
OSV.dev · 实时热榜
- 01DEBIAN-CVE-2026-18798 · Debian:13/openssl
Affected packages: Debian:13/openssl、Debian:14/openssl Attributes: Fix available
最高第 1 名01:10 达到01:10 首次观测上榜07:02 观测离榜上榜 2 次(重入 1 次)累计约2小时56分 - 02DEBIAN-CVE-2026-52489 · Debian:11/gpac
Affected packages: Debian:11/gpac Attributes: No fix available
最高第 1 名23:02 达到23:02 首次观测上榜23:34 观测离榜累计约32分钟 - 03DEBIAN-CVE-2026-59186 · Debian:11/openexr
Affected packages: Debian:11/openexr、Debian:12/openexr、Debian:13/openexr、Debian:14/openexr Attributes: No fix available
最高第 1 名15:02 达到15:02 首次观测上榜15:50 观测离榜累计约48分钟 - 04DEBIAN-CVE-2026-59984 · Debian:11/openexr
Affected packages: Debian:11/openexr、Debian:12/openexr、Debian:13/openexr、Debian:14/openexr Attributes: No fix available
最高第 1 名13:10 达到13:10 首次观测上榜15:02 观测离榜累计约1小时52分 - 05DEBIAN-CVE-2026-63072 · Debian:11/openssl
Affected packages: Debian:11/openssl、Debian:12/openssl、Debian:13/openssl、Debian:14/openssl Attributes: Fix available
最高第 1 名05:26 达到01:10 首次观测上榜07:18 观测离榜上榜 2 次(重入 1 次)累计约2小时39分 - 06DEBIAN-CVE-2026-63073 · Debian:13/openssl
Affected packages: Debian:13/openssl、Debian:14/openssl Attributes: Fix available
最高第 1 名05:10 达到01:10 首次观测上榜07:18 观测离榜上榜 2 次(重入 1 次)累计约2小时40分 - 07DEBIAN-CVE-2026-63676 · Debian:11/libyaml-perl
Affected packages: Debian:11/libyaml-perl、Debian:12/libyaml-perl、Debian:13/libyaml-perl、Debian:14/libyaml-perl Attributes: No fix available
最高第 1 名04:06 达到04:06 首次观测上榜05:26 观测离榜累计约1小时20分 - 08DEBIAN-CVE-2026-68763 · Debian:11/tomcat9
Affected packages: Debian:11/tomcat9、Debian:12/tomcat10、Debian:12/tomcat9、Debian:13/tomcat10、Debian:13/tomcat11、... 4 more Attributes: Fix available
最高第 1 名19:02 达到19:02 首次观测上榜21:42 观测离榜累计约2小时40分 - 09DEBIAN-CVE-2026-70665 · Debian:11/ruby-doorkeeper-openid-connect
Affected packages: Debian:11/ruby-doorkeeper-openid-connect、Debian:12/ruby-doorkeeper-openid-connect、Debian:13/ruby-doorkeeper-openid-connect、Debian:14/ruby-doorkeeper-openid-connect Attributes: Fix available
最高第 1 名21:10 达到21:10 首次观测上榜22:30 观测离榜累计约1小时20分 - 10DEBIAN-CVE-2026-79046 · Debian:11/chromium
Affected packages: Debian:11/chromium、Debian:12/chromium、Debian:13/chromium、Debian:14/chromium Attributes: No fix available
最高第 1 名18:14 达到18:14 首次观测上榜18:46 观测离榜累计约32分钟 - 11DEBIAN-CVE-2026-79675 · Debian:11/nltk
Affected packages: Debian:11/nltk、Debian:12/nltk、Debian:13/nltk、Debian:14/nltk Attributes: Fix available
最高第 1 名07:02 达到07:02 首次观测上榜10:46 观测离榜累计约3小时45分 - 12DEBIAN-CVE-2026-79777 · Debian:11/rclone
Affected packages: Debian:11/rclone、Debian:12/rclone、Debian:13/rclone Attributes: No fix available
最高第 1 名07:18 达到07:18 首次观测上榜10:46 观测离榜累计约3小时29分 - 13DEBIAN-CVE-2026-79992 · Debian:11/emacs
Affected packages: Debian:11/emacs、Debian:12/emacs、Debian:13/emacs、Debian:14/emacs Attributes: No fix available
最高第 1 名03:02 达到03:02 首次观测上榜04:38 观测离榜累计约1小时36分 - 14DEBIAN-CVE-2026-80182 · Debian:11/keystone
Affected packages: Debian:11/keystone、Debian:12/keystone、Debian:13/keystone、Debian:14/keystone Attributes: No fix available
最高第 1 名17:10 达到17:10 首次观测上榜18:14 观测离榜累计约1小时4分 - 15ECHO-0c44-ee86-473d · Echo/libdbi-perl
Affected packages: Echo/libdbi-perl Attributes: Fix available
最高第 1 名16:54 达到16:54 首次观测上榜18:14 观测离榜累计约1小时20分 - 16ECHO-1c9d-3961-cc2b · Echo/webkit2gtk
Affected packages: Echo/webkit2gtk Attributes: No fix available
最高第 1 名10:46 达到10:46 首次观测上榜12:22 观测离榜累计约1小时36分 - 17ECHO-66d7-e273-5f0f · Echo/openssl
Affected packages: Echo/openssl Attributes: Fix available
最高第 1 名09:58 达到09:58 首次观测上榜12:22 观测离榜累计约2小时24分 - 18ECHO-8e41-0efd-8249 · Echo/libheif
Affected packages: Echo/libheif Attributes: Fix available
最高第 1 名18:46 达到18:46 首次观测上榜20:38 观测离榜累计约1小时52分 - 19ECHO-a943-8f53-50df · Echo/libyaml-perl
Affected packages: Echo/libyaml-perl Attributes: No fix available
最高第 1 名17:58 达到17:58 首次观测上榜18:14 观测离榜累计约16分钟 - 20ECHO-c31d-7527-5ac7 · Echo/openexr
Affected packages: Echo/openexr Attributes: No fix available
最高第 1 名15:50 达到15:50 首次观测上榜17:10 观测离榜累计约1小时20分 - 21GHSA-2wxc-x7rj-hg8f · asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh has SCP Path Traversal to Arbitrary File Write Affected packages: PyPI/asyncssh Attributes: Fix available、Severity - 8.1 (High)
最高第 1 名23:50 达到23:50 首次观测上榜当日结束时仍在榜累计约0分钟 - 22GHSA-3x77-wg38-92r3 · mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable Affected packages: Go/github.com/sonirico/mcp-shell Attributes: Fix available、Severity - 8.4 (High)
最高第 1 名00:00 达到当日首次采集时已在榜00:54 观测离榜累计约55分钟 - 23GHSA-72f3-6w86-7rv3 · @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint Affected packages: npm/@arikusi/deepseek-mcp-server Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名02:46 达到02:46 首次观测上榜04:38 观测离榜累计约1小时52分 - 24GHSA-f63g-88cj-hjf9 · IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries Affected packages: Maven/org.codehaus.izpack:izpack-installer Attributes: No fix available、Severity - 7.4 (High)
最高第 1 名22:30 达到22:30 首次观测上榜23:34 观测离榜累计约1小时4分 - 25GHSA-hvfh-5mj3-5f3j · Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access Affected packages: PyPI/chainlit Attributes: Fix available、Severity - 7.2 (High)
最高第 1 名03:34 达到03:34 首次观测上榜04:38 观测离榜累计约1小时4分 - 26GHSA-p43p-whwx-q52h · JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login Affected packages: PyPI/jupyterhub Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名03:50 达到03:50 首次观测上榜05:10 观测离榜累计约1小时20分 - 27GHSA-ppx3-28rw-8fpf · utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins Affected packages: PyPI/utcp-gql、PyPI/utcp-websocket Attributes: Fix available、Severity - 4.7 (Medium)
最高第 1 名00:07 达到00:07 首次观测上榜01:10 观测离榜累计约1小时3分 - 28GHSA-q27q-98j4-9pfv · qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` Affected packages: PyPI/qwed Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名00:38 达到00:38 首次观测上榜01:10 观测离榜累计约32分钟 - 29GHSA-q8gf-9rvj-gmgj · gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
gRPC Erlang package has unbounded request body accumulation in `read_full_body/3` Affected packages: Hex/grpc Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名02:30 达到02:30 首次观测上榜04:06 观测离榜累计约1小时36分 - 30GHSA-qj6x-xx2h-8hvv · Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript Affected packages: npm/@platejs/media Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名00:54 达到00:54 首次观测上榜01:10 观测离榜累计约16分钟 - 31GHSA-vwf3-4xxj-qg6h · mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment Affected packages: PyPI/mcp-contextforge-gateway Attributes: Fix available
最高第 1 名01:58 达到01:58 首次观测上榜02:46 观测离榜累计约48分钟 - 32GHSA-w93q-cq9w-58p7 · SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed Affected packages: npm/suneditor Attributes: Fix available、Severity - 8.5 (High)
最高第 1 名23:34 达到23:34 首次观测上榜当日结束时仍在榜累计约16分钟 - 33GHSA-x287-5c68-36wp · OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses Affected packages: PyPI/openwisp-ipam Attributes: Fix available、Severity - 5.3 (Medium)
最高第 1 名22:46 达到22:46 首次观测上榜23:34 观测离榜累计约48分钟 - 34GHSA-xx4j-w367-7247 · djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls Affected packages: PyPI/djust Attributes: Fix available、Severity - 8.2 (High)
最高第 1 名00:23 达到00:23 首次观测上榜01:10 观测离榜累计约47分钟 - 35GO-2026-6293 · Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5
Encoded slash (%2F) bypasses route-level protection and exposes static files in github.com/labstack/echo/v4 and github.com/labstack/echo/v5 Affected packages: Go/github.com/labstack/echo/v4、Go/github.com/labstack/echo/v5 Attributes: Fix available
最高第 1 名23:18 达到23:18 首次观测上榜23:34 观测离榜累计约16分钟 - 36MAL-2026-14514 · Malicious code in wm-eslint-fe (npm)
Malicious code in wm-eslint-fe (npm) Affected packages: npm/wm-eslint-fe Attributes: No fix available
最高第 1 名01:42 达到01:42 首次观测上榜02:30 观测离榜累计约48分钟 - 37MAL-2026-14519 · Malicious code in array-shuffler-utils-99 (npm)
Malicious code in array-shuffler-utils-99 (npm) Affected packages: npm/array-shuffler-utils-99 Attributes: No fix available
最高第 1 名12:38 达到12:38 首次观测上榜14:46 观测离榜累计约2小时8分 - 38MAL-2026-14523 · Malicious code in rce-test (PyPI)
Malicious code in rce-test (PyPI) Affected packages: PyPI/rce-test Attributes: No fix available
最高第 1 名13:42 达到13:42 首次观测上榜15:02 观测离榜累计约1小时20分 - 39MAL-2026-14527 · Malicious code in @fongsidev/scraper (npm)
Malicious code in @fongsidev/scraper (npm) Affected packages: npm/@fongsidev/scraper Attributes: No fix available
最高第 1 名21:58 达到21:58 首次观测上榜22:30 观测离榜累计约32分钟 - 40MINI-7535-p953-8hq8 · MinimOS/openfga-fips
Affected packages: MinimOS/openfga-fips Attributes: Fix available
最高第 1 名11:02 达到11:02 首次观测上榜12:22 观测离榜累计约1小时20分 - 41MINI-v2qc-5wfv-jhrr · MinimOS/corretto-fips-config-17
Affected packages: MinimOS/corretto-fips-config-17 Attributes: Fix available
最高第 1 名14:46 达到14:46 首次观测上榜15:50 观测离榜累计约1小时4分 - 42RHSA-2026:60004 · Red Hat Security Advisory: httpd security update
Red Hat Security Advisory: httpd security update Affected packages: Red Hat:enterprise_linux:10.2/httpd、Red Hat:enterprise_linux:10.2/httpd-core、Red Hat:enterprise_linux:10.2/httpd-core-debuginfo、Red Hat:enterprise_linux:10.2/httpd-debuginfo、Red Hat:enterprise_linux:10.2/httpd-debugsource、... 15 more Attributes: Fix available、Severity - 4.6 (Medium)
最高第 1 名18:30 达到18:30 首次观测上榜19:02 观测离榜累计约32分钟 - 43RLSA-2026:22120 · Important: golang security update
Important: golang security update Affected packages: Rocky Linux:10/golang Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名08:39 达到08:39 首次观测上榜12:22 观测离榜累计约3小时44分 - 44RLSA-2026:59372 · Moderate: assertj-core security update
Moderate: assertj-core security update Affected packages: Rocky Linux:10/assertj-core Attributes: Fix available、Severity - 6.1 (Medium)
最高第 1 名20:38 达到20:38 首次观测上榜22:30 观测离榜累计约1小时52分 - 45RLSA-2026:59487 · Important: gstreamer1-plugins-base security update
Important: gstreamer1-plugins-base security update Affected packages: Rocky Linux:8/gstreamer1-plugins-base Attributes: Fix available、Severity - 7.8 (High)
最高第 1 名14:30 达到14:30 首次观测上榜15:50 观测离榜累计约1小时20分 - 46ROOT-APP-NPM-AIKIDO-2026-961622 · AIKIDO-2026-961622 in @fastify/busboy - Patched by Root
AIKIDO-2026-961622 in @fastify/busboy - Patched by Root Affected packages: Root:npm/@fastify/busboy、Root:npm/@rootio/fastify__busboy Attributes: Fix available
最高第 1 名19:18 达到19:18 首次观测上榜21:42 观测离榜累计约2小时24分 - 47ROOT-OS-DEBIAN-13-CVE-2004-0230 · CVE-2004-0230 in linux - Patched by Root
CVE-2004-0230 in linux - Patched by Root Affected packages: Root:Debian:13/linux、Root:Debian:13/rootio-linux Attributes: Fix available
最高第 1 名12:22 达到12:22 首次观测上榜14:46 观测离榜累计约2小时24分 - 48DEBIAN-CVE-2026-56704 · Debian:11/adminer
Affected packages: Debian:11/adminer、Debian:12/adminer、Debian:13/adminer、Debian:14/adminer Attributes: Fix available
最高第 2 名01:10 达到01:10 首次观测上榜02:30 观测离榜累计约1小时20分 - 49DEBIAN-CVE-2026-59184 · Debian:11/openexr
Affected packages: Debian:11/openexr、Debian:12/openexr、Debian:13/openexr、Debian:14/openexr Attributes: No fix available
最高第 2 名15:02 达到15:02 首次观测上榜15:50 观测离榜累计约48分钟 - 50DEBIAN-CVE-2026-59985 · Debian:11/openexr
Affected packages: Debian:11/openexr、Debian:12/openexr、Debian:13/openexr、Debian:14/openexr Attributes: No fix available
最高第 2 名13:10 达到13:10 首次观测上榜15:02 观测离榜累计约1小时52分


































































































