达到00:29 首次观测上榜02:21 观测离榜累计约1小时52分
  13. 13
    GHSA-v93f-fgjr-hjrj · Electron: window.open features string controls some window options considered privileged

    Electron: window.open features string controls some window options considered privileged Affected packages: npm/electron Attributes: Fix available、Severity - 5.3 (Medium)

    最高第 100:45 达到00:45 首次观测上榜02:37 观测离榜累计约1小时52分
  14. 14
    GHSA-x8rc-wpg4-grpf · Electron: Cross-origin iframe can position native autofill popup

    Electron: Cross-origin iframe can position native autofill popup Affected packages: npm/electron Attributes: Fix available、Severity - 3.1 (Low)

    最高第 100:00 达到当日首次采集时已在榜00:45 观测离榜累计约46分钟
  15. 15
    JLSEC-2026-1164 · Deno: ` fetch() ` API sandbox bypass via missing DNS resolution check

    Deno: ` fetch() ` API sandbox bypass via missing DNS resolution check Affected packages: Julia/Deno_jll Attributes: Fix available、Severity - 5.2 (Medium)

    最高第 102:37 达到02:37 首次观测上榜04:45 观测离榜累计约2小时8分
  16. 16
    JLSEC-2026-1168 · GMP has an integer overflow with crafted inputs on 32-bit builds in ` int_raw.c ` , leading to buffer overflow

    GMP has an integer overflow with crafted inputs on 32-bit builds in ` int_raw.c ` , leading to buffer overflow Affected packages: Julia/GCCBootstrap_jll、Julia/GMP_jll、Julia/LibStdCxx_jll Attributes: Fix available、Severity - 7.5 (High)

    最高第 105:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分
  17. 17
    MAL-2026-13370 · Malicious code in llm-interceptor (npm)

    Malicious code in llm-interceptor (npm) Affected packages: npm/llm-interceptor Attributes: No fix available

    最高第 103:25 达到03:25 首次观测上榜04:45 观测离榜累计约1小时20分
  18. 18
    MAL-2026-13380 · Malicious code in uncrypt (PyPI)

    Malicious code in uncrypt (PyPI) Affected packages: PyPI/uncrypt Attributes: No fix available

    最高第 106:53 达到06:53 首次观测上榜08:45 观测离榜累计约1小时52分
  19. 19
    MAL-2026-13386 · Malicious code in decapod-common (PyPI)

    Malicious code in decapod-common (PyPI) Affected packages: PyPI/decapod-common Attributes: No fix available

    最高第 115:41 达到15:41 首次观测上榜16:45 观测离榜累计约1小时4分
  20. 20
    MAL-2026-13393 · Malicious code in wallet-monitor-snap (npm)

    Malicious code in wallet-monitor-snap (npm) Affected packages: npm/wallet-monitor-snap Attributes: No fix available

    最高第 120:35 达到20:35 首次观测上榜21:55 观测离榜累计约1小时20分
  21. 21
    MAL-2026-13400 · Malicious code in agenttunnels (npm)

    Malicious code in agenttunnels (npm) Affected packages: npm/agenttunnels Attributes: No fix available

    最高第 121:39 达到21:39 首次观测上榜22:27 观测离榜累计约48分钟
  22. 22
    MAL-2026-13419 · Malicious code in @holocronlab/botruntime-runtime (npm)

    Malicious code in @holocronlab/botruntime-runtime (npm) Affected packages: npm/@holocronlab/botruntime-runtime Attributes: No fix available

    最高第 122:43 达到22:43 首次观测上榜23:47 观测离榜累计约1小时4分
  23. 23
    MINI-292j-93mg-c5vm · MinimOS/opensearch-3

    Affected packages: MinimOS/opensearch-3、MinimOS/opensearch-3-alerting、MinimOS/opensearch-3-anomaly-detection、MinimOS/opensearch-3-crypto-kms、MinimOS/opensearch-3-discovery-ec2、... 11 more Attributes: Fix available

    最高第 110:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分
  24. 24
    MINI-2rmr-9cpg-6243 · MinimOS/portainer-ce-2.39

    Affected packages: MinimOS/portainer-ce-2.39 Attributes: Fix available

    最高第 122:27 达到22:27 首次观测上榜22:43 观测离榜累计约16分钟
  25. 25
    MINI-5xfc-qf8m-mg3g · MinimOS/gnutar

    Affected packages: MinimOS/gnutar、MinimOS/gnutar-doc、MinimOS/gnutar-rmt、MinimOS/tar Attributes: Fix available

    最高第 120:51 达到20:51 首次观测上榜21:55 观测离榜累计约1小时4分
  26. 26
    MINI-f632-6jhm-593p · MinimOS/py3.10-pip-base

    Affected packages: MinimOS/py3.10-pip-base、MinimOS/py3.11-pip-base、MinimOS/py3.12-pip-base、MinimOS/py3.13-pip-base、MinimOS/py3.14-pip-base Attributes: Fix available

    最高第 121:07 达到21:07 首次观测上榜22:27 观测离榜累计约1小时20分
  27. 27
    MINI-m7hm-39h3-6jgv · MinimOS/teleport-18

    Affected packages: MinimOS/teleport-18 Attributes: Fix available

    最高第 116:45 达到16:45 首次观测上榜17:33 观测离榜累计约48分钟
  28. 28
    RLSA-2026:50142 · Important: sg3_utils security, bug fix, and enhancement update

    Important: sg3_utils security, bug fix, and enhancement update Affected packages: Rocky Linux:10/sg3_utils Attributes: Fix available、Severity - 7.6 (High)

    最高第 108:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分
  29. 29
    ROOT-OS-ALPINE-318-CVE-2026-40200 · CVE-2026-40200 in musl - Patched by Root

    CVE-2026-40200 in musl - Patched by Root Affected packages: Root:Alpine:3.18/musl、Root:Alpine:3.18/rootio-musl Attributes: Fix available、Severity - 7.8 (High)

    最高第 115:25 达到15:25 首次观测上榜16:45 观测离榜累计约1小时20分
  30. 30
    ROOT-OS-DEBIAN-12-CVE-2004-0230 · CVE-2004-0230 in linux - Patched by Root

    CVE-2004-0230 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available

    最高第 113:17 达到13:17 首次观测上榜16:45 观测离榜累计约3小时28分
  31. 31
    RUSTSEC-2026-0236 · A ` BigInt ` division panics, and two neighbouring operations answer wrongly in silence

    A ` BigInt ` division panics, and two neighbouring operations answer wrongly in silence Affected packages: crates.io/viperjs Attributes: Fix available、Severity - 7.5 (High)

    最高第 117:17 达到17:17 首次观测上榜21:39 观测离榜累计约4小时22分
  32. 32
    DEBIAN-CVE-2026-64589 · Debian:13/linux

    Affected packages: Debian:13/linux、Debian:14/linux Attributes: Fix available

    最高第 218:05 达到18:05 首次观测上榜18:59 观测离榜累计约54分钟
  33. 33
    EEF-CVE-2026-66298 · JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts

    JS-view sandboxed output can synthesize keyboard events to trigger unconfirmed global shortcuts Affected packages: Hex/livebook、github.com/livebook-dev/livebook Attributes: Fix available、Severity - 8.6 (High)

    最高第 203:57 达到03:57 首次观测上榜05:01 观测离榜累计约1小时4分
  34. 34
    EEF-CVE-2026-68749 · Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service

    Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service Affected packages: Hex/html_sanitize_ex、github.com/rrrene/html_sanitize_ex Attributes: Fix available、Severity - 8.2 (High)

    最高第 223:15 达到23:15 首次观测上榜当日结束时仍在榜累计约32分钟
  35. 35
    GHSA-2m8m-jhrm-w6j2 · rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution

    rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 8.0 (High)

    最高第 204:45 达到04:45 首次观测上榜06:21 观测离榜累计约1小时36分
  36. 36
    GHSA-48hr-524c-v5w3 · Nuxt: Unauthorized Component Instantiation via Server Island Props

    Nuxt: Unauthorized Component Instantiation via Server Island Props Affected packages: npm/nuxt Attributes: Fix available、Severity - 4.8 (Medium)

    最高第 205:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分
  37. 37
    GHSA-4f78-qhmw-8j8m · Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter

    Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Affected packages: npm/electron Attributes: Fix available、Severity - 5.7 (Medium)

    最高第 201:49 达到01:49 首次观测上榜03:25 观测离榜累计约1小时36分
  38. 38
    GHSA-4vr5-p2gc-h23p · rclone archive extract allows S3 destination prefix escape via crafted archive paths

    rclone archive extract allows S3 destination prefix escape via crafted archive paths Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 5.0 (Medium)

    最高第 205:01 达到05:01 首次观测上榜06:21 观测离榜累计约1小时20分
  39. 39
    GHSA-5c9j-mhmv-5xgx · Electron: shell.openPath path validation bypass via embedded null byte

    Electron: shell.openPath path validation bypass via embedded null byte Affected packages: npm/electron Attributes: Fix available、Severity - 6.0 (Medium)

    最高第 200:13 达到00:13 首次观测上榜01:49 观测离榜累计约1小时36分
  40. 40
    GHSA-9pf5-hg6p-4pwp · Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin

    Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)

    最高第 200:00 达到当日首次采集时已在榜00:45 观测离榜累计约46分钟
  41. 41
    GHSA-f2r8-jv7c-xqmp · Electron: DevTools embedder handler executes arbitrary files via shell open

    Electron: DevTools embedder handler executes arbitrary files via shell open Affected packages: npm/electron Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 202:05 达到02:05 首次观测上榜03:41 观测离榜累计约1小时36分
  42. 42
    GHSA-gwfq-86j8-7qhv · rclone: Verbose Stack Trace Disclosure in RC API Error Responses

    rclone: Verbose Stack Trace Disclosure in RC API Error Responses Affected packages: Go/github.com/rclone/rclone Attributes: Fix available、Severity - 2.7 (Low)

    最高第 204:29 达到04:29 首次观测上榜05:17 观测离榜累计约48分钟
  43. 43
    GHSA-qq9q-x9w4-chhj · Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

    Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Affected packages: Go/Traefik Attributes: Fix available、Severity - 5.3 (Medium)

    最高第 206:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分
  44. 44
    GHSA-v64r-4m7r-3mvq · Electron: HTTP redirect followed into local file loader

    Electron: HTTP redirect followed into local file loader Affected packages: npm/electron Attributes: Fix available、Severity - 5.9 (Medium)

    最高第 200:29 达到00:29 首次观测上榜02:21 观测离榜累计约1小时52分
  45. 45
    JLSEC-2026-1165 · Deno: WebSocket API sandbox bypass via missing post-DNS check

    Deno: WebSocket API sandbox bypass via missing post-DNS check Affected packages: Julia/Deno_jll Attributes: Fix available、Severity - 5.2 (Medium)

    最高第 202:37 达到02:37 首次观测上榜04:45 观测离榜累计约2小时8分
  46. 46
    JLSEC-2026-1169 · 7-Zip for Windows fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive

    7-Zip for Windows fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive Affected packages: Julia/p7zip_jll Attributes: No fix available、Severity - 4.8 (Medium)

    最高第 205:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分
  47. 47
    MAL-2026-13369 · Malicious code in kepler (npm)

    Malicious code in kepler (npm) Affected packages: npm/kepler Attributes: No fix available

    最高第 203:25 达到03:25 首次观测上榜04:45 观测离榜累计约1小时20分
  48. 48
    MAL-2026-13392 · Malicious code in golaaa (npm)

    Malicious code in golaaa (npm) Affected packages: npm/golaaa Attributes: No fix available

    最高第 220:35 达到20:35 首次观测上榜21:55 观测离榜累计约1小时20分
  49. 49
    MAL-2026-13394 · Malicious code in @activepieces/piece-google-bigquery (npm)

    Malicious code in @activepieces/piece-google-bigquery (npm) Affected packages: npm/@activepieces/piece-google-bigquery Attributes: No fix available

    最高第 221:39 达到21:39 首次观测上榜22:27 观测离榜累计约48分钟
  50. 50
    MAL-2026-13420 · Malicious code in @innocarpe/deepseek-build (npm)

    Malicious code in @innocarpe/deepseek-build (npm) Affected packages: npm/@innocarpe/deepseek-build Attributes: No fix available

    最高第 222:43 达到22:43 首次观测上榜23:47 观测离榜累计约1小时4分