全部/科技/实时热榜

OSV.dev · 实时热榜

HISTORY2026年8月25日189 不同热搜
08/0309/01 有历史数据
DAILY UNIQUE TOPICS189 个热搜
  1. 01
    BIT-keycloak-2026-17048 · Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api

    Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 4.9 (Medium)

    最高第 120:54 达到20:54 首次观测上榜22:15 观测离榜累计约1小时21分
  2. 02
    BIT-python-2026-19672 · tarfile extraction filter bypass allows creation of directories outside the destination

    tarfile extraction filter bypass allows creation of directories outside the destination Affected packages: Bitnami/python Attributes: No fix available、Severity - 6.3 (Medium)

    最高第 121:27 达到21:27 首次观测上榜23:03 观测离榜累计约1小时36分
  3. 03
    CVE-2026-78683 · NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization

    NLTK before 3.10.0 Remote Code Execution via Unsafe Pickle Deserialization Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 9.4 (Critical)

    最高第 112:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分
  4. 04
    GHSA-3x77-wg38-92r3 · mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable

    mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable Affected packages: Go/github.com/sonirico/mcp-shell Attributes: Fix available、Severity - 8.4 (High)

    最高第 123:51 达到23:51 首次观测上榜当日结束时仍在榜累计约0分钟
  5. 05
    GHSA-5r34-2g38-6569 · praisonaiagents web_crawl vulnerable to SSRF via redirect-following

    praisonaiagents web_crawl vulnerable to SSRF via redirect-following Affected packages: PyPI/praisonaiagents Attributes: Fix available、Severity - 7.5 (High)

    最高第 122:15 达到22:15 首次观测上榜23:03 观测离榜累计约48分钟
  6. 06
    GHSA-gxmw-5f7x-6g22 · praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

    praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location Affected packages: PyPI/praisonaiagents Attributes: Fix available、Severity - 7.1 (High)

    最高第 123:19 达到23:19 首次观测上榜当日结束时仍在榜累计约32分钟
  7. 07
    GHSA-mw6r-2hvm-4rp2 · qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

    qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Affected packages: PyPI/qwed-mcp Attributes: Fix available、Severity - 9.8 (Critical)

    最高第 123:35 达到23:35 首次观测上榜当日结束时仍在榜累计约16分钟
  8. 08
    GHSA-r7v3-x45f-g7hp · PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

    PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 7.3 (High)

    最高第 123:03 达到23:03 首次观测上榜23:51 观测离榜累计约48分钟
  9. 09
    GHSA-vg6p-v9vm-6fgj · praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

    praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) Affected packages: PyPI/praisonaiagents Attributes: Fix available、Severity - 7.5 (High)

    最高第 122:47 达到22:47 首次观测上榜23:19 观测离榜累计约32分钟
  10. 10
    GHSA-wj6g-v78p-6fx3 · PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

    PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 122:31 达到22:31 首次观测上榜23:03 观测离榜累计约32分钟
  11. 11
    RLSA-2026:58819 · Important: nodejs24 security update

    Important: nodejs24 security update Affected packages: Rocky Linux:10/nodejs24 Attributes: Fix available、Severity - 8.6 (High)

    最高第 120:38 达到20:38 首次观测上榜22:15 观测离榜累计约1小时37分
  12. 12
    RLSA-2026:58902 · Important: python3.12 security update

    Important: python3.12 security update Affected packages: Rocky Linux:10/python3.12 Attributes: Fix available、Severity - 7.3 (High)

    最高第 120:22 达到20:22 首次观测上榜22:15 观测离榜累计约1小时53分
  13. 13
    UBUNTU-CVE-2026-75803 · Ubuntu:22.04:LTS/openssl

    Affected packages: Ubuntu:22.04:LTS/openssl、Ubuntu:24.04:LTS/edk2、Ubuntu:24.04:LTS/openssl、Ubuntu:26.04:LTS/edk2、Ubuntu:26.04:LTS/openssl、... 7 more Attributes: No fix available

    最高第 100:00 达到当日首次采集时已在榜12:06 观测离榜累计约12小时6分
  14. 14
    BIT-keycloak-2026-15945 · Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2

    Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2 Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 2.7 (Low)

    最高第 220:54 达到20:54 首次观测上榜22:15 观测离榜累计约1小时21分
  15. 15
    BIT-python-min-2026-19672 · tarfile extraction filter bypass allows creation of directories outside the destination

    tarfile extraction filter bypass allows creation of directories outside the destination Affected packages: Bitnami/python-min Attributes: No fix available、Severity - 6.3 (Medium)

    最高第 221:27 达到21:27 首次观测上榜23:03 观测离榜累计约1小时36分
  16. 16
    CVE-2026-78682 · NLTK before 3.10.3 SSRF Protection Bypass via Proxy

    NLTK before 3.10.3 SSRF Protection Bypass via Proxy Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 8.7 (High)

    最高第 212:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分
  17. 17
    EEF-CVE-2026-75542 · OAuth token exchange grants repository scopes for organizations the principal cannot access

    OAuth token exchange grants repository scopes for organizations the principal cannot access Affected packages: github.com/hexpm/hexpm Attributes: Fix available、Severity - 8.3 (High)

    最高第 204:15 达到04:15 首次观测上榜12:06 观测离榜累计约7小时51分
  18. 18
    EEF-CVE-2026-75554 · Explicit organization scopes survive token refresh after membership ends

    Explicit organization scopes survive token refresh after membership ends Affected packages: github.com/hexpm/hexpm Attributes: Fix available、Severity - 2.3 (Low)

    最高第 204:31 达到04:31 首次观测上榜12:06 观测离榜累计约7小时35分
  19. 19
    GHSA-4ph6-mjv7-3fq6 · netfoil vulnerable to improper handling of untrusted DoH response data

    netfoil vulnerable to improper handling of untrusted DoH response data Affected packages: Go/github.com/tinfoil-factory/netfoil Attributes: Fix available、Severity - 2.7 (Low)

    最高第 205:03 达到05:03 首次观测上榜12:06 观测离榜累计约7小时3分
  20. 20
    GHSA-6g6r-q6gw-w8fg · PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

    PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 9.1 (Critical)

    最高第 223:35 达到23:35 首次观测上榜当日结束时仍在榜累计约16分钟
  21. 21
    GHSA-74hp-mggr-hv58 · mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias

    mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias Affected packages: Go/github.com/sonirico/mcp-shell Attributes: Fix available、Severity - 8.4 (High)

    最高第 223:51 达到23:51 首次观测上榜当日结束时仍在榜累计约0分钟
  22. 22
    GHSA-7ww9-85pg-cv4x · PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

    PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 8.6 (High)

    最高第 222:47 达到22:47 首次观测上榜23:19 观测离榜累计约32分钟
  23. 23
    GHSA-8hjw-25cg-g52h · praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

    praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets Affected packages: PyPI/praisonaiagents Attributes: Fix available、Severity - 7.7 (High)

    最高第 222:31 达到22:31 首次观测上榜23:03 观测离榜累计约32分钟
  24. 24
    GHSA-9284-fjc3-fmmj · Sakai Profile Image Deletion has an IDOR

    Sakai Profile Image Deletion has an IDOR Affected packages: Maven/org.sakaiproject.profile2:profile2-api、Maven/org.sakaiproject.profile2:profile2-impl Attributes: Fix available、Severity - 6.5 (Medium)

    最高第 203:59 达到03:59 首次观测上榜08:47 观测离榜累计约4小时48分
  25. 25
    GHSA-ch89-h4r2-c8f8 · PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

    PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 7.1 (High)

    最高第 223:03 达到23:03 首次观测上榜23:51 观测离榜累计约48分钟
  26. 26
    GHSA-fx4f-mhw4-qm7j · vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths

    vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths Affected packages: crates.io/vibeio-http Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 208:47 达到08:47 首次观测上榜12:06 观测离榜累计约3小时19分
  27. 27
    GHSA-jm48-m3rr-9hgg · 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation

    3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation Affected packages: Go/github.com/mhsanaei/3x-ui/v2、Go/github.com/mhsanaei/3x-ui/v3 Attributes: Fix available、Severity - 7.2 (High)

    最高第 205:19 达到05:19 首次观测上榜12:06 观测离榜累计约6小时47分
  28. 28
    GHSA-pvxx-r596-f5qj · PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

    PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 8.8 (High)

    最高第 223:19 达到23:19 首次观测上榜当日结束时仍在榜累计约32分钟
  29. 29
    GHSA-xm98-3vcf-fph7 · mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

    mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server Affected packages: PyPI/mcp-contextforge-gateway Attributes: Fix available

    最高第 203:43 达到03:43 首次观测上榜08:47 观测离榜累计约5小时4分
  30. 30
    JLSEC-2026-1387 · A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian...

    A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian... Affected packages: Julia/xapian_jll Attributes: No fix available、Severity - 4.4 (Medium)

    最高第 202:38 达到02:38 首次观测上榜05:03 观测离榜累计约2小时25分
  31. 31
    MAL-2026-14412 · Malicious code in @deepaksilaych/sess (npm)

    Malicious code in @deepaksilaych/sess (npm) Affected packages: npm/@deepaksilaych/sess Attributes: No fix available

    最高第 200:00 达到当日首次采集时已在榜01:02 观测离榜累计约1小时3分
  32. 32
    MAL-2026-14418 · Malicious code in dotish (npm)

    Malicious code in dotish (npm) Affected packages: npm/dotish Attributes: No fix available

    最高第 200:46 达到00:46 首次观测上榜01:02 观测离榜累计约16分钟
  33. 33
    MAL-2026-14423 · Malicious code in @medisend/shared (npm)

    Malicious code in @medisend/shared (npm) Affected packages: npm/@medisend/shared Attributes: No fix available

    最高第 201:02 达到01:02 首次观测上榜02:54 观测离榜累计约1小时52分
  34. 34
    RLSA-2026:58899 · Important: firefox security update

    Important: firefox security update Affected packages: Rocky Linux:10/firefox Attributes: Fix available、Severity - 7.5 (High)

    最高第 220:38 达到20:38 首次观测上榜22:15 观测离榜累计约1小时37分
  35. 35
    ROOT-OS-DEBIAN-12-CVE-2023-34152 · CVE-2023-34152 in imagemagick - Patched by Root

    CVE-2023-34152 in imagemagick - Patched by Root Affected packages: Root:Debian:12/imagemagick、Root:Debian:12/rootio-imagemagick Attributes: Fix available、Severity - 9.8 (Critical)

    最高第 220:22 达到20:22 首次观测上榜20:54 观测离榜累计约32分钟
  36. 36
    ROOT-OS-DEBIAN-12-CVE-2026-44169 · CVE-2026-44169 in mariadb - Patched by Root

    CVE-2026-44169 in mariadb - Patched by Root Affected packages: Root:Debian:12/mariadb、Root:Debian:12/rootio-mariadb Attributes: Fix available

    最高第 222:15 达到22:15 首次观测上榜23:03 观测离榜累计约48分钟
  37. 37
    BIT-keycloak-2026-14613 · Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission

    Keycloak-services: keycloak-services: keycloak: fgap v2 role groups endpoint discloses hidden group metadata without group view permission Affected packages: Bitnami/keycloak Attributes: Fix available、Severity - 4.9 (Medium)

    最高第 320:54 达到20:54 首次观测上榜22:15 观测离榜累计约1小时21分
  38. 38
    BIT-libpython-2026-19672 · tarfile extraction filter bypass allows creation of directories outside the destination

    tarfile extraction filter bypass allows creation of directories outside the destination Affected packages: Bitnami/libpython Attributes: No fix available、Severity - 6.3 (Medium)

    最高第 321:27 达到21:27 首次观测上榜23:03 观测离榜累计约1小时36分
  39. 39
    CVE-2026-78681 · NLTK before 3.10.3 Entity Expansion DoS via ElementTree

    NLTK before 3.10.3 Entity Expansion DoS via ElementTree Affected packages: github.com/nltk/nltk Attributes: Fix available、Severity - 8.7 (High)

    最高第 312:06 达到12:06 首次观测上榜20:22 观测离榜累计约8小时16分
  40. 40
    GHSA-3gjw-f78c-vvpw · tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service

    tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service Affected packages: crates.io/tokio-postgres Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 304:15 达到04:15 首次观测上榜12:06 观测离榜累计约7小时51分
  41. 41
    GHSA-cfxv-8fw8-rwpv · praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

    praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool Affected packages: PyPI/praisonaiagents Attributes: Fix available、Severity - 6.1 (Medium)

    最高第 323:03 达到23:03 首次观测上榜23:19 观测离榜累计约16分钟
  42. 42
    GHSA-hmfx-4v44-9qw9 · PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

    PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 6.8 (Medium)

    最高第 323:19 达到23:19 首次观测上榜当日结束时仍在榜累计约32分钟
  43. 43
    GHSA-hxmv-c4g6-5fqc · PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

    PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code Affected packages: PyPI/praisonai、PyPI/praisonaiagents Attributes: Fix available、Severity - 7.8 (High)

    最高第 322:31 达到22:31 首次观测上榜23:03 观测离榜累计约32分钟
  44. 44
    GHSA-pvph-5j39-v8qc · PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

    PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server Affected packages: PyPI/praisonai Attributes: Fix available、Severity - 7.6 (High)

    最高第 323:35 达到23:35 首次观测上榜当日结束时仍在榜累计约16分钟
  45. 45
    GHSA-w2x5-gv52-9ccv · Sakai Conversations has a Stored XSS Issue

    Sakai Conversations has a Stored XSS Issue Affected packages: Maven/org.sakaiproject.conversations:sakai-conversations-impl、Maven/org.sakaiproject.kernel:sakai-kernel-impl、Maven/org.sakaiproject.rubrics:rubrics-impl Attributes: No fix available、Severity - 8.7 (High)

    最高第 303:59 达到03:59 首次观测上榜08:47 观测离榜累计约4小时48分
  46. 46
    GHSA-w67g-5rqw-f597 · Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key

    Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key Affected packages: Go/github.com/gorilla/websocket Attributes: Fix available、Severity - 6.9 (Medium)

    最高第 305:19 达到05:19 首次观测上榜12:06 观测离榜累计约6小时47分
  47. 47
    GHSA-w8j7-39hp-8x59 · Cloudreve's remote download file paths can escape the selected destination directory

    Cloudreve's remote download file paths can escape the selected destination directory Affected packages: Go/github.com/cloudreve/Cloudreve/v4 Attributes: No fix available、Severity - 5.5 (Medium)

    最高第 308:47 达到08:47 首次观测上榜12:06 观测离榜累计约3小时19分
  48. 48
    GHSA-x44h-65qv-cw74 · praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

    praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`) Affected packages: PyPI/praisonaiagents Attributes: Fix available、Severity - 8.5 (High)

    最高第 322:47 达到22:47 首次观测上榜23:03 观测离榜累计约16分钟
  49. 49
    MAL-2026-14413 · Malicious code in livemcp (npm)

    Malicious code in livemcp (npm) Affected packages: npm/livemcp Attributes: No fix available

    最高第 300:00 达到当日首次采集时已在榜01:02 观测离榜累计约1小时3分
  50. 50
    MAL-2026-14416 · Malicious code in dims-hydration-ui (npm)

    Malicious code in dims-hydration-ui (npm) Affected packages: npm/dims-hydration-ui Attributes: No fix available

    最高第 300:46 达到00:46 首次观测上榜01:02 观测离榜累计约16分钟