
OSV.dev · 实时热榜
- 01BIT-powershell-2026-70338 · Microsoft PowerShell Security Feature Bypass Vulnerability
Microsoft PowerShell Security Feature Bypass Vulnerability Affected packages: Bitnami/powershell Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名20:27 达到20:27 首次观测上榜21:31 观测离榜累计约1小时4分 - 02CLSA-2026-1786946462 · TuxCare security update for pypdf (5 CVEs)
TuxCare security update for pypdf (5 CVEs) Affected packages: TuxCare:PyPI/pypdf Attributes: Fix available
最高第 1 名14:51 达到14:51 首次观测上榜16:11 观测离榜累计约1小时20分 - 03DEBIAN-CVE-2026-18724 · Debian:11/open-iscsi
Affected packages: Debian:11/open-iscsi、Debian:12/open-iscsi、Debian:13/open-iscsi、Debian:14/open-iscsi Attributes: No fix available
最高第 1 名17:15 达到17:15 首次观测上榜18:35 观测离榜累计约1小时20分 - 04DEBIAN-CVE-2026-72888 · Debian:11/libnet-oauth-perl
Affected packages: Debian:11/libnet-oauth-perl、Debian:12/libnet-oauth-perl、Debian:13/libnet-oauth-perl、Debian:14/libnet-oauth-perl Attributes: No fix available
最高第 1 名00:11 达到00:11 首次观测上榜04:11 观测离榜累计约4小时 - 05DEBIAN-CVE-2026-74579 · Debian:11/linux
Affected packages: Debian:11/linux、Debian:12/linux、Debian:13/linux、Debian:14/linux Attributes: Fix available
最高第 1 名16:11 达到16:11 首次观测上榜16:59 观测离榜累计约48分钟 - 06ECHO-48b4-f133-d141 · Echo/lvm2
Affected packages: Echo/lvm2 Attributes: No fix available
最高第 1 名16:27 达到16:27 首次观测上榜16:59 观测离榜累计约32分钟 - 07ECHO-67da-49b3-07ec · Echo/openssl
Affected packages: Echo/openssl Attributes: No fix available
最高第 1 名15:55 达到15:55 首次观测上榜16:11 观测离榜累计约16分钟 - 08ECHO-fc20-8bd8-847a · Echo/cjson
Affected packages: Echo/cjson Attributes: No fix available
最高第 1 名05:47 达到05:47 首次观测上榜10:03 观测离榜累计约4小时16分 - 09GHSA-m44r-7c5h-m6mj · Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage Affected packages: npm/@medplum/core Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名21:47 达到21:47 首次观测上榜22:19 观测离榜累计约32分钟 - 10JLSEC-2026-1330 · Julia/LibCURL_jll
Affected packages: Julia/LibCURL_jll Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名21:31 达到21:31 首次观测上榜22:19 观测离榜累计约48分钟 - 11MAL-2026-14069 · Malicious code in kb-ai (PyPI)
Malicious code in kb-ai (PyPI) Affected packages: PyPI/kb-ai Attributes: No fix available
最高第 1 名03:55 达到03:55 首次观测上榜10:03 观测离榜累计约6小时8分 - 12MAL-2026-14070 · Malicious code in @ai-vertical/ai-agent (npm)
Malicious code in @ai-vertical/ai-agent (npm) Affected packages: npm/@ai-vertical/ai-agent Attributes: No fix available
最高第 1 名13:15 达到13:15 首次观测上榜16:11 观测离榜累计约2小时56分 - 13MINI-2q95-wf8g-qrf3 · MinimOS/victoriatraces
Affected packages: MinimOS/victoriatraces Attributes: Fix available
最高第 1 名10:03 达到10:03 首次观测上榜16:11 观测离榜累计约6小时8分 - 14MINI-43jq-rjj6-qmxf · MinimOS/yet-another-cloudwatch-exporter-fips
Affected packages: MinimOS/yet-another-cloudwatch-exporter-fips Attributes: Fix available
最高第 1 名22:51 达到22:51 首次观测上榜当日结束时仍在榜累计约1小时4分 - 15MINI-5cqf-m8m5-j8c8 · MinimOS/argo-rollouts-fips
Affected packages: MinimOS/argo-rollouts-fips、MinimOS/kubectl-argo-rollouts-fips Attributes: Fix available
最高第 1 名22:19 达到22:19 首次观测上榜22:35 观测离榜累计约16分钟 - 16MINI-cjv8-v6pc-vrhq · MinimOS/frankenphp-fips-8.5
Affected packages: MinimOS/frankenphp-fips-8.5 Attributes: No fix available
最高第 1 名17:47 达到17:47 首次观测上榜18:35 观测离榜累计约48分钟 - 17MINI-f9v7-c3pj-cxjr · MinimOS/frankenphp-8.4
Affected packages: MinimOS/frankenphp-8.4 Attributes: No fix available
最高第 1 名17:31 达到17:31 首次观测上榜18:35 观测离榜累计约1小时4分 - 18MINI-jw45-54cx-62x2 · MinimOS/tdbg-fips-1.28
Affected packages: MinimOS/tdbg-fips-1.28、MinimOS/temporal-cassandra-tool-fips-1.28、MinimOS/temporal-server-fips-1.28、MinimOS/temporal-sql-tool-fips-1.28 Attributes: Fix available
最高第 1 名22:35 达到22:35 首次观测上榜22:51 观测离榜累计约16分钟 - 19MINI-xjgr-8rpq-g9vf · MinimOS/freerdp-2-libs
Affected packages: MinimOS/freerdp-2-libs Attributes: No fix available
最高第 1 名16:59 达到16:59 首次观测上榜17:47 观测离榜累计约48分钟 - 20OSEC-2026-17 · Timing leak in NIST elliptic curves scalar multiplication
Timing leak in NIST elliptic curves scalar multiplication Affected packages: github.com/mirage/mirage-crypto、opam/mirage-crypto-ec Attributes: Fix available、Severity - 5.9 (Medium)
最高第 1 名18:19 达到18:19 首次观测上榜18:35 观测离榜累计约16分钟 - 21RHSA-2026:55450 · Red Hat Security Advisory: curl security update
Red Hat Security Advisory: curl security update Affected packages: Red Hat:enterprise_linux:10.2/curl、Red Hat:enterprise_linux:10.2/curl-debuginfo、Red Hat:enterprise_linux:10.2/curl-debugsource、Red Hat:enterprise_linux:10.2/libcurl、Red Hat:enterprise_linux:10.2/libcurl-debuginfo、... 3 more Attributes: Fix available、Severity - 8.1 (High)
最高第 1 名18:35 达到18:35 首次观测上榜19:07 观测离榜累计约32分钟 - 22ROOT-APP-MAVEN-CVE-2026-22735 · CVE-2026-22735 in org.springframework:spring-webflux - Patched by Root
CVE-2026-22735 in org.springframework:spring-webflux - Patched by Root Affected packages: Root:Maven/io.root.org.springframework:spring-webflux、Root:Maven/io.root.org.springframework:spring-webmvc、Root:Maven/org.springframework:spring-webflux、Root:Maven/org.springframework:spring-webmvc Attributes: Fix available、Severity - 2.6 (Low)
最高第 1 名23:23 达到23:23 首次观测上榜当日结束时仍在榜累计约32分钟 - 23ROOT-APP-NPM-CVE-2023-26133 · CVE-2023-26133 in progressbar.js - Patched by Root
CVE-2023-26133 in progressbar.js - Patched by Root Affected packages: Root:npm/@rootio/progressbar.js、Root:npm/progressbar.js Attributes: Fix available
最高第 1 名00:00 达到当日首次采集时已在榜04:11 观测离榜累计约4小时12分 - 24ROOT-APP-NPM-CVE-2025-59471 · CVE-2025-59471 in next - Patched by Root
CVE-2025-59471 in next - Patched by Root Affected packages: Root:npm/@rootio/next、Root:npm/next Attributes: Fix available
最高第 1 名21:15 达到21:15 首次观测上榜21:47 观测离榜累计约32分钟 - 25ROOT-APP-PYPI-CVE-2026-25990 · CVE-2026-25990 in pillow - Patched by Root
CVE-2026-25990 in pillow - Patched by Root Affected packages: Root:PyPI/pillow、Root:PyPI/rootio-pillow Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名19:07 达到19:07 首次观测上榜21:15 观测离榜累计约2小时8分 - 26BIT-powershell-2026-70337 · Microsoft PowerShell Remote Code Execution Vulnerability
Microsoft PowerShell Remote Code Execution Vulnerability Affected packages: Bitnami/powershell Attributes: Fix available、Severity - 8.8 (High)
最高第 2 名20:27 达到20:27 首次观测上榜21:31 观测离榜累计约1小时4分 - 27CLSA-2026-1786944250 · TuxCare security update for pyjwt (2 CVEs)
TuxCare security update for pyjwt (2 CVEs) Affected packages: TuxCare:PyPI/pyjwt Attributes: Fix available
最高第 2 名14:51 达到14:51 首次观测上榜16:11 观测离榜累计约1小时20分 - 28DEBIAN-CVE-2026-18725 · Debian:11/open-iscsi
Affected packages: Debian:11/open-iscsi、Debian:12/open-iscsi、Debian:13/open-iscsi、Debian:14/open-iscsi Attributes: No fix available
最高第 2 名17:15 达到17:15 首次观测上榜18:35 观测离榜累计约1小时20分 - 29DEBIAN-CVE-2026-72887 · Debian:11/libnet-oauth-perl
Affected packages: Debian:11/libnet-oauth-perl、Debian:12/libnet-oauth-perl、Debian:13/libnet-oauth-perl、Debian:14/libnet-oauth-perl Attributes: No fix available
最高第 2 名00:11 达到00:11 首次观测上榜04:11 观测离榜累计约4小时 - 30GHSA-2qvg-qr73-mqxp · conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target Affected packages: GitHub Actions/wktk/conflibot Attributes: Fix available、Severity - 9.1 (Critical)
最高第 2 名21:47 达到21:47 首次观测上榜22:19 观测离榜累计约32分钟 - 31JLSEC-2026-1331 · Julia/LibCURL_jll
Affected packages: Julia/LibCURL_jll Attributes: Fix available、Severity - 7.8 (High)
最高第 2 名21:31 达到21:31 首次观测上榜22:19 观测离榜累计约48分钟 - 32MINI-495p-qxrv-7p5c · MinimOS/yet-another-cloudwatch-exporter-fips
Affected packages: MinimOS/yet-another-cloudwatch-exporter-fips Attributes: Fix available
最高第 2 名22:51 达到22:51 首次观测上榜当日结束时仍在榜累计约1小时4分 - 33MINI-5ghm-x737-vg6w · MinimOS/victoriatraces
Affected packages: MinimOS/victoriatraces Attributes: Fix available
最高第 2 名10:03 达到10:03 首次观测上榜16:11 观测离榜累计约6小时8分 - 34MINI-5m7v-cgq9-x3cc · MinimOS/argo-rollouts-fips
Affected packages: MinimOS/argo-rollouts-fips、MinimOS/kubectl-argo-rollouts-fips Attributes: Fix available
最高第 2 名22:19 达到22:19 首次观测上榜22:35 观测离榜累计约16分钟 - 35MINI-5mfg-ghrg-r6cr · MinimOS/zot
Affected packages: MinimOS/zot Attributes: Fix available
最高第 2 名04:11 达到04:11 首次观测上榜10:03 观测离榜累计约5小时52分 - 36MINI-6685-9wf8-jf4h · MinimOS/rabbitmq-cluster-operator-fips
Affected packages: MinimOS/rabbitmq-cluster-operator-fips Attributes: Fix available
最高第 2 名16:11 达到16:11 首次观测上榜16:27 观测离榜累计约16分钟 - 37MINI-g56v-3pwg-2p7c · MinimOS/tdbg-1.29
Affected packages: MinimOS/tdbg-1.29、MinimOS/temporal-cassandra-tool-1.29、MinimOS/temporal-server-1.29、MinimOS/temporal-sql-tool-1.29 Attributes: Fix available
最高第 2 名22:35 达到22:35 首次观测上榜22:51 观测离榜累计约16分钟 - 38MINI-pfcq-gjm4-cvfx · MinimOS/freerdp-2
Affected packages: MinimOS/freerdp-2 Attributes: Fix available
最高第 2 名00:00 达到当日首次采集时已在榜04:11 观测离榜累计约4小时12分 - 39MINI-q5mj-444m-4359 · MinimOS/frankenphp-fips-8.4
Affected packages: MinimOS/frankenphp-fips-8.4 Attributes: No fix available
最高第 2 名17:47 达到17:47 首次观测上榜18:35 观测离榜累计约48分钟 - 40MINI-qjvg-c249-jjqc · MinimOS/freerdp-2
Affected packages: MinimOS/freerdp-2 Attributes: No fix available
最高第 2 名16:59 达到16:59 首次观测上榜17:47 观测离榜累计约48分钟 - 41MINI-x54f-2vh3-477c · MinimOS/frankenphp-8.3
Affected packages: MinimOS/frankenphp-8.3 Attributes: No fix available
最高第 2 名17:31 达到17:31 首次观测上榜18:35 观测离榜累计约1小时4分 - 42RHSA-2026:55448 · Red Hat Security Advisory: libXfont2 security update
Red Hat Security Advisory: libXfont2 security update Affected packages: Red Hat:enterprise_linux:10.2/libXfont2、Red Hat:enterprise_linux:10.2/libXfont2-debuginfo、Red Hat:enterprise_linux:10.2/libXfont2-debugsource、Red Hat:enterprise_linux:10.2/libXfont2-devel Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名18:35 达到18:35 首次观测上榜19:07 观测离榜累计约32分钟 - 43ROOT-APP-MAVEN-CVE-2026-22737 · CVE-2026-22737 in org.springframework:spring-webmvc - Patched by Root
CVE-2026-22737 in org.springframework:spring-webmvc - Patched by Root Affected packages: Root:Maven/io.root.org.springframework:spring-webflux、Root:Maven/io.root.org.springframework:spring-webmvc、Root:Maven/org.springframework:spring-webflux、Root:Maven/org.springframework:spring-webmvc Attributes: Fix available、Severity - 5.9 (Medium)
最高第 2 名23:23 达到23:23 首次观测上榜当日结束时仍在榜累计约32分钟 - 44ROOT-APP-NPM-CVE-2026-64647 · CVE-2026-64647 in next - Patched by Root
CVE-2026-64647 in next - Patched by Root Affected packages: Root:npm/@rootio/next、Root:npm/next Attributes: Fix available
最高第 2 名21:15 达到21:15 首次观测上榜21:47 观测离榜累计约32分钟 - 45ROOT-APP-PYPI-CVE-2026-40192 · CVE-2026-40192 in pillow - Patched by Root
CVE-2026-40192 in pillow - Patched by Root Affected packages: Root:PyPI/pillow、Root:PyPI/rootio-pillow Attributes: Fix available、Severity - 7.5 (High)
最高第 2 名19:07 达到19:07 首次观测上榜21:15 观测离榜累计约2小时8分 - 46BIT-golang-2026-46600 · Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage Affected packages: Bitnami/golang Attributes: Fix available、Severity - 7.5 (High)
最高第 3 名20:27 达到20:27 首次观测上榜21:31 观测离榜累计约1小时4分 - 47CLSA-2026-1786943805 · TuxCare security update for org.apache.activemq (1 CVE)
TuxCare security update for org.apache.activemq (1 CVE) Affected packages: TuxCare:Maven/org.apache.activemq:activemq-branding、TuxCare:Maven/org.apache.activemq:apache-artemis、TuxCare:Maven/org.apache.activemq:artemis-amqp-protocol、TuxCare:Maven/org.apache.activemq:artemis-bom、TuxCare:Maven/org.apache.activemq:artemis-boot、... 50 more Attributes: Fix available
最高第 3 名14:51 达到14:51 首次观测上榜16:11 观测离榜累计约1小时20分 - 48GHSA-ggr8-5vv4-36mx · DeepmergeTS has stack exhaustion when merging recursive object graphs
DeepmergeTS has stack exhaustion when merging recursive object graphs Affected packages: npm/deepmerge-ts Attributes: Fix available、Severity - 8.2 (High)
最高第 3 名21:47 达到21:47 首次观测上榜22:19 观测离榜累计约32分钟 - 49JLSEC-2026-1332 · Julia/LibCURL_jll
Affected packages: Julia/LibCURL_jll Attributes: Fix available、Severity - 3.7 (Low)
最高第 3 名21:31 达到21:31 首次观测上榜22:19 观测离榜累计约48分钟 - 50MINI-2pjr-r396-xg55 · MinimOS/yq
Affected packages: MinimOS/yq Attributes: Fix available
最高第 3 名16:27 达到16:27 首次观测上榜16:59 观测离榜累计约32分钟


































































































