Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-GG76-HG3V-5Q6CHighmacroquad: macroquad vulnerable to multiple soundness issuesCVE-2025-46718Lowsudo-rs: sudo-rs Allows Low Privilege Users to Enumerate Privileges of OthersCVE-2025-46717Lowsudo-rs: sudo-rs Allows Low Privilege Users to Discover the Existence of Files in Inaccessible FoldersCVE-2025-47736Lowlibsql-sqlite3-parser: libsql-sqlite3-parser crash due to invalid UTF-8 inputCVE-2025-47737Lowtrailer: trailer mishandles allocating with a size of zeroCVE-2025-47735Lowwgp: wgp race condition in inner::dropGHSA-4H96-MV53-2C86Mediumfast_id_map: fast_id_map has a soundness issue and is unmaintainedGHSA-79M9-55JC-P6MWLowscanner: scanner has a Public API without sufficient bounds checkingGHSA-QV97-5QR8-2266Mediummithril-client: Mithril snapshots for Cardano database could be compromised by an adversaryGHSA-58XC-HPVQ-8473Lowredox_uefi_std: Redox UEFI Safe API can cause heap-buffer-overflowGHSA-M2XR-2VJ4-WH94Mediumtanton_engine: tanton_engine has unsound public APICVE-2025-46723Highopenvm: OpenVM allows the byte decomposition of pc in AUIPC chip to overflowCVE-2024-58253Lowobfstr: obfstr Type Confusion vulnerabilityGHSA-927Q-G9W9-PM54Mediummp3-metadata: Panic in mp3-metadata due to the lack of bounds checkingCVE-2025-32439Mediumpleezer: Pleezer resource exhaustion through uncollected hook script processesGHSA-5Q9X-554G-9JGGMediumsurrealdb: SurrealDB bypass of deny-net flags via redirect results in server-side request forgery (SSRF)GHSA-PXW4-94J3-V9PFHighsurrealdb: SurrealDB CPU exhaustion via custom functions result in total DoSGHSA-3824-QMFQ-2QV7Lowsurrealdb: SurrealDB no JavaScript script function default timeout could facilitate DoSGHSA-3633-G6MG-P6QQHighsurrealdb: SurrealDB memory exhaustion via string::replace using regex GHSA-CCJ3-5P93-8P42Criticalsurrealdb: SurrealDB server-takeover via SurrealQL injection on backup importGHSA-2CVJ-G5R5-JRRGLowsurrealdb: SurrealDB has local file read of 2-column TSV files via analyzers GHSA-M7RC-8W7M-R9QRMediumsurrealdb: SurrealDB vulnerable to memory exhaustion via nested functions and scriptsGHSA-RQ86-9M6R-CM3GHighsurrealdb: SurrealDB has uncaught exception in Net module that leads to database crashCVE-2025-4574Mediumcrossbeam-channel: crossbeam-channel Vulnerable to Double Free on DropGHSA-6JRF-4JV4-R9MWHightendermint-light-client-verifier: tendermint-rs's Light Client Verifier allows malicious validators to spoof votes from other validators

Stop the waste.
Protect your environment with Kodem.