
OSV.dev · 实时热榜
- 01DEBIAN-CVE-2026-12074 · Debian:11/nltk
Affected packages: Debian:11/nltk、Debian:12/nltk、Debian:13/nltk、Debian:14/nltk Attributes: No fix available
最高第 1 名01:02 达到01:02 首次观测上榜03:58 观测离榜累计约2小时56分 - 02DEBIAN-CVE-2026-53802 · Debian:11/rsync
Affected packages: Debian:11/rsync、Debian:12/rsync、Debian:13/rsync、Debian:14/rsync Attributes: No fix available
最高第 1 名14:06 达到14:06 首次观测上榜15:59 观测离榜累计约1小时52分 - 03ECHO-0f77-53c4-f946 · Echo:PyPi/h2
Affected packages: Echo:PyPi/h2 Attributes: Fix available
最高第 1 名08:46 达到08:46 首次观测上榜10:22 观测离榜累计约1小时36分 - 04ECHO-4f46-4ddd-9dfd · Echo/rsync
Affected packages: Echo/rsync Attributes: No fix available
最高第 1 名21:18 达到21:18 首次观测上榜21:51 观测离榜累计约32分钟 - 05ECHO-dd45-764e-65f0 · Echo/qemu
Affected packages: Echo/qemu Attributes: No fix available
最高第 1 名16:30 达到16:30 首次观测上榜18:06 观测离榜累计约1小时36分 - 06EEF-CVE-2026-67579 · Filter expression injection via forged keyset pagination cursor in Ash
Filter expression injection via forged keyset pagination cursor in Ash Affected packages: Hex/ash、github.com/ash-project/ash Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名04:31 达到04:31 首次观测上榜06:54 观测离榜累计约2小时24分 - 07GHSA-49m4-vp58-wgc9 · MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` Affected packages: PyPI/stata-mcp Attributes: Fix available、Severity - 8.4 (High)
最高第 1 名03:42 达到03:42 首次观测上榜06:54 观测离榜累计约3小时12分 - 08GHSA-cxgv-hp74-jj7r · Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv)
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) Affected packages: PyPI/ansible-jailexec Attributes: Fix available、Severity - 7.3 (High)
最高第 1 名07:42 达到07:42 首次观测上榜10:22 观测离榜累计约2小时40分 - 09GHSA-fjgc-3mj7-8rg8 · ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header Affected packages: npm/ep_etherpad-lite Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名22:06 达到22:06 首次观测上榜22:38 观测离榜累计约32分钟 - 10GHSA-pfvm-w89x-94jw · SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS)
SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS) Affected packages: NuGet/SIPSorcery Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名03:58 达到03:58 首次观测上榜06:54 观测离榜累计约2小时56分 - 11GHSA-rm43-82j9-r4mj · atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read Affected packages: PyPI/atomic-agents-stack Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名22:38 达到22:38 首次观测上榜当日结束时仍在榜累计约1小时20分 - 12GHSA-vqfp-p66c-xrp9 · ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token Affected packages: npm/ep_etherpad-lite Attributes: Fix available、Severity - 6.8 (Medium)
最高第 1 名22:22 达到22:22 首次观测上榜当日结束时仍在榜累计约1小时36分 - 13JLSEC-2026-1262 · In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are...
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are... Affected packages: Julia/wxWidgets_jll Attributes: No fix available、Severity - 3.7 (Low)
最高第 1 名00:00 达到当日首次采集时已在榜01:02 观测离榜累计约1小时3分 - 14JLSEC-2026-1266 · Julia/opusfile_jll
Affected packages: Julia/opusfile_jll Attributes: No fix available、Severity - 7.8 (High)
最高第 1 名00:30 达到00:30 首次观测上榜03:58 观测离榜累计约3小时28分 - 15JLSEC-2026-1267 · A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function...
A vulnerability was identified in uclouvain openjpeg up to 2.5.4. This impacts the function... Affected packages: Julia/OpenJpeg_jll Attributes: No fix available、Severity - 1.9 (Low)
最高第 1 名00:47 达到00:47 首次观测上榜03:58 观测离榜累计约3小时12分 - 16JLSEC-2026-1268 · Cap'n Proto and its Rust implementation vulnerable to out-of-bounds read due to logic error handling list-of-list
Cap'n Proto and its Rust implementation vulnerable to out-of-bounds read due to logic error handling list-of-list Affected packages: Julia/capnproto_jll Attributes: No fix available、Severity - 5.4 (Medium)
最高第 1 名04:14 达到04:14 首次观测上榜06:54 观测离榜累计约2小时40分 - 17JLSEC-2026-1271 · Julia/cryptopp_jll
Affected packages: Julia/cryptopp_jll Attributes: No fix available、Severity - 5.9 (Medium)
最高第 1 名14:39 达到14:39 首次观测上榜15:59 观测离榜累计约1小时20分 - 18JLSEC-2026-1276 · Julia/Graphviz_jll
Affected packages: Julia/Graphviz_jll Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名17:51 达到17:51 首次观测上榜18:39 观测离榜累计约48分钟 - 19JLSEC-2026-1281 · Julia/ruby_jll
Affected packages: Julia/ruby_jll Attributes: No fix available、Severity - 7.5 (High)
最高第 1 名18:06 达到18:06 首次观测上榜18:39 观测离榜累计约32分钟 - 20JLSEC-2026-1292 · Julia/libconfuse_jll
Affected packages: Julia/libconfuse_jll Attributes: No fix available、Severity - 8.8 (High)
最高第 1 名19:10 达到19:10 首次观测上榜20:30 观测离榜累计约1小时20分 - 21JLSEC-2026-1302 · Julia/Libcroco_jll
Affected packages: Julia/Libcroco_jll Attributes: No fix available、Severity - 7.1 (High)
最高第 1 名20:46 达到20:46 首次观测上榜21:18 观测离榜累计约32分钟 - 22MAL-2026-13923 · Malicious code in tailwind-form-templates (npm)
Malicious code in tailwind-form-templates (npm) Affected packages: npm/tailwind-form-templates Attributes: No fix available
最高第 1 名00:15 达到00:15 首次观测上榜02:23 观测离榜累计约2小时8分 - 23MAL-2026-13927 · Malicious code in svelte-kit-vim (npm)
Malicious code in svelte-kit-vim (npm) Affected packages: npm/svelte-kit-vim Attributes: No fix available
最高第 1 名01:51 达到01:51 首次观测上榜03:58 观测离榜累计约2小时8分 - 24MAL-2026-13928 · Malicious code in internallib_v756 (npm)
Malicious code in internallib_v756 (npm) Affected packages: npm/internallib_v756 Attributes: No fix available
最高第 1 名05:02 达到05:02 首次观测上榜06:54 观测离榜累计约1小时52分 - 25MAL-2026-13934 · Malicious code in ai-analyzer (npm)
Malicious code in ai-analyzer (npm) Affected packages: npm/ai-analyzer Attributes: No fix available
最高第 1 名23:43 达到23:43 首次观测上榜当日结束时仍在榜累计约16分钟 - 26MINI-42rf-6f3j-w25w · MinimOS/apisix-ingress-controller-fips
Affected packages: MinimOS/apisix-ingress-controller-fips Attributes: Fix available
最高第 1 名15:59 达到15:59 首次观测上榜18:06 观测离榜累计约2小时8分 - 27MINI-4gwv-r9jv-8xj2 · MinimOS/elasticsearch-fips-9.3
Affected packages: MinimOS/elasticsearch-fips-9.3 Attributes: No fix available
最高第 1 名21:51 达到21:51 首次观测上榜22:06 观测离榜累计约16分钟 - 28MINI-r2g6-2626-p6j5 · MinimOS/podman
Affected packages: MinimOS/podman Attributes: Fix available
最高第 1 名10:22 达到10:22 首次观测上榜14:06 观测离榜累计约3小时44分 - 29RHSA-2026:54517 · Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update Affected packages: Red Hat:hummingbird:1/grafana13.1 Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:39 达到18:39 首次观测上榜20:30 观测离榜累计约1小时52分 - 30RLSA-2026:47126 · Moderate: resource-agents security update
Moderate: resource-agents security update Affected packages: Rocky Linux:8/resource-agents Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名02:38 达到02:38 首次观测上榜03:58 观测离榜累计约1小时20分 - 31RLSA-2026:54210 · Moderate: dhcpcd security update
Moderate: dhcpcd security update Affected packages: Rocky Linux:10/dhcpcd Attributes: Fix available、Severity - 6.5 (Medium)
最高第 1 名20:30 达到20:30 首次观测上榜21:18 观测离榜累计约48分钟 - 32ROOT-OS-UBUNTU-2204-CVE-2013-7445 · CVE-2013-7445 in linux - Patched by Root
CVE-2013-7445 in linux - Patched by Root Affected packages: Root:Ubuntu:22.04/linux、Root:Ubuntu:22.04/rootio-linux Attributes: Fix available
最高第 1 名06:54 达到06:54 首次观测上榜10:22 观测离榜累计约3小时28分 - 33DEBIAN-CVE-2026-12061 · Debian:11/nltk
Affected packages: Debian:11/nltk、Debian:12/nltk、Debian:13/nltk、Debian:14/nltk Attributes: No fix available
最高第 2 名01:02 达到01:02 首次观测上榜03:58 观测离榜累计约2小时56分 - 34DEBIAN-CVE-2026-70456 · Debian:11/rsync
Affected packages: Debian:11/rsync、Debian:12/rsync、Debian:13/rsync、Debian:14/rsync Attributes: No fix available
最高第 2 名14:06 达到14:06 首次观测上榜15:59 观测离榜累计约1小时52分 - 35ECHO-2923-d825-c1f1 · Echo/rsync
Affected packages: Echo/rsync Attributes: No fix available
最高第 2 名21:18 达到21:18 首次观测上榜21:51 观测离榜累计约32分钟 - 36ECHO-5e25-20a4-1de0 · Echo:PyPi/redshift-connector
Affected packages: Echo:PyPi/redshift-connector Attributes: Fix available
最高第 2 名08:46 达到08:46 首次观测上榜10:22 观测离榜累计约1小时36分 - 37GHSA-2jwf-f4xq-f24h · ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite Affected packages: npm/ep_etherpad-lite Attributes: Fix available、Severity - 4.2 (Medium)
最高第 2 名22:22 达到22:22 首次观测上榜当日结束时仍在榜累计约1小时36分 - 38GHSA-2mhj-fhvg-v428 · Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name Affected packages: Packagist/pimcore/pimcore Attributes: Fix available、Severity - 8.5 (High)
最高第 2 名22:06 达到22:06 首次观测上榜22:38 观测离榜累计约32分钟 - 39GHSA-h47f-gmjp-m7rr · compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 Affected packages: PyPI/compliance-trestle Attributes: Fix available、Severity - 8.6 (High)
最高第 2 名00:00 达到当日首次采集时已在榜01:02 观测离榜累计约1小时3分 - 40GHSA-h7p7-w5gc-xj3w · Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials Affected packages: PyPI/pydantic-ai、PyPI/pydantic-ai-slim Attributes: Fix available、Severity - 6.8 (Medium)
最高第 2 名22:38 达到22:38 首次观测上榜当日结束时仍在榜累计约1小时20分 - 41GHSA-jwjp-4649-v8jp · SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing
SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing Affected packages: NuGet/SIPSorcery Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名03:58 达到03:58 首次观测上榜06:54 观测离榜累计约2小时56分 - 42GHSA-w62w-66v9-vvgv · SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access
SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access Affected packages: Go/github.com/seaweedfs/seaweedfs Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名03:42 达到03:42 首次观测上榜03:58 观测离榜累计约16分钟 - 43JLSEC-2026-1264 · GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file...
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file... Affected packages: Julia/Gzip_jll Attributes: No fix available、Severity - 2.0 (Low)
最高第 2 名00:30 达到00:30 首次观测上榜03:58 观测离榜累计约3小时28分 - 44JLSEC-2026-1269 · Julia/capnproto_jll
Affected packages: Julia/capnproto_jll Attributes: No fix available、Severity - 6.3 (Medium)
最高第 2 名04:14 达到04:14 首次观测上榜06:54 观测离榜累计约2小时40分 - 45JLSEC-2026-1272 · Julia/cryptopp_jll
Affected packages: Julia/cryptopp_jll Attributes: No fix available、Severity - 7.5 (High)
最高第 2 名14:39 达到14:39 首次观测上榜15:59 观测离榜累计约1小时20分 - 46JLSEC-2026-1277 · Julia/Soup3_jll
Affected packages: Julia/Soup3_jll Attributes: No fix available、Severity - 7.5 (High)
最高第 2 名17:51 达到17:51 首次观测上榜18:39 观测离榜累计约48分钟 - 47JLSEC-2026-1282 · Julia/ruby_jll
Affected packages: Julia/ruby_jll Attributes: No fix available、Severity - 7.5 (High)
最高第 2 名18:06 达到18:06 首次观测上榜18:39 观测离榜累计约32分钟 - 48JLSEC-2026-1293 · Julia/flex_jll
Affected packages: Julia/flex_jll Attributes: No fix available、Severity - 5.5 (Medium)
最高第 2 名19:10 达到19:10 首次观测上榜20:30 观测离榜累计约1小时20分 - 49MAL-2026-13922 · Malicious code in passkeys-react (npm)
Malicious code in passkeys-react (npm) Affected packages: npm/passkeys-react Attributes: No fix available
最高第 2 名00:15 达到00:15 首次观测上榜02:23 观测离榜累计约2小时8分 - 50MAL-2026-13926 · Malicious code in sui-gql (npm)
Malicious code in sui-gql (npm) Affected packages: npm/sui-gql Attributes: No fix available
最高第 2 名01:51 达到01:51 首次观测上榜03:58 观测离榜累计约2小时8分


































































































