
OSV.dev · 实时热榜
- 01UBUNTU-CVE-2026-75803 · Ubuntu:22.04:LTS/openssl
Affected packages: Ubuntu:22.04:LTS/openssl、Ubuntu:24.04:LTS/edk2、Ubuntu:24.04:LTS/openssl、Ubuntu:26.04:LTS/edk2、Ubuntu:26.04:LTS/openssl、... 7 more Attributes: No fix available
最高第 1 名00:00 达到当日首次采集时已在榜12:06 观测离榜累计约12小时6分 - 02CVE-2026-72697 · Grav CMS before 2.0.16 Path Traversal via media_directory
Grav CMS before 2.0.16 Path Traversal via media_directory Affected packages: github.com/getgrav/grav Attributes: Fix available、Severity - 7.1 (High)
最高第 16 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 03CVE-2026-72698 · Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass
Grav CMS before 2.0.16 Information Disclosure via Twig Sandbox Bypass Affected packages: github.com/getgrav/grav Attributes: Fix available、Severity - 7.1 (High)
最高第 15 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 04CVE-2026-72701 · Grav CMS before 2.0.16 Timing Attack via verifyNonce
Grav CMS before 2.0.16 Timing Attack via verifyNonce Affected packages: github.com/getgrav/grav Attributes: Fix available、Severity - 6.3 (Medium)
最高第 14 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 05CVE-2026-72702 · Grav CMS before 2.0.16 Origin Validation Bypass via Referer
Grav CMS before 2.0.16 Origin Validation Bypass via Referer Affected packages: github.com/getgrav/grav Attributes: Fix available、Severity - 9.3 (Critical)
最高第 13 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 06CVE-2026-75575 · Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method
Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method Affected packages: github.com/rocketchat/rocket.chat Attributes: Fix available、Severity - 6.9 (Medium)
最高第 12 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 07CVE-2026-76839 · Grav before 2.0.16 Information Disclosure via offsetGet
Grav before 2.0.16 Information Disclosure via offsetGet Affected packages: github.com/getgrav/grav Attributes: Fix available、Severity - 8.7 (High)
最高第 11 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 08CVE-2026-76846 · Grav before 2.0.16 Information Disclosure via Twig Sandbox
Grav before 2.0.16 Information Disclosure via Twig Sandbox Affected packages: github.com/getgrav/grav Attributes: Fix available、Severity - 8.7 (High)
最高第 10 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 09CVE-2026-78675 · GitPython before 3.1.59 Local File Content Disclosure via .gitmodules
GitPython before 3.1.59 Local File Content Disclosure via .gitmodules Affected packages: github.com/gitpython-developers/gitpython Attributes: Fix available、Severity - 8.6 (High)
最高第 9 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 10CVE-2026-78676 · GitPython before 3.1.59 Remote Code Execution via Config Injection
GitPython before 3.1.59 Remote Code Execution via Config Injection Affected packages: github.com/gitpython-developers/gitpython Attributes: Fix available、Severity - 9.3 (Critical)
最高第 8 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 11CVE-2026-78677 · GitPython before 3.1.59 Path Traversal via separate-git-dir
GitPython before 3.1.59 Path Traversal via separate-git-dir Affected packages: github.com/gitpython-developers/gitpython Attributes: Fix available、Severity - 8.7 (High)
最高第 7 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 12CVE-2026-78678 · GitPython before 3.1.59 Arbitrary File Read via Repo.blame()
GitPython before 3.1.59 Arbitrary File Read via Repo.blame() Affected packages: github.com/gitpython-developers/gitpython Attributes: Fix available、Severity - 7.1 (High)
最高第 6 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 13CVE-2026-78679 · GitPython before 3.1.59 Arbitrary File Read via TagReference.create
GitPython before 3.1.59 Arbitrary File Read via TagReference.create Affected packages: github.com/gitpython-developers/gitpython Attributes: Fix available、Severity - 7.1 (High)
最高第 5 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 14CVE-2026-78680 · NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary
NLTK before 3.10.3 Arbitrary Code Execution via Graphviz dot Binary Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 8.5 (High)
最高第 4 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 15CVE-2026-78681 · NLTK before 3.10.3 Entity Expansion DoS via ElementTree
NLTK before 3.10.3 Entity Expansion DoS via ElementTree Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 8.7 (High)
最高第 3 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 16CVE-2026-78682 · NLTK before 3.10.3 SSRF Protection Bypass via Proxy
NLTK before 3.10.3 SSRF Protection Bypass via Proxy Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 8.7 (High)
最高第 2 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 17CVE-2026-78683 · NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization
NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 9.4 (Critical)
最高第 1 名12:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分 - 18EEF-CVE-2026-75542 · OAuth token exchange grants repository scopes for organizations the principal cannot access
OAuth token exchange grants repository scopes for organizations the principal cannot access Affected packages: github.com/hexpm/hexpm Attributes: Fix available、Severity - 8.3 (High)
最高第 2 名04:15 达到04:15 首次观测上榜12:06 观测离榜累计约7小时51分 - 19GHSA-3gjw-f78c-vvpw · tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service
tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service Affected packages: crates.io/tokio-postgres Attributes: Fix available、Severity - 6.9 (Medium)
最高第 3 名04:15 达到04:15 首次观测上榜12:06 观测离榜累计约7小时51分 - 20EEF-CVE-2026-75554 · Explicit organization scopes survive token refresh after membership ends
Explicit organization scopes survive token refresh after membership ends Affected packages: github.com/hexpm/hexpm Attributes: Fix available、Severity - 2.3 (Low)
最高第 2 名04:31 达到04:31 首次观测上榜12:06 观测离榜累计约7小时35分 - 21GHSA-8jj7-4v57-frf5 · django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) Affected packages: PyPI/django-cms Attributes: Fix available、Severity - 7.1 (High)
最高第 5 名04:31 达到04:31 首次观测上榜12:06 观测离榜累计约7小时35分 - 22GHSA-fwjf-m4qw-9f2x · django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) Affected packages: PyPI/django-cms Attributes: Fix available、Severity - 4.8 (Medium)
最高第 4 名04:31 达到04:31 首次观测上榜12:06 观测离榜累计约7小时35分 - 23GHSA-4ph6-mjv7-3fq6 · netfoil vulnerable to improper handling of untrusted DoH response data
netfoil vulnerable to improper handling of untrusted DoH response data Affected packages: Go/github.com/tinfoil-factory/netfoil Attributes: Fix available、Severity - 2.7 (Low)
最高第 2 名05:03 达到05:03 首次观测上榜12:06 观测离榜累计约7小时3分 - 24ECHO-b159-47c9-e4c0 · Echo/gst-plugins-good1.0
Affected packages: Echo/gst-plugins-good1.0 Attributes: No fix available
最高第 5 名05:19 达到05:19 首次观测上榜12:06 观测离榜累计约6小时47分 - 25ECHO-f527-df54-bb49 · Echo/gst-plugins-good1.0
Affected packages: Echo/gst-plugins-good1.0 Attributes: No fix available
最高第 6 名05:19 达到05:19 首次观测上榜12:06 观测离榜累计约6小时47分 - 26GHSA-jm48-m3rr-9hgg · 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation Affected packages: Go/github.com/mhsanaei/3x-ui/v2、Go/github.com/mhsanaei/3x-ui/v3 Attributes: Fix available、Severity - 7.2 (High)
最高第 2 名05:19 达到05:19 首次观测上榜12:06 观测离榜累计约6小时47分 - 27GHSA-w67g-5rqw-f597 · Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key Affected packages: Go/github.com/gorilla/websocket Attributes: Fix available、Severity - 6.9 (Medium)
最高第 3 名05:19 达到05:19 首次观测上榜12:06 观测离榜累计约6小时47分 - 28GHSA-xm98-3vcf-fph7 · mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server Affected packages: PyPI/mcp-contextforge-gateway Attributes: Fix available
最高第 2 名03:43 达到03:43 首次观测上榜08:47 观测离榜累计约5小时4分 - 29GHSA-9284-fjc3-fmmj · Sakai Profile Image Deletion has an IDOR
Sakai Profile Image Deletion has an IDOR Affected packages: Maven/org.sakaiproject.profile2:profile2-api、Maven/org.sakaiproject.profile2:profile2-impl Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名03:59 达到03:59 首次观测上榜08:47 观测离榜累计约4小时48分 - 30GHSA-w2x5-gv52-9ccv · Sakai Conversations has a Stored XSS Issue
Sakai Conversations has a Stored XSS Issue Affected packages: Maven/org.sakaiproject.conversations:sakai-conversations-impl、Maven/org.sakaiproject.kernel:sakai-kernel-impl、Maven/org.sakaiproject.rubrics:rubrics-impl Attributes: No fix available、Severity - 8.7 (High)
最高第 3 名03:59 达到03:59 首次观测上榜08:47 观测离榜累计约4小时48分 - 31GHSA-5x78-73v4-xg6w · postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service Affected packages: crates.io/postgres-protocol Attributes: Fix available、Severity - 8.7 (High)
最高第 5 名04:15 达到04:15 首次观测上榜09:03 观测离榜累计约4小时48分 - 32GHSA-rgqc-3x5p-6gwg · postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service Affected packages: crates.io/postgres-protocol Attributes: Fix available、Severity - 6.9 (Medium)
最高第 4 名04:15 达到04:15 首次观测上榜09:03 观测离榜累计约4小时48分 - 33GHSA-fx4f-mhw4-qm7j · vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths
vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths Affected packages: crates.io/vibeio-http Attributes: Fix available、Severity - 6.9 (Medium)
最高第 2 名08:47 达到08:47 首次观测上榜12:06 观测离榜累计约3小时19分 - 34GHSA-vx2m-jpxr-xv7w · Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint Affected packages: Go/github.com/cloudreve/Cloudreve/v4 Attributes: No fix available、Severity - 5.3 (Medium)
最高第 4 名08:47 达到08:47 首次观测上榜12:06 观测离榜累计约3小时19分 - 35GHSA-w8j7-39hp-8x59 · Cloudreve's remote download file paths can escape the selected destination directory
Cloudreve's remote download file paths can escape the selected destination directory Affected packages: Go/github.com/cloudreve/Cloudreve/v4 Attributes: No fix available、Severity - 5.5 (Medium)
最高第 3 名08:47 达到08:47 首次观测上榜12:06 观测离榜累计约3小时19分 - 36DEBIAN-CVE-2026-56135 · Debian:11/ntfs-3g
Affected packages: Debian:11/ntfs-3g、Debian:12/ntfs-3g、Debian:13/ntfs-3g、Debian:14/ntfs-3g Attributes: Fix available
最高第 6 名09:03 达到09:03 首次观测上榜12:06 观测离榜累计约3小时3分 - 37DEBIAN-CVE-2026-56136 · Debian:11/ntfs-3g
Affected packages: Debian:11/ntfs-3g、Debian:12/ntfs-3g、Debian:13/ntfs-3g、Debian:14/ntfs-3g Attributes: Fix available
最高第 5 名09:03 达到09:03 首次观测上榜12:06 观测离榜累计约3小时3分 - 38JLSEC-2026-1387 · A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian...
A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian... Affected packages: Julia/xapian_jll Attributes: No fix available、Severity - 4.4 (Medium)
最高第 2 名02:38 达到02:38 首次观测上榜05:03 观测离榜累计约2小时25分 - 39ROOT-OS-DEBIAN-13-CVE-2026-44168 · CVE-2026-44168 in mariadb - Patched by Root
CVE-2026-44168 in mariadb - Patched by Root Affected packages: Root:Debian:13/mariadb、Root:Debian:13/rootio-mariadb Attributes: Fix available
最高第 3 名02:54 达到02:54 首次观测上榜05:03 观测离榜累计约2小时9分 - 40ROOT-OS-DEBIAN-13-CVE-2026-44169 · CVE-2026-44169 in mariadb - Patched by Root
CVE-2026-44169 in mariadb - Patched by Root Affected packages: Root:Debian:13/mariadb、Root:Debian:13/rootio-mariadb Attributes: Fix available
最高第 4 名02:54 达到02:54 首次观测上榜05:03 观测离榜累计约2小时9分 - 41ROOT-OS-DEBIAN-13-CVE-2026-44170 · CVE-2026-44170 in mariadb - Patched by Root
CVE-2026-44170 in mariadb - Patched by Root Affected packages: Root:Debian:13/mariadb、Root:Debian:13/rootio-mariadb Attributes: Fix available
最高第 5 名02:54 达到02:54 首次观测上榜05:03 观测离榜累计约2小时9分 - 42ROOT-OS-DEBIAN-13-CVE-2026-44171 · CVE-2026-44171 in mariadb - Patched by Root
CVE-2026-44171 in mariadb - Patched by Root Affected packages: Root:Debian:13/mariadb、Root:Debian:13/rootio-mariadb Attributes: Fix available
最高第 6 名02:54 达到02:54 首次观测上榜05:03 观测离榜累计约2小时9分 - 43RLSA-2026:58902 · Important: python3.12 security update
Important: python3.12 security update Affected packages: Rocky Linux:10/python3.12 Attributes: Fix available、Severity - 7.3 (High)
最高第 1 名20:22 达到20:22 首次观测上榜22:15 观测离榜累计约1小时53分 - 44MAL-2026-14421 · Malicious code in @medisend/auth (npm)
Malicious code in @medisend/auth (npm) Affected packages: npm/@medisend/auth Attributes: No fix available
最高第 4 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分 - 45MAL-2026-14422 · Malicious code in @medisend/core (npm)
Malicious code in @medisend/core (npm) Affected packages: npm/@medisend/core Attributes: No fix available
最高第 5 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分 - 46MAL-2026-14423 · Malicious code in @medisend/shared (npm)
Malicious code in @medisend/shared (npm) Affected packages: npm/@medisend/shared Attributes: No fix available
最高第 2 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分 - 47MAL-2026-14424 · Malicious code in @medisend/webview-bridge (npm)
Malicious code in @medisend/webview-bridge (npm) Affected packages: npm/@medisend/webview-bridge Attributes: No fix available
最高第 6 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分 - 48MAL-2026-14425 · Malicious code in auth-otp (npm)
Malicious code in auth-otp (npm) Affected packages: npm/auth-otp Attributes: No fix available
最高第 12 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分 - 49MAL-2026-14426 · Malicious code in babel-polyfill-plugin-corejs2 (npm)
Malicious code in babel-polyfill-plugin-corejs2 (npm) Affected packages: npm/babel-polyfill-plugin-corejs2 Attributes: No fix available
最高第 10 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分 - 50MAL-2026-14427 · Malicious code in chai-as-mno (npm)
Malicious code in chai-as-mno (npm) Affected packages: npm/chai-as-mno Attributes: No fix available
最高第 3 名01:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分


































































































