
OSV.dev · 实时热榜
- 01CVE-2025-15687 · Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service
Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service Affected packages: github.com/open5gs/open5gs Attributes: No fix available、Severity - 2.1 (Low)
最高第 1 名12:14 达到12:14 首次观测上榜15:27 观测离榜累计约3小时12分 - 02DEBIAN-CVE-2026-19566 · Debian:11/libnet-cidr-set-perl
Affected packages: Debian:11/libnet-cidr-set-perl、Debian:12/libnet-cidr-set-perl、Debian:13/libnet-cidr-set-perl、Debian:14/libnet-cidr-set-perl Attributes: No fix available
最高第 1 名19:10 达到19:10 首次观测上榜20:30 观测离榜累计约1小时20分 - 03DEBIAN-CVE-2026-52062 · Debian:14/mongoose
Affected packages: Debian:14/mongoose Attributes: Fix available
最高第 1 名21:02 达到21:02 首次观测上榜21:50 观测离榜累计约48分钟 - 04DEBIAN-CVE-2026-71194 · Debian:11/designate
Affected packages: Debian:11/designate、Debian:12/designate、Debian:13/designate、Debian:14/designate Attributes: No fix available
最高第 1 名01:02 达到01:02 首次观测上榜03:11 观测离榜累计约2小时8分 - 05DEBIAN-CVE-2026-73212 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: Fix available
最高第 1 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 06ECHO-cb83-2ee2-b675 · Echo/xdg-dbus-proxy
Affected packages: Echo/xdg-dbus-proxy Attributes: No fix available
最高第 1 名09:50 达到09:50 首次观测上榜10:06 观测离榜累计约16分钟 - 07ECHO-daef-217d-eb9d · Echo:PyPi/python-ldap
Affected packages: Echo:PyPi/python-ldap Attributes: Fix available
最高第 1 名08:46 达到08:46 首次观测上榜10:06 观测离榜累计约1小时20分 - 08GHSA-87fv-vqqr-m4jr · SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Affected packages: Go/github.com/seaweedfs/seaweedfs Attributes: Fix available、Severity - 9.3 (Critical)
最高第 1 名00:15 达到00:15 首次观测上榜03:11 观测离榜累计约2小时56分 - 09GHSA-9mr8-pwpw-3j2w · Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62909 – .NET Elevation of Privilege Vulnerability Affected packages: NuGet/Microsoft.NETCore.App.Runtime.linux-arm、NuGet/Microsoft.NETCore.App.Runtime.linux-arm64、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-arm、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-arm64、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-x64、... 3 more Attributes: Fix available、Severity - 6.7 (Medium)
最高第 1 名03:26 达到03:26 首次观测上榜04:47 观测离榜累计约1小时20分 - 10GHSA-fx4q-gjrx-2jw6 · Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-62897 – .NET Remote Code Execution Vulnerability Affected packages: NuGet/Microsoft.WindowsDesktop.App.Runtime.win-arm64、NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x64、NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x86 Attributes: Fix available、Severity - 7.0 (High)
最高第 1 名03:59 达到03:59 首次观测上榜07:58 观测离榜上榜 2 次(重入 1 次)累计约1小时36分 - 11GHSA-gg8c-3338-xw2f · Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability
Microsoft Security Advisory CVE-2026-70354 – .NET Core Remote Code Execution Vulnerability Affected packages: NuGet/Microsoft.WindowsDesktop.App.Runtime.win-arm64、NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x64、NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x86 Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名03:43 达到03:43 首次观测上榜04:47 观测离榜累计约1小时4分 - 12GHSA-h47f-gmjp-m7rr · compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 Affected packages: PyPI/compliance-trestle Attributes: Fix available、Severity - 8.6 (High)
最高第 1 名23:42 达到23:42 首次观测上榜当日结束时仍在榜累计约16分钟 - 13GHSA-m7jc-g4rc-jmvh · Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax Affected packages: Packagist/winter/wn-backend-module Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名22:55 达到22:55 首次观测上榜23:42 观测离榜累计约48分钟 - 14GHSA-m93f-wj8c-rp8p · Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability
Microsoft Security Advisory CVE-2026-62901 – .NET Denial of Service Vulnerability Affected packages: NuGet/Microsoft.NETCore.App.Runtime.linux-arm、NuGet/Microsoft.NETCore.App.Runtime.linux-arm64、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-arm、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-arm64、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-x64、... 6 more Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名03:11 达到03:11 首次观测上榜04:47 观测离榜累计约1小时36分 - 15GHSA-r6mh-95jw-g7qg · Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability
Microsoft Security Advisory CVE-2026-62899 – .NET Security Feature Bypass Vulnerability Affected packages: NuGet/Microsoft.NETCore.App.Runtime.linux-arm、NuGet/Microsoft.NETCore.App.Runtime.linux-arm64、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-arm、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-arm64、NuGet/Microsoft.NETCore.App.Runtime.linux-musl-x64、... 3 more Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名02:54 达到02:54 首次观测上榜03:43 观测离榜累计约48分钟 - 16GO-2026-5075 · Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall Affected packages: Go/github.com/dadrus/heimdall Attributes: Fix available
最高第 1 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 17GO-2026-5306 · Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd
Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd Affected packages: Go/github.com/canonical/lxd Attributes: No fix available
最高第 1 名07:58 达到07:58 首次观测上榜08:46 观测离榜累计约48分钟 - 18JLSEC-2026-1257 · Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function...
Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function... Affected packages: Julia/Mongoose_jll Attributes: No fix available、Severity - 8.7 (High)
最高第 1 名15:43 达到15:43 首次观测上榜17:18 观测离榜累计约1小时36分 - 19JLSEC-2026-1262 · In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are...
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are... Affected packages: Julia/wxWidgets_jll Attributes: No fix available、Severity - 3.7 (Low)
最高第 1 名23:58 达到23:58 首次观测上榜当日结束时仍在榜累计约0分钟 - 20MAL-2026-13736 · Malicious code in @nzeros/codebreak (npm)
Malicious code in @nzeros/codebreak (npm) Affected packages: npm/@nzeros/codebreak Attributes: No fix available
最高第 1 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 21MAL-2026-13742 · Malicious code in zeal-rq-hooks (npm)
Malicious code in zeal-rq-hooks (npm) Affected packages: npm/zeal-rq-hooks Attributes: No fix available
最高第 1 名01:34 达到01:34 首次观测上榜03:11 观测离榜累计约1小时36分 - 22MAL-2026-13743 · Malicious code in whs4_ued (npm)
Malicious code in whs4_ued (npm) Affected packages: npm/whs4_ued Attributes: No fix available
最高第 1 名02:07 达到02:07 首次观测上榜03:26 观测离榜累计约1小时20分 - 23MAL-2026-13780 · Malicious code in @noxzacode/eslint-config (npm)
Malicious code in @noxzacode/eslint-config (npm) Affected packages: npm/@noxzacode/eslint-config Attributes: No fix available
最高第 1 名18:54 达到18:54 首次观测上榜20:30 观测离榜累计约1小时36分 - 24MAL-2026-13847 · Malicious code in @years18/n8n-nodes-utils-helper-a (npm)
Malicious code in @years18/n8n-nodes-utils-helper-a (npm) Affected packages: npm/@years18/n8n-nodes-utils-helper-a Attributes: No fix available
最高第 1 名20:30 达到20:30 首次观测上榜21:02 观测离榜累计约32分钟 - 25MINI-26v6-65rj-4p8h · MinimOS/litellm-1.95
Affected packages: MinimOS/litellm-1.95 Attributes: Fix available
最高第 1 名16:30 达到16:30 首次观测上榜18:38 观测离榜累计约2小时8分 - 26MINI-35hp-9r2c-55gh · MinimOS/traefik-2
Affected packages: MinimOS/traefik-2 Attributes: No fix available
最高第 1 名22:07 达到22:07 首次观测上榜23:42 观测离榜累计约1小时36分 - 27MINI-3996-jx8v-pwx5 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 1 名10:06 达到10:06 首次观测上榜15:10 观测离榜累计约5小时4分 - 28MINI-f3hf-m5x8-f8fv · MinimOS/busybox
Affected packages: MinimOS/busybox、MinimOS/busybox-full、MinimOS/busybox-mdev-openrc、MinimOS/busybox-openrc、MinimOS/busybox-suid Attributes: Fix available
最高第 1 名16:46 达到16:46 首次观测上榜18:38 观测离榜累计约1小时52分 - 29RHSA-2026:54246 · Red Hat Security Advisory: kernel security update
Red Hat Security Advisory: kernel security update Affected packages: Red Hat:enterprise_linux:8::baseos/bpftool、Red Hat:enterprise_linux:8::baseos/bpftool-debuginfo、Red Hat:enterprise_linux:8::baseos/kernel、Red Hat:enterprise_linux:8::baseos/kernel-abi-stablelists、Red Hat:enterprise_linux:8::baseos/kernel-core、... 38 more Attributes: Fix available、Severity - 7.0 (High)
最高第 1 名18:38 达到18:38 首次观测上榜18:54 观测离榜累计约16分钟 - 30RLSA-2026:53847 · Important: isns-utils security update
Important: isns-utils security update Affected packages: Rocky Linux:9/isns-utils Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名14:38 达到14:38 首次观测上榜17:18 观测离榜累计约2小时40分 - 31ROOT-APP-MAVEN-CVE-2026-41695 · CVE-2026-41695 in org.springframework.data:spring-data-commons - Patched by Root
CVE-2026-41695 in org.springframework.data:spring-data-commons - Patched by Root Affected packages: Root:Maven/io.root.org.springframework.data:spring-data-commons、Root:Maven/org.springframework.data:spring-data-commons Attributes: Fix available
最高第 1 名17:18 达到17:18 首次观测上榜18:38 观测离榜累计约1小时20分 - 32ROOT-APP-NPM-CVE-2026-67213 · CVE-2026-67213 in nanoid - Patched by Root
CVE-2026-67213 in nanoid - Patched by Root Affected packages: Root:npm/@rootio/nanoid、Root:npm/nanoid Attributes: Fix available
最高第 1 名19:42 达到19:42 首次观测上榜20:30 观测离榜累计约48分钟 - 33ROOT-APP-PYPI-CVE-2026-40192 · CVE-2026-40192 in pillow - Patched by Root
CVE-2026-40192 in pillow - Patched by Root Affected packages: Root:PyPI/pillow、Root:PyPI/rootio-pillow Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名21:50 达到21:50 首次观测上榜22:07 观测离榜累计约16分钟 - 34CVE-2025-15686 · Open5GS HSS Service fd_msg_sess_get denial of service
Open5GS HSS Service fd_msg_sess_get denial of service Affected packages: github.com/open5gs/open5gs Attributes: No fix available、Severity - 2.1 (Low)
最高第 2 名12:14 达到12:14 首次观测上榜15:27 观测离榜累计约3小时12分 - 35DEBIAN-CVE-2026-52076 · Debian:14/mongoose
Affected packages: Debian:14/mongoose Attributes: Fix available
最高第 2 名21:02 达到21:02 首次观测上榜21:50 观测离榜累计约48分钟 - 36DEBIAN-CVE-2026-71193 · Debian:11/designate
Affected packages: Debian:11/designate、Debian:12/designate、Debian:13/designate、Debian:14/designate Attributes: No fix available
最高第 2 名01:02 达到01:02 首次观测上榜03:11 观测离榜累计约2小时8分 - 37DEBIAN-CVE-2026-73213 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: No fix available
最高第 2 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 38ECHO-5c6a-872b-49bb · Echo/qtbase-opensource-src
Affected packages: Echo/qtbase-opensource-src Attributes: Fix available
最高第 2 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 39ECHO-f6d8-9d6f-c927 · Echo:PyPi/python-ldap
Affected packages: Echo:PyPi/python-ldap Attributes: Fix available
最高第 2 名08:46 达到08:46 首次观测上榜10:06 观测离榜累计约1小时20分 - 40GHSA-c494-m2fq-59mx · Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability
Microsoft Security Advisory CVE-2026-62898 – .NET Information Disclosure Vulnerability Affected packages: NuGet/Microsoft.NETCore.App.Runtime.win-arm64、NuGet/Microsoft.NETCore.App.Runtime.win-x64、NuGet/Microsoft.NETCore.App.Runtime.win-x86 Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名02:54 达到02:54 首次观测上榜03:26 观测离榜累计约32分钟 - 41GHSA-jqhp-238x-qhgf · Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability
Microsoft Security Advisory CVE-2026-62886 – .NET Elevation of Privilege Vulnerability Affected packages: NuGet/Microsoft.WindowsDesktop.App.Runtime.win-arm64、NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x64、NuGet/Microsoft.WindowsDesktop.App.Runtime.win-x86 Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名03:26 达到03:26 首次观测上榜04:47 观测离榜累计约1小时20分 - 42GHSA-q939-rpr3-3284 · SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames
SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames Affected packages: NuGet/SSH.NET Attributes: Fix available、Severity - 7.1 (High)
最高第 2 名23:42 达到23:42 首次观测上榜当日结束时仍在榜累计约16分钟 - 43GO-2026-5119 · Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha Affected packages: Go/github.com/naiba/nezha、Go/github.com/nezhahq/nezha Attributes: Fix available
最高第 2 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 44GO-2026-5368 · VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd Affected packages: Go/github.com/canonical/lxd Attributes: No fix available
最高第 2 名07:58 达到07:58 首次观测上榜08:46 观测离榜累计约48分钟 - 45JLSEC-2026-1260 · GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified...
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified... Affected packages: Julia/patch_jll Attributes: No fix available、Severity - 4.6 (Medium)
最高第 2 名22:55 达到22:55 首次观测上榜23:42 观测离榜累计约48分钟 - 46MAL-2026-13752 · Malicious code in chapters-core (npm)
Malicious code in chapters-core (npm) Affected packages: npm/chapters-core Attributes: No fix available
最高第 2 名03:11 达到03:11 首次观测上榜04:47 观测离榜累计约1小时36分 - 47MAL-2026-13781 · Malicious code in @noxzacode/libsignal-node (npm)
Malicious code in @noxzacode/libsignal-node (npm) Affected packages: npm/@noxzacode/libsignal-node Attributes: No fix available
最高第 2 名18:54 达到18:54 首次观测上榜20:30 观测离榜累计约1小时36分 - 48MAL-2026-13848 · Malicious code in @years18/n8n-nodes-utils-helper-b (npm)
Malicious code in @years18/n8n-nodes-utils-helper-b (npm) Affected packages: npm/@years18/n8n-nodes-utils-helper-b Attributes: No fix available
最高第 2 名20:30 达到20:30 首次观测上榜21:02 观测离榜累计约32分钟 - 49MINI-44h5-g63x-69r7 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 2 名10:06 达到10:06 首次观测上榜15:10 观测离榜累计约5小时4分 - 50MINI-jj2f-pq5p-vr55 · MinimOS/litellm-1.95
Affected packages: MinimOS/litellm-1.95 Attributes: Fix available
最高第 2 名16:30 达到16:30 首次观测上榜18:38 观测离榜累计约2小时8分


































































































