
OSV.dev · 实时热榜
- 01MINI-3996-jx8v-pwx5 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 1 名10:06 达到10:06 首次观测上榜15:10 观测离榜累计约5小时4分 - 02MINI-44h5-g63x-69r7 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 2 名10:06 达到10:06 首次观测上榜15:10 观测离榜累计约5小时4分 - 03MINI-5pwr-rm8w-8wqp · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 3 名10:06 达到10:06 首次观测上榜15:10 观测离榜累计约5小时4分 - 04MINI-6cmj-xhvw-phqx · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 4 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 05MINI-6j38-g9gc-4r5r · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 5 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 06MINI-746j-qv3x-8qp7 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 6 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 07MINI-86f4-8wgx-95gx · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 7 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 08MINI-8vx4-vvmc-7fq3 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 8 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 09MINI-8wqm-qmp7-74w9 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 9 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 10MINI-98w4-588g-5r6f · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 10 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 11MINI-9rrr-2pp4-pxp6 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 11 名10:06 达到10:06 首次观测上榜14:38 观测离榜累计约4小时32分 - 12GO-2026-5075 · Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall
Heimdall: IP Spoofing via Unvalidated Forwarding Headers in github.com/dadrus/heimdall Affected packages: Go/github.com/dadrus/heimdall Attributes: Fix available
最高第 1 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 13GO-2026-5119 · Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha Affected packages: Go/github.com/naiba/nezha、Go/github.com/nezhahq/nezha Attributes: Fix available
最高第 2 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 14GO-2026-5152 · Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik
Traefik: SNICheck ignores wildcard TLSOptions mappings in github.com/traefik/traefik Affected packages: Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available
最高第 3 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 15GO-2026-5274 · Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph
Dgraph: Unauthenticated admin token disclosure via /debug/pprof/cmdline in github.com/dgraph-io/dgraph Affected packages: Go/github.com/dgraph-io/dgraph、Go/github.com/dgraph-io/dgraph/v25、Go/github.com/hypermodeinc/dgraph/v24 Attributes: Fix available
最高第 4 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 16GO-2026-5287 · Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik Affected packages: Go/github.com/traefik/traefik、Go/github.com/traefik/traefik/v2、Go/github.com/traefik/traefik/v3 Attributes: Fix available
最高第 5 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 17GO-2026-5466 · Unauthenticated backend instantiation in github.com/rclone/rclone
Unauthenticated backend instantiation in github.com/rclone/rclone Affected packages: Go/github.com/ncw/rclone、Go/github.com/rclone/rclone Attributes: Fix available
最高第 6 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 18GO-2026-5516 · Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph
Pre-Auth DQL injection in upsert condition field in github.com/dgraph-io/dgraph Affected packages: Go/github.com/dgraph-io/dgraph、Go/github.com/dgraph-io/dgraph/v25、Go/github.com/hypermodeinc/dgraph/v24 Attributes: Fix available
最高第 7 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 19GO-2026-5529 · Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph
Unauthenticated restoreTenant mutation allows database overwrite and SSRF in github.com/dgraph-io/dgraph Affected packages: Go/github.com/dgraph-io/dgraph、Go/github.com/dgraph-io/dgraph/v25、Go/github.com/hypermodeinc/dgraph/v24 Attributes: Fix available
最高第 8 名04:47 达到04:47 首次观测上榜08:31 观测离榜累计约3小时44分 - 20CVE-2025-15685 · Open5GS freeDiameter memory corruption
Open5GS freeDiameter memory corruption Affected packages: github.com/open5gs/open5gs Attributes: No fix available、Severity - 5.3 (Medium)
最高第 3 名12:14 达到12:14 首次观测上榜15:27 观测离榜累计约3小时12分 - 21CVE-2025-15686 · Open5GS HSS Service fd_msg_sess_get denial of service
Open5GS HSS Service fd_msg_sess_get denial of service Affected packages: github.com/open5gs/open5gs Attributes: No fix available、Severity - 2.1 (Low)
最高第 2 名12:14 达到12:14 首次观测上榜15:27 观测离榜累计约3小时12分 - 22CVE-2025-15687 · Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service
Open5GS SMF Diameter Gx Credit-Control-Answer smf_gx_cca_cb denial of service Affected packages: github.com/open5gs/open5gs Attributes: No fix available、Severity - 2.1 (Low)
最高第 1 名12:14 达到12:14 首次观测上榜15:27 观测离榜累计约3小时12分 - 23ECHO-5c6a-872b-49bb · Echo/qtbase-opensource-src
Affected packages: Echo/qtbase-opensource-src Attributes: Fix available
最高第 2 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 24ECHO-ac3c-11a6-be31 · Echo/qtbase-opensource-src
Affected packages: Echo/qtbase-opensource-src Attributes: Fix available
最高第 3 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 25MAL-2026-13734 · Malicious code in @aerodrome-finance/contracts (npm)
Malicious code in @aerodrome-finance/contracts (npm) Affected packages: npm/@aerodrome-finance/contracts Attributes: No fix available
最高第 4 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 26MAL-2026-13736 · Malicious code in @nzeros/codebreak (npm)
Malicious code in @nzeros/codebreak (npm) Affected packages: npm/@nzeros/codebreak Attributes: No fix available
最高第 1 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 27MAL-2026-13737 · Malicious code in @openzeppelin-4/contracts (npm)
Malicious code in @openzeppelin-4/contracts (npm) Affected packages: npm/@openzeppelin-4/contracts Attributes: No fix available
最高第 5 名00:00 达到当日首次采集时已在榜03:11 观测离榜累计约3小时11分 - 28CVE-2026-9318 · tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title
tablib versions prior to 3.10.0 Stored XSS via HTML Export Dataset Title Affected packages: github.com/jazzband/tablib Attributes: Fix available、Severity - 4.8 (Medium)
最高第 3 名12:30 达到12:30 首次观测上榜15:27 观测离榜累计约2小时56分 - 29CVE-2025-15684 · Open5GS CER init.c diam_log_func assertion
Open5GS CER init.c diam_log_func assertion Affected packages: github.com/open5gs/open5gs Attributes: No fix available、Severity - 5.5 (Medium)
最高第 4 名12:14 达到12:14 首次观测上榜15:10 观测离榜累计约2小时56分 - 30GHSA-87fv-vqqr-m4jr · SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle
SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle Affected packages: Go/github.com/seaweedfs/seaweedfs Attributes: Fix available、Severity - 9.3 (Critical)
最高第 1 名00:15 达到00:15 首次观测上榜03:11 观测离榜累计约2小时56分 - 31MAL-2026-13738 · Malicious code in @openzeppelin-5/contracts (npm)
Malicious code in @openzeppelin-5/contracts (npm) Affected packages: npm/@openzeppelin-5/contracts Attributes: No fix available
最高第 6 名00:00 达到当日首次采集时已在榜02:54 观测离榜累计约2小时55分 - 32MAL-2026-13739 · Malicious code in ethereum-vault-connector (npm)
Malicious code in ethereum-vault-connector (npm) Affected packages: npm/ethereum-vault-connector Attributes: No fix available
最高第 7 名00:00 达到当日首次采集时已在榜02:54 观测离榜累计约2小时55分 - 33RLSA-2026:53329 · Important: kernel security, bug fix, and enhancement update
Important: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:9/kernel Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名14:38 达到14:38 首次观测上榜17:18 观测离榜累计约2小时40分 - 34RLSA-2026:53365 · Important: fence-agents security update
Important: fence-agents security update Affected packages: Rocky Linux:9/fence-agents Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名14:38 达到14:38 首次观测上榜17:18 观测离榜累计约2小时40分 - 35RLSA-2026:53452 · Moderate: gstreamer1-plugins-good security update
Moderate: gstreamer1-plugins-good security update Affected packages: Rocky Linux:9/gstreamer1-plugins-good Attributes: Fix available、Severity - 7.5 (High)
最高第 4 名14:38 达到14:38 首次观测上榜17:18 观测离榜累计约2小时40分 - 36RLSA-2026:53844 · Important: iscsi-initiator-utils security, bug fix, and enhancement update
Important: iscsi-initiator-utils security, bug fix, and enhancement update Affected packages: Rocky Linux:9/iscsi-initiator-utils Attributes: Fix available、Severity - 8.6 (High)
最高第 5 名14:38 达到14:38 首次观测上榜17:18 观测离榜累计约2小时40分 - 37RLSA-2026:53847 · Important: isns-utils security update
Important: isns-utils security update Affected packages: Rocky Linux:9/isns-utils Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名14:38 达到14:38 首次观测上榜17:18 观测离榜累计约2小时40分 - 38MINI-c4p8-cchw-33vm · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 12 名10:06 达到10:06 首次观测上榜12:30 观测离榜累计约2小时24分 - 39DEBIAN-CVE-2026-71193 · Debian:11/designate
Affected packages: Debian:11/designate、Debian:12/designate、Debian:13/designate、Debian:14/designate Attributes: No fix available
最高第 2 名01:02 达到01:02 首次观测上榜03:11 观测离榜累计约2小时8分 - 40DEBIAN-CVE-2026-71194 · Debian:11/designate
Affected packages: Debian:11/designate、Debian:12/designate、Debian:13/designate、Debian:14/designate Attributes: No fix available
最高第 1 名01:02 达到01:02 首次观测上榜03:11 观测离榜累计约2小时8分 - 41DEBIAN-CVE-2026-20901 · Debian:11/intel-microcode
Affected packages: Debian:11/intel-microcode、Debian:12/intel-microcode、Debian:13/intel-microcode、Debian:14/intel-microcode Attributes: No fix available
最高第 7 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 42DEBIAN-CVE-2026-20917 · Debian:11/intel-microcode
Affected packages: Debian:11/intel-microcode、Debian:12/intel-microcode、Debian:13/intel-microcode、Debian:14/intel-microcode Attributes: No fix available
最高第 3 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 43DEBIAN-CVE-2026-73212 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: Fix available
最高第 1 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 44DEBIAN-CVE-2026-73213 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: No fix available
最高第 2 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 45DEBIAN-CVE-2026-73214 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: No fix available
最高第 6 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 46DEBIAN-CVE-2026-73215 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: No fix available
最高第 4 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 47DEBIAN-CVE-2026-73216 · Debian:11/coturn
Affected packages: Debian:11/coturn、Debian:12/coturn、Debian:13/coturn、Debian:14/coturn Attributes: No fix available
最高第 8 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 48DEBIAN-CVE-2026-73228 · Debian:11/djangorestframework
Affected packages: Debian:11/djangorestframework、Debian:12/djangorestframework、Debian:13/djangorestframework、Debian:14/djangorestframework Attributes: No fix available
最高第 5 名05:03 达到05:03 首次观测上榜07:10 观测离榜累计约2小时8分 - 49MINI-26v6-65rj-4p8h · MinimOS/litellm-1.95
Affected packages: MinimOS/litellm-1.95 Attributes: Fix available
最高第 1 名16:30 达到16:30 首次观测上榜18:38 观测离榜累计约2小时8分 - 50MINI-c62r-wwwx-hmc3 · MinimOS/neo4j-2026.06
Affected packages: MinimOS/neo4j-2026.06 Attributes: No fix available
最高第 13 名10:06 达到10:06 首次观测上榜12:14 观测离榜累计约2小时8分


































































































