
OSV.dev · 实时热榜
- 01MAL-2026-13937 · Malicious code in @ethers-js/contracts (npm)
Malicious code in @ethers-js/contracts (npm) Affected packages: npm/@ethers-js/contracts Attributes: No fix available
最高第 16 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 02MAL-2026-13938 · Malicious code in @kolbo/mcp (npm)
Malicious code in @kolbo/mcp (npm) Affected packages: npm/@kolbo/mcp Attributes: No fix available
最高第 6 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 03MAL-2026-13939 · Malicious code in @leonardo0902/vortex-kit (npm)
Malicious code in @leonardo0902/vortex-kit (npm) Affected packages: npm/@leonardo0902/vortex-kit Attributes: No fix available
最高第 3 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 04MAL-2026-13941 · Malicious code in @solana-js/web3 (npm)
Malicious code in @solana-js/web3 (npm) Affected packages: npm/@solana-js/web3 Attributes: No fix available
最高第 1 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 05MAL-2026-13942 · Malicious code in chai-as-reformed (npm)
Malicious code in chai-as-reformed (npm) Affected packages: npm/chai-as-reformed Attributes: No fix available
最高第 10 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 06MAL-2026-13943 · Malicious code in cilm-ui-commons (npm)
Malicious code in cilm-ui-commons (npm) Affected packages: npm/cilm-ui-commons Attributes: No fix available
最高第 12 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 07MAL-2026-13944 · Malicious code in copytrade-core (npm)
Malicious code in copytrade-core (npm) Affected packages: npm/copytrade-core Attributes: No fix available
最高第 13 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 08MAL-2026-13949 · Malicious code in external-process-live-log (npm)
Malicious code in external-process-live-log (npm) Affected packages: npm/external-process-live-log Attributes: No fix available
最高第 2 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 09MAL-2026-13950 · Malicious code in fmt-util-k7x2 (npm)
Malicious code in fmt-util-k7x2 (npm) Affected packages: npm/fmt-util-k7x2 Attributes: No fix available
最高第 14 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 10MAL-2026-13951 · Malicious code in functions-framework-nodejs (npm)
Malicious code in functions-framework-nodejs (npm) Affected packages: npm/functions-framework-nodejs Attributes: No fix available
最高第 11 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 11MAL-2026-13952 · Malicious code in global-intel (npm)
Malicious code in global-intel (npm) Affected packages: npm/global-intel Attributes: No fix available
最高第 4 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 12MAL-2026-13959 · Malicious code in prediction-trader (npm)
Malicious code in prediction-trader (npm) Affected packages: npm/prediction-trader Attributes: No fix available
最高第 8 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 13MAL-2026-13960 · Malicious code in process-live-log (npm)
Malicious code in process-live-log (npm) Affected packages: npm/process-live-log Attributes: No fix available
最高第 15 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 14MAL-2026-13961 · Malicious code in velora-kit (npm)
Malicious code in velora-kit (npm) Affected packages: npm/velora-kit Attributes: No fix available
最高第 9 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 15MAL-2026-13962 · Malicious code in ventra-kit (npm)
Malicious code in ventra-kit (npm) Affected packages: npm/ventra-kit Attributes: No fix available
最高第 7 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 16MAL-2026-13963 · Malicious code in vexium-kit (npm)
Malicious code in vexium-kit (npm) Affected packages: npm/vexium-kit Attributes: No fix available
最高第 5 名01:35 达到01:35 首次观测上榜06:04 观测离榜累计约4小时30分 - 17ECHO-16b4-af99-5729 · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 1 名11:08 达到11:08 首次观测上榜15:24 观测离榜累计约4小时16分 - 18ECHO-3f3c-1720-1cf2 · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 2 名11:08 达到11:08 首次观测上榜15:24 观测离榜累计约4小时16分 - 19ECHO-40e5-0764-92ff · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 3 名11:08 达到11:08 首次观测上榜15:24 观测离榜累计约4小时16分 - 20ECHO-81a7-2888-c43b · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 5 名11:08 达到11:08 首次观测上榜15:24 观测离榜累计约4小时16分 - 21ECHO-e27c-7219-f23a · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 4 名11:08 达到11:08 首次观测上榜15:24 观测离榜累计约4小时16分 - 22ECHO-1137-4f23-2f4e · Echo/postgresql-17
Affected packages: Echo/postgresql-17 Attributes: Fix available
最高第 2 名11:24 达到11:24 首次观测上榜15:24 观测离榜累计约4小时 - 23ECHO-1690-243f-9082 · Echo/postgresql-17
Affected packages: Echo/postgresql-17 Attributes: Fix available
最高第 1 名11:24 达到11:24 首次观测上榜15:24 观测离榜累计约4小时 - 24ECHO-930d-ab3a-f99c · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 6 名11:08 达到11:08 首次观测上榜14:52 观测离榜累计约3小时44分 - 25ECHO-87ab-7830-3981 · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 8 名11:08 达到11:08 首次观测上榜14:36 观测离榜累计约3小时28分 - 26ECHO-f9a0-cc73-ab07 · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 7 名11:08 达到11:08 首次观测上榜14:36 观测离榜累计约3小时28分 - 27CVE-2026-19786 · francoisjacquet RosarioSIS Modules.php cross-site request forgery
francoisjacquet RosarioSIS Modules.php cross-site request forgery Affected packages: github.com/francoisjacquet/rosariosis Attributes: No fix available、Severity - 5.3 (Medium)
最高第 3 名12:12 达到12:12 首次观测上榜15:24 观测离榜累计约3小时12分 - 28ECHO-3067-e4d3-8356 · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 9 名11:08 达到11:08 首次观测上榜14:04 观测离榜累计约2小时56分 - 29ECHO-cd45-9423-f52d · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 10 名11:08 达到11:08 首次观测上榜14:04 观测离榜累计约2小时56分 - 30ECHO-d44b-2515-54de · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 11 名11:08 达到11:08 首次观测上榜14:04 观测离榜累计约2小时56分 - 31ECHO-f2c3-3dd7-067b · Echo/postgresql-15
Affected packages: Echo/postgresql-15 Attributes: No fix available
最高第 12 名11:08 达到11:08 首次观测上榜14:04 观测离榜累计约2小时56分 - 32MGASA-2026-0335 · Updated dhcpcd packages fix security vulnerabilities
Updated dhcpcd packages fix security vulnerabilities Affected packages: Mageia:10/dhcpcd Attributes: Fix available
最高第 1 名06:04 达到06:04 首次观测上榜09:00 观测离榜累计约2小时55分 - 33GO-2026-5972 · Enforce maximum recursion depth in encoding/asn1
Enforce maximum recursion depth in encoding/asn1 Affected packages: Go/stdlib Attributes: Fix available
最高第 2 名06:04 达到06:04 首次观测上榜08:44 观测离榜累计约2小时39分 - 34GO-2026-6088 · Add recursion depth guard during decode in encoding/xml
Add recursion depth guard during decode in encoding/xml Affected packages: Go/stdlib Attributes: Fix available
最高第 3 名06:04 达到06:04 首次观测上榜08:44 观测离榜累计约2小时39分 - 35GO-2026-6089 · Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http Affected packages: Go/stdlib Attributes: Fix available
最高第 4 名06:04 达到06:04 首次观测上榜08:44 观测离榜累计约2小时39分 - 36GO-2026-6090 · Limit handshake messages we are willing to accept post-handshake in crypto/tls
Limit handshake messages we are willing to accept post-handshake in crypto/tls Affected packages: Go/stdlib Attributes: Fix available
最高第 5 名06:04 达到06:04 首次观测上榜08:44 观测离榜累计约2小时39分 - 37GO-2026-6091 · Fix Javascript regexp context tracking in html/template
Fix Javascript regexp context tracking in html/template Affected packages: Go/stdlib Attributes: Fix available
最高第 6 名06:04 达到06:04 首次观测上榜08:44 观测离榜累计约2小时39分 - 38RLSA-2026:40416 · Low: php:8.2 security, bug fix, and enhancement update
Low: php:8.2 security, bug fix, and enhancement update Affected packages: Rocky Linux:9/php、Rocky Linux:9/php-pecl-apcu、Rocky Linux:9/php-pecl-rrd、Rocky Linux:9/php-pecl-xdebug3、Rocky Linux:9/php-pecl-zip Attributes: Fix available、Severity - 5.6 (Medium)
最高第 3 名08:44 达到08:44 首次观测上榜11:08 观测离榜累计约2小时24分 - 39RLSA-2026:48170 · Low: php security, bug fix, and enhancement update
Low: php security, bug fix, and enhancement update Affected packages: Rocky Linux:10/php Attributes: Fix available、Severity - 5.6 (Medium)
最高第 1 名08:44 达到08:44 首次观测上榜11:08 观测离榜累计约2小时24分 - 40RLSA-2026:48197 · Low: php:8.3 security, bug fix, and enhancement update
Low: php:8.3 security, bug fix, and enhancement update Affected packages: Rocky Linux:9/php、Rocky Linux:9/php-pecl-apcu、Rocky Linux:9/php-pecl-redis6、Rocky Linux:9/php-pecl-rrd、Rocky Linux:9/php-pecl-xdebug3、... 1 more Attributes: Fix available、Severity - 5.6 (Medium)
最高第 4 名08:44 达到08:44 首次观测上榜11:08 观测离榜累计约2小时24分 - 41RLSA-2026:49914 · Low: php8.4 security, bug fix, and enhancement update
Low: php8.4 security, bug fix, and enhancement update Affected packages: Rocky Linux:10/php8.4 Attributes: Fix available、Severity - 5.6 (Medium)
最高第 2 名08:44 达到08:44 首次观测上榜11:08 观测离榜累计约2小时24分 - 42CVE-2026-19785 · francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection
francoisjacquet RosarioSIS Student Medical Medical.inc.php sql injection Affected packages: github.com/francoisjacquet/rosariosis Attributes: No fix available、Severity - 5.3 (Medium)
最高第 11 名12:12 达到12:12 首次观测上榜14:36 观测离榜累计约2小时24分 - 43ROOT-APP-MAVEN-CVE-2025-11143 · CVE-2025-11143 in org.eclipse.jetty:jetty-http - Patched by Root
CVE-2025-11143 in org.eclipse.jetty:jetty-http - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty:jetty-http、Root:Maven/org.eclipse.jetty:jetty-http Attributes: Fix available、Severity - 3.7 (Low)
最高第 1 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 44ROOT-APP-MAVEN-CVE-2025-1948 · CVE-2025-1948 in org.eclipse.jetty.http2:jetty-http2-common - Patched by Root
CVE-2025-1948 in org.eclipse.jetty.http2:jetty-http2-common - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty.http2:jetty-http2-common、Root:Maven/org.eclipse.jetty.http2:jetty-http2-common Attributes: Fix available
最高第 2 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 45ROOT-APP-MAVEN-CVE-2025-5115 · CVE-2025-5115 in org.eclipse.jetty.http2:jetty-http2-common - Patched by Root
CVE-2025-5115 in org.eclipse.jetty.http2:jetty-http2-common - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty.http2:jetty-http2-common、Root:Maven/org.eclipse.jetty.http2:jetty-http2-common Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 46ROOT-APP-MAVEN-CVE-2026-10050 · CVE-2026-10050 in org.eclipse.jetty:jetty-security - Patched by Root
CVE-2026-10050 in org.eclipse.jetty:jetty-security - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty:jetty-security、Root:Maven/org.eclipse.jetty:jetty-security Attributes: Fix available
最高第 4 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 47ROOT-APP-MAVEN-CVE-2026-10051 · CVE-2026-10051 in org.eclipse.jetty:jetty-server - Patched by Root
CVE-2026-10051 in org.eclipse.jetty:jetty-server - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty:jetty-server、Root:Maven/org.eclipse.jetty:jetty-server Attributes: Fix available
最高第 5 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 48ROOT-APP-MAVEN-CVE-2026-1605 · CVE-2026-1605 in org.eclipse.jetty:jetty-server - Patched by Root
CVE-2026-1605 in org.eclipse.jetty:jetty-server - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty:jetty-server、Root:Maven/org.eclipse.jetty:jetty-server Attributes: Fix available、Severity - 7.5 (High)
最高第 6 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 49ROOT-APP-MAVEN-CVE-2026-2332 · CVE-2026-2332 in org.eclipse.jetty:jetty-http - Patched by Root
CVE-2026-2332 in org.eclipse.jetty:jetty-http - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty:jetty-http、Root:Maven/org.eclipse.jetty:jetty-http Attributes: Fix available、Severity - 7.4 (High)
最高第 7 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分 - 50ROOT-APP-MAVEN-CVE-2026-5795 · CVE-2026-5795 in org.eclipse.jetty.ee10:jetty-ee10-jaspi - Patched by Root
CVE-2026-5795 in org.eclipse.jetty.ee10:jetty-ee10-jaspi - Patched by Root Affected packages: Root:Maven/io.root.org.eclipse.jetty.ee10:jetty-ee10-jaspi、Root:Maven/org.eclipse.jetty.ee10:jetty-ee10-jaspi Attributes: Fix available
最高第 8 名07:24 达到07:24 首次观测上榜09:48 观测离榜累计约2小时24分


































































































