
OSV.dev · 实时热榜
- 01RLSA-2026:49621 · Important: thunderbird security update
Important: thunderbird security update Affected packages: Rocky Linux:10/thunderbird Attributes: Fix available、Severity - 8.8 (High)
最高第 2 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 02RLSA-2026:49836 · Important: ldns security update
Important: ldns security update Affected packages: Rocky Linux:10/ldns Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 03RLSA-2026:49838 · Important: osbuild-composer security, bug fix, and enhancement update
Important: osbuild-composer security, bug fix, and enhancement update Affected packages: Rocky Linux:9/osbuild-composer Attributes: Fix available、Severity - 7.5 (High)
最高第 8 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 04RLSA-2026:49870 · Low: kernel security, bug fix, and enhancement update
Low: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:9/kernel Attributes: Fix available、Severity - 5.5 (Medium)
最高第 9 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 05RLSA-2026:49871 · Moderate: kernel security, bug fix, and enhancement update
Moderate: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:10/kernel Attributes: Fix available、Severity - 5.5 (Medium)
最高第 4 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 06RLSA-2026:49921 · Important: thunderbird security update
Important: thunderbird security update Affected packages: Rocky Linux:9/thunderbird Attributes: Fix available、Severity - 8.8 (High)
最高第 10 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 07RLSA-2026:50108 · Important: ldns security update
Important: ldns security update Affected packages: Rocky Linux:9/ldns Attributes: Fix available、Severity - 7.5 (High)
最高第 11 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 08RLSA-2026:50141 · Important: sg3_utils security, bug fix, and enhancement update
Important: sg3_utils security, bug fix, and enhancement update Affected packages: Rocky Linux:9/sg3_utils Attributes: Fix available、Severity - 7.6 (High)
最高第 7 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 09RLSA-2026:50142 · Important: sg3_utils security, bug fix, and enhancement update
Important: sg3_utils security, bug fix, and enhancement update Affected packages: Rocky Linux:10/sg3_utils Attributes: Fix available、Severity - 7.6 (High)
最高第 1 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 10RLSA-2026:50144 · Moderate: libgcrypt security update
Moderate: libgcrypt security update Affected packages: Rocky Linux:10/libgcrypt Attributes: Fix available、Severity - 7.5 (High)
最高第 5 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 11RLSA-2026:50747 · Important: freerdp security update
Important: freerdp security update Affected packages: Rocky Linux:10/freerdp Attributes: Fix available、Severity - 7.5 (High)
最高第 6 名08:45 达到08:45 首次观测上榜13:17 观测离榜累计约4小时32分 - 12RUSTSEC-2026-0236 · A ` BigInt ` division panics, and two neighbouring operations answer wrongly in silence
A ` BigInt ` division panics, and two neighbouring operations answer wrongly in silence Affected packages: crates.io/viperjs Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名17:17 达到17:17 首次观测上榜21:39 观测离榜累计约4小时22分 - 13GHSA-hxvh-4h3w-prp9 · Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721) Affected packages: npm/nuxt Attributes: Fix available、Severity - 8.2 (High)
最高第 3 名05:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分 - 14JLSEC-2026-1168 · GMP has an integer overflow with crafted inputs on 32-bit builds in ` int_raw.c ` , leading to buffer overflow
GMP has an integer overflow with crafted inputs on 32-bit builds in ` int_raw.c ` , leading to buffer overflow Affected packages: Julia/GCCBootstrap_jll、Julia/GMP_jll、Julia/LibStdCxx_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名05:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分 - 15JLSEC-2026-1169 · 7-Zip for Windows fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive
7-Zip for Windows fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive Affected packages: Julia/p7zip_jll Attributes: No fix available、Severity - 4.8 (Medium)
最高第 2 名05:17 达到05:17 首次观测上榜08:45 观测离榜累计约3小时28分 - 16ROOT-OS-DEBIAN-12-CVE-2004-0230 · CVE-2004-0230 in linux - Patched by Root
CVE-2004-0230 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 1 名13:17 达到13:17 首次观测上榜16:45 观测离榜累计约3小时28分 - 17ROOT-OS-DEBIAN-12-CVE-2008-2544 · CVE-2008-2544 in linux - Patched by Root
CVE-2008-2544 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 2 名13:17 达到13:17 首次观测上榜16:45 观测离榜累计约3小时28分 - 18ROOT-OS-DEBIAN-12-CVE-2010-5321 · CVE-2010-5321 in linux - Patched by Root
CVE-2010-5321 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 3 名13:17 达到13:17 首次观测上榜16:45 观测离榜累计约3小时28分 - 19ROOT-OS-DEBIAN-12-CVE-2011-4915 · CVE-2011-4915 in linux - Patched by Root
CVE-2011-4915 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 4 名13:17 达到13:17 首次观测上榜16:45 观测离榜累计约3小时28分 - 20MINI-292j-93mg-c5vm · MinimOS/opensearch-3
Affected packages: MinimOS/opensearch-3、MinimOS/opensearch-3-alerting、MinimOS/opensearch-3-anomaly-detection、MinimOS/opensearch-3-crypto-kms、MinimOS/opensearch-3-discovery-ec2、... 11 more Attributes: Fix available
最高第 1 名10:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分 - 21MINI-29vr-x773-4rxp · MinimOS/opensearch-3
Affected packages: MinimOS/opensearch-3、MinimOS/opensearch-3-ml-commons、MinimOS/opensearch-3-notifications、MinimOS/opensearch-3-performance-analyzer、MinimOS/opensearch-3-repository-azure、... 2 more Attributes: Fix available
最高第 2 名10:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分 - 22MINI-2c7c-jh4w-r7hj · MinimOS/node-feature-discovery-0.19
Affected packages: MinimOS/node-feature-discovery-0.19 Attributes: Fix available
最高第 3 名10:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分 - 23MINI-2j7v-wwpf-wvxj · MinimOS/kube-arangodb-fips
Affected packages: MinimOS/kube-arangodb-fips Attributes: Fix available
最高第 5 名10:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分 - 24MINI-36fq-h8f9-gp5h · MinimOS/node-feature-discovery-fips-0.19
Affected packages: MinimOS/node-feature-discovery-fips-0.19 Attributes: Fix available
最高第 4 名10:05 达到10:05 首次观测上榜13:17 观测离榜累计约3小时12分 - 25GHSA-279x-mwfv-vcqv · Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Affected packages: npm/@nuxt/devtools Attributes: Fix available、Severity - 9.6 (Critical)
最高第 1 名05:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分 - 26GHSA-48hr-524c-v5w3 · Nuxt: Unauthorized Component Instantiation via Server Island Props
Nuxt: Unauthorized Component Instantiation via Server Island Props Affected packages: npm/nuxt Attributes: Fix available、Severity - 4.8 (Medium)
最高第 2 名05:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分 - 27GHSA-wm8w-6qjm-cv43 · Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients Affected packages: npm/nuxt Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名05:33 达到05:33 首次观测上榜08:45 观测离榜累计约3小时12分 - 28ROOT-OS-DEBIAN-12-CVE-2005-3660 · CVE-2005-3660 in linux - Patched by Root
CVE-2005-3660 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 2 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 29ROOT-OS-DEBIAN-12-CVE-2008-4609 · CVE-2008-4609 in linux - Patched by Root
CVE-2008-4609 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 4 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 30ROOT-OS-DEBIAN-12-CVE-2010-4563 · CVE-2010-4563 in linux - Patched by Root
CVE-2010-4563 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 5 名13:33 达到13:33 首次观测上榜16:45 观测离榜累计约3小时12分 - 31GHSA-42cj-m3vj-89wv · Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass Affected packages: Go/github.com/traefik/traefik/v3 Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名06:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分 - 32GHSA-9473-5f9j-94wq · Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props Affected packages: npm/nuxt Attributes: Fix available、Severity - 8.1 (High)
最高第 4 名06:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分 - 33GHSA-9pgf-384g-p7mv · Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation Affected packages: npm/nuxt Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名06:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分 - 34GHSA-qq9q-x9w4-chhj · Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion Affected packages: Go/Traefik Attributes: Fix available、Severity - 5.3 (Medium)
最高第 2 名06:05 达到06:05 首次观测上榜08:45 观测离榜累计约2小时40分 - 35MAL-2026-13374 · Malicious code in @chnayser/server (npm)
Malicious code in @chnayser/server (npm) Affected packages: npm/@chnayser/server Attributes: No fix available
最高第 6 名06:21 达到06:21 首次观测上榜08:45 观测离榜累计约2小时24分 - 36MAL-2026-13375 · Malicious code in app-api-sdk (npm)
Malicious code in app-api-sdk (npm) Affected packages: npm/app-api-sdk Attributes: No fix available
最高第 15 名06:21 达到06:21 首次观测上榜08:45 观测离榜累计约2小时24分 - 37MAL-2026-13376 · Malicious code in claude-remote-agent (npm)
Malicious code in claude-remote-agent (npm) Affected packages: npm/claude-remote-agent Attributes: No fix available
最高第 8 名06:21 达到06:21 首次观测上榜08:45 观测离榜累计约2小时24分 - 38MAL-2026-13377 · Malicious code in ezdiscordbots (npm)
Malicious code in ezdiscordbots (npm) Affected packages: npm/ezdiscordbots Attributes: No fix available
最高第 9 名06:21 达到06:21 首次观测上榜08:45 观测离榜累计约2小时24分 - 39MAL-2026-13378 · Malicious code in npm-dc-dev (npm)
Malicious code in npm-dc-dev (npm) Affected packages: npm/npm-dc-dev Attributes: No fix available
最高第 10 名06:21 达到06:21 首次观测上榜08:45 观测离榜累计约2小时24分 - 40ROOT-OS-DEBIAN-11-CVE-2025-15649 · CVE-2025-15649 in perl - Patched by Root
CVE-2025-15649 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 2 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 41ROOT-OS-DEBIAN-11-CVE-2025-40909 · CVE-2025-40909 in perl - Patched by Root
CVE-2025-40909 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 3 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 42ROOT-OS-DEBIAN-11-CVE-2026-12087 · CVE-2026-12087 in perl - Patched by Root
CVE-2026-12087 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 4 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 43ROOT-OS-DEBIAN-11-CVE-2026-13221 · CVE-2026-13221 in perl - Patched by Root
CVE-2026-13221 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 5 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 44ROOT-OS-DEBIAN-11-CVE-2026-42496 · CVE-2026-42496 in perl - Patched by Root
CVE-2026-42496 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available、Severity - 9.1 (Critical)
最高第 6 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 45ROOT-OS-DEBIAN-11-CVE-2026-42497 · CVE-2026-42497 in perl - Patched by Root
CVE-2026-42497 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available、Severity - 7.5 (High)
最高第 7 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 46ROOT-OS-DEBIAN-11-CVE-2026-48959 · CVE-2026-48959 in perl - Patched by Root
CVE-2026-48959 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 8 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 47ROOT-OS-DEBIAN-11-CVE-2026-48961 · CVE-2026-48961 in perl - Patched by Root
CVE-2026-48961 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 9 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 48ROOT-OS-DEBIAN-11-CVE-2026-48962 · CVE-2026-48962 in perl - Patched by Root
CVE-2026-48962 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available、Severity - 7.8 (High)
最高第 10 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 49ROOT-OS-DEBIAN-11-CVE-2026-57432 · CVE-2026-57432 in perl - Patched by Root
CVE-2026-57432 in perl - Patched by Root Affected packages: Root:Debian:11/perl、Root:Debian:11/rootio-perl Attributes: Fix available
最高第 11 名19:31 达到19:31 首次观测上榜21:39 观测离榜累计约2小时8分 - 50ROOT-OS-DEBIAN-12-CVE-2011-4916 · CVE-2011-4916 in linux - Patched by Root
CVE-2011-4916 in linux - Patched by Root Affected packages: Root:Debian:12/linux、Root:Debian:12/rootio-linux Attributes: Fix available
最高第 8 名13:33 达到13:33 首次观测上榜15:41 观测离榜累计约2小时8分


































































































