
OSV.dev · 实时热榜
- 01CLSA-2026-1786382292 · TuxCare security update for 38 packages (2 CVEs)
TuxCare security update for 38 packages (2 CVEs) Affected packages: TuxCare:Maven/org.apache.tomcat.embed:tomcat-embed-core、TuxCare:Maven/org.apache.tomcat.embed:tomcat-embed-el、TuxCare:Maven/org.apache.tomcat.embed:tomcat-embed-jasper、TuxCare:Maven/org.apache.tomcat.embed:tomcat-embed-websocket、TuxCare:Maven/org.apache.tomcat.experimental:tomcat-embed-programmatic、... 33 more Attributes: Fix available
最高第 1 名02:55 达到02:55 首次观测上榜04:15 观测离榜累计约1小时20分 - 02DEBIAN-CVE-2026-19349 · Debian:11/lemonldap-ng
Affected packages: Debian:11/lemonldap-ng、Debian:12/lemonldap-ng、Debian:13/lemonldap-ng、Debian:14/lemonldap-ng Attributes: No fix available
最高第 1 名16:15 达到16:15 首次观测上榜18:23 观测离榜累计约2小时8分 - 03DEBIAN-CVE-2026-61552 · Debian:11/icinga2
Affected packages: Debian:11/icinga2、Debian:12/icinga2、Debian:13/icinga2、Debian:14/icinga2 Attributes: Fix available
最高第 1 名00:00 达到当日首次采集时已在榜00:15 观测离榜累计约15分钟 - 04DEBIAN-CVE-2026-68112 · Debian:11/linux
Affected packages: Debian:11/linux、Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 1 名00:15 达到00:15 首次观测上榜02:07 观测离榜累计约1小时52分 - 05DEBIAN-CVE-2026-69184 · Debian:13/c-ares
Affected packages: Debian:13/c-ares、Debian:14/c-ares Attributes: Fix available
最高第 1 名01:03 达到01:03 首次观测上榜04:15 观测离榜累计约3小时12分 - 06DEBIAN-CVE-2026-73152 · Debian:11/svxlink
Affected packages: Debian:11/svxlink、Debian:12/svxlink、Debian:13/svxlink、Debian:14/svxlink Attributes: Fix available
最高第 1 名21:03 达到21:03 首次观测上榜22:23 观测离榜累计约1小时20分 - 07ECHO-0ea6-1c68-a084 · Echo/gst-plugins-bad1.0
Affected packages: Echo/gst-plugins-bad1.0 Attributes: No fix available
最高第 1 名05:35 达到05:35 首次观测上榜14:07 观测离榜累计约8小时32分 - 08ECHO-49ac-ba0f-ce98 · Echo/gst-plugins-good1.0
Affected packages: Echo/gst-plugins-good1.0 Attributes: No fix available
最高第 1 名07:43 达到07:43 首次观测上榜14:55 观测离榜累计约7小时12分 - 09JLSEC-2026-1242 · ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function...
ncurses v6.5 and v6.4 are vulnerable to Buffer Overflow in progs/infocmp.c, function... Affected packages: Julia/Ncurses_jll Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名04:31 达到04:31 首次观测上榜09:51 观测离榜累计约5小时20分 - 10JLSEC-2026-1243 · A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in...
A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in... Affected packages: Julia/Glib_jll Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名22:07 达到22:07 首次观测上榜23:59 观测离榜累计约1小时52分 - 11JLSEC-2026-1250 · Julia/LibModbus_jll
Affected packages: Julia/LibModbus_jll Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名22:23 达到22:23 首次观测上榜23:59 观测离榜累计约1小时36分 - 12MAL-2026-13712 · Malicious code in bigtime (PyPI)
Malicious code in bigtime (PyPI) Affected packages: PyPI/bigtime Attributes: No fix available
最高第 1 名06:07 达到06:07 首次观测上榜14:39 观测离榜累计约8小时32分 - 13MAL-2026-13728 · Malicious code in dlmm (PyPI)
Malicious code in dlmm (PyPI) Affected packages: PyPI/dlmm Attributes: No fix available
最高第 1 名14:07 达到14:07 首次观测上榜17:03 观测离榜累计约2小时56分 - 14MAL-2026-13729 · Malicious code in dlmm-sdk (PyPI)
Malicious code in dlmm-sdk (PyPI) Affected packages: PyPI/dlmm-sdk Attributes: No fix available
最高第 1 名15:11 达到15:11 首次观测上榜17:03 观测离榜累计约1小时52分 - 15MAL-2026-13733 · Malicious code in newtun (npm)
Malicious code in newtun (npm) Affected packages: npm/newtun Attributes: No fix available
最高第 1 名20:31 达到20:31 首次观测上榜21:35 观测离榜累计约1小时4分 - 16MAL-2026-13736 · Malicious code in @nzeros/codebreak (npm)
Malicious code in @nzeros/codebreak (npm) Affected packages: npm/@nzeros/codebreak Attributes: No fix available
最高第 1 名23:43 达到23:43 首次观测上榜当日结束时仍在榜累计约16分钟 - 17MGASA-2026-0328 · Updated openslide packages fix a security vulnerability
Updated openslide packages fix a security vulnerability Affected packages: Mageia:10/openslide Attributes: Fix available
最高第 1 名03:43 达到03:43 首次观测上榜09:03 观测离榜累计约5小时20分 - 18MINI-hfh4-fwgv-55jv · MinimOS/vllm-cu130
Affected packages: MinimOS/vllm-cu130 Attributes: Fix available
最高第 1 名15:59 达到15:59 首次观测上榜18:23 观测离榜累计约2小时24分 - 19MINI-q765-q5mr-3rph · MinimOS/jupyterhub
Affected packages: MinimOS/jupyterhub Attributes: Fix available
最高第 1 名09:51 达到09:51 首次观测上榜15:59 观测离榜累计约6小时8分 - 20RHSA-2026:53298 · Red Hat Security Advisory: nodejs22 security update
Red Hat Security Advisory: nodejs22 security update Affected packages: Red Hat:enterprise_linux_eus:10.0/nodejs、Red Hat:enterprise_linux_eus:10.0/nodejs-debuginfo、Red Hat:enterprise_linux_eus:10.0/nodejs-devel、Red Hat:enterprise_linux_eus:10.0/nodejs-docs、Red Hat:enterprise_linux_eus:10.0/nodejs-full-i18n、... 6 more Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:23 达到18:23 首次观测上榜21:03 观测离榜累计约2小时40分 - 21RLSA-2026:52674 · Moderate: libarchive security update
Moderate: libarchive security update Affected packages: Rocky Linux:9/libarchive Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名14:39 达到14:39 首次观测上榜17:03 观测离榜累计约2小时24分 - 22RUSTSEC-2026-0252 · Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read)
Panic-safety unsoundness in `SplitVec::extend_from_slice` (uninitialized read) Affected packages: crates.io/orx-split-vec Attributes: Fix available
最高第 1 名18:55 达到18:55 首次观测上榜21:03 观测离榜累计约2小时8分 - 23BELL-CVE-2026-68083 · Alpaquita:23/linux-lts
Affected packages: Alpaquita:23/linux-lts、Alpaquita:25/linux-lts、Alpaquita:stream/linux-lts Attributes: Fix available
最高第 2 名15:27 达到15:27 首次观测上榜17:03 观测离榜累计约1小时36分 - 24CLSA-2026-1786399295 · TuxCare security update for symfony/yaml (1 CVE)
TuxCare security update for symfony/yaml (1 CVE) Affected packages: TuxCare:Packagist/symfony/yaml Attributes: Fix available
最高第 2 名08:47 达到08:47 首次观测上榜14:39 观测离榜累计约5小时52分 - 25DEBIAN-CVE-2026-61551 · Debian:11/icinga2
Affected packages: Debian:11/icinga2、Debian:12/icinga2、Debian:13/icinga2、Debian:14/icinga2 Attributes: Fix available
最高第 2 名00:00 达到当日首次采集时已在榜00:15 观测离榜累计约15分钟 - 26DEBIAN-CVE-2026-6791 · Debian:11/glibc
Affected packages: Debian:11/glibc、Debian:12/glibc、Debian:13/glibc、Debian:14/glibc Attributes: No fix available
最高第 2 名01:03 达到01:03 首次观测上榜04:15 观测离榜累计约3小时12分 - 27DEBIAN-CVE-2026-68383 · Debian:13/linux
Affected packages: Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 2 名00:15 达到00:15 首次观测上榜02:07 观测离榜累计约1小时52分 - 28DEBIAN-CVE-2026-73151 · Debian:11/svxlink
Affected packages: Debian:11/svxlink、Debian:12/svxlink、Debian:13/svxlink、Debian:14/svxlink Attributes: Fix available
最高第 2 名21:03 达到21:03 首次观测上榜22:23 观测离榜累计约1小时20分 - 29ECHO-5c6a-872b-49bb · Echo/qtbase-opensource-src
Affected packages: Echo/qtbase-opensource-src Attributes: Fix available
最高第 2 名23:59 达到23:59 首次观测上榜当日结束时仍在榜累计约0分钟 - 30JLSEC-2026-1244 · A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the...
A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the... Affected packages: Julia/Glib_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名22:07 达到22:07 首次观测上榜23:43 观测离榜累计约1小时36分 - 31JLSEC-2026-1251 · Julia/LibModbus_jll
Affected packages: Julia/LibModbus_jll Attributes: Fix available、Severity - 9.8 (Critical)
最高第 2 名22:23 达到22:23 首次观测上榜23:59 观测离榜累计约1小时36分 - 32MAL-2026-13711 · Malicious code in plp-contract (PyPI)
Malicious code in plp-contract (PyPI) Affected packages: PyPI/plp-contract Attributes: No fix available
最高第 2 名04:47 达到04:47 首次观测上榜09:51 观测离榜累计约5小时4分 - 33MAL-2026-13732 · Malicious code in joule-btp-extension (PyPI)
Malicious code in joule-btp-extension (PyPI) Affected packages: PyPI/joule-btp-extension Attributes: No fix available
最高第 2 名20:15 达到20:15 首次观测上榜21:03 观测离榜累计约48分钟 - 34MAL-2026-13734 · Malicious code in @aerodrome-finance/contracts (npm)
Malicious code in @aerodrome-finance/contracts (npm) Affected packages: npm/@aerodrome-finance/contracts Attributes: No fix available
最高第 2 名23:43 达到23:43 首次观测上榜当日结束时仍在榜累计约16分钟 - 35MGASA-2026-0329 · Updated php8.4 packages fix security vulnerabilities
Updated php8.4 packages fix security vulnerabilities Affected packages: Mageia:10/php8.4 Attributes: Fix available
最高第 2 名03:43 达到03:43 首次观测上榜09:03 观测离榜累计约5小时20分 - 36MINI-4xgc-c5pf-hmfw · MinimOS/virt-exportserver-1.8
Affected packages: MinimOS/virt-exportserver-1.8 Attributes: Fix available
最高第 2 名15:59 达到15:59 首次观测上榜18:23 观测离榜累计约2小时24分 - 37MINI-9c36-jq5h-fq7v · MinimOS/python-3.10
Affected packages: MinimOS/python-3.10、MinimOS/python-3.10-base、MinimOS/python-3.10-base-dev、MinimOS/python-3.10-dev、MinimOS/python-3.10-doc Attributes: Fix available
最高第 2 名19:59 达到19:59 首次观测上榜21:03 观测离榜累计约1小时4分 - 38MINI-cjf5-whw9-c7p6 · MinimOS/grype
Affected packages: MinimOS/grype Attributes: Fix available
最高第 2 名09:51 达到09:51 首次观测上榜15:27 观测离榜累计约5小时36分 - 39MINI-mhm7-2xm2-wqh7 · MinimOS/python-3.12
Affected packages: MinimOS/python-3.12、MinimOS/python-3.12-base、MinimOS/python-3.12-base-dev、MinimOS/python-3.12-dev、MinimOS/python-3.12-doc、... 1 more Attributes: Fix available
最高第 2 名19:43 达到19:43 首次观测上榜21:03 观测离榜累计约1小时20分 - 40RHSA-2026:53364 · Red Hat Security Advisory: resource-agents security update
Red Hat Security Advisory: resource-agents security update Affected packages: Red Hat:enterprise_linux:8::highavailability/resource-agents、Red Hat:enterprise_linux:8::highavailability/resource-agents-aliyun、Red Hat:enterprise_linux:8::highavailability/resource-agents-aliyun-debuginfo、Red Hat:enterprise_linux:8::highavailability/resource-agents-debuginfo、Red Hat:enterprise_linux:8::highavailability/resource-agents-debugsource、... 9 more Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名18:23 达到18:23 首次观测上榜21:03 观测离榜累计约2小时40分 - 41RLSA-2026:38509 · Important: vim security update
Important: vim security update Affected packages: Rocky Linux:10/vim Attributes: Fix available、Severity - 7.3 (High)
最高第 2 名20:31 达到20:31 首次观测上榜21:35 观测离榜累计约1小时4分 - 42RLSA-2026:52761 · Moderate: kernel-rt security update
Moderate: kernel-rt security update Affected packages: Rocky Linux:8/kernel-rt Attributes: Fix available、Severity - 5.5 (Medium)
最高第 2 名14:39 达到14:39 首次观测上榜17:03 观测离榜累计约2小时24分 - 43ROOT-APP-PYPI-CVE-2024-52304 · CVE-2024-52304 in aiohttp - Patched by Root
CVE-2024-52304 in aiohttp - Patched by Root Affected packages: Root:PyPI/aiohttp、Root:PyPI/rootio-aiohttp Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名17:03 达到17:03 首次观测上榜18:23 观测离榜累计约1小时20分 - 44ROOT-OS-UBUNTU-2204-CVE-2025-27613 · CVE-2025-27613 in git - Patched by Root
CVE-2025-27613 in git - Patched by Root Affected packages: Root:Ubuntu:22.04/git、Root:Ubuntu:22.04/rootio-git Attributes: Fix available
最高第 2 名06:23 达到06:23 首次观测上榜14:39 观测离榜累计约8小时16分 - 45DEBIAN-CVE-2026-61550 · Debian:11/icinga2
Affected packages: Debian:11/icinga2、Debian:12/icinga2、Debian:13/icinga2、Debian:14/icinga2 Attributes: Fix available
最高第 3 名00:00 达到当日首次采集时已在榜00:15 观测离榜累计约15分钟 - 46DEBIAN-CVE-2026-68176 · Debian:11/linux
Affected packages: Debian:11/linux、Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 3 名00:15 达到00:15 首次观测上榜02:07 观测离榜累计约1小时52分 - 47DEBIAN-CVE-2026-69186 · Debian:13/c-ares
Affected packages: Debian:13/c-ares、Debian:14/c-ares Attributes: Fix available
最高第 3 名01:03 达到01:03 首次观测上榜04:15 观测离榜累计约3小时12分 - 48DEBIAN-CVE-2026-73148 · Debian:11/svxlink
Affected packages: Debian:11/svxlink、Debian:12/svxlink、Debian:13/svxlink、Debian:14/svxlink Attributes: Fix available
最高第 3 名21:03 达到21:03 首次观测上榜22:23 观测离榜累计约1小时20分 - 49ECHO-ac3c-11a6-be31 · Echo/qtbase-opensource-src
Affected packages: Echo/qtbase-opensource-src Attributes: Fix available
最高第 3 名23:59 达到23:59 首次观测上榜当日结束时仍在榜累计约0分钟 - 50JLSEC-2026-1245 · A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used...
A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used... Affected packages: Julia/Glib_jll Attributes: Fix available、Severity - 8.2 (High)
最高第 3 名22:07 达到22:07 首次观测上榜23:43 观测离榜累计约1小时36分


































































































