Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-58262Lowcurve25519-dalek: curve25519-dalek has timing variability in `curve25519-dalek`'s `Scalar29::sub`/`Scalar52::sub`CVE-2024-36760Highrhai: Rhai stack overflow vulenrabilityCVE-2024-38358Lowwasmer: Symlink bypasses filesystem sandboxGHSA-52XF-5P2M-9WRVLows2n-tls: s2n-tls has a potentially observable differences in RSA premaster secret handlingCVE-2024-36400Criticalnano-id: Unable to generate the correct character setCVE-2024-3584Criticalqdrant: qdrant is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpointCVE-2024-35222Mediumtauri: iFrames Bypass Origin Checks for Tauri API Access ControlCVE-2024-35197Mediumgix-worktree-state: gix refs and paths with reserved Windows device names access the devicesCVE-2024-35186Highgix-worktree-state: gix traversal outside working tree enables arbitrary code executionCVE-2024-4435Mediumic-stable-structures: ic-stable-structures vulnerable to BTreeMap memory leak when deallocating nodes with overflowsCVE-2024-35313Mediumtor-circmgr: Tor path lengths too short when "full Vanguards" configuredCVE-2024-35312Higharti: Tor Arti's STUB circuits incorrectly have a length of 2CVE-2024-34353Mediummatrix-sdk-crypto: matrix-sdk-crypto contains a log exposure of private key of the server-side key backupCVE-2024-32980Criticalspin-sdk: Spin applications with specific configuration vulnerable to potential network sandbox escapeCVE-2024-34346Highdeno: Deno permission escalation vulnerability via open of privileged files with missing `--deny` flagCVE-2024-34063Lowvodozemac: vodozemac has degraded secret zeroization capabilitiesCVE-2024-32971Criticalapollo-router: Apollo Router vulnerable to Critical Regression In Query Plan CacheCVE-2024-32984Highyamux: Yamux Memory Exhaustion Vulnerability via Active::pending_frames property CVE-2024-32966Mediumstatic-web-server: static-web-server vulnerable to stored Cross-site Scripting in directory listings via file namesCVE-2024-58263Lowcosmwasm-std: CosmWasm affected by arithmetic overflowsCVE-2024-32650Highrustls: Denial of Service Vulnerability in Rustls LibraryCVE-2024-32884Mediumgix-transport: gix-transport indirect code execution via malicious usernameGHSA-MC39-H54G-PVW6Mediumlibdav1d-sys: libdav1d-sys affected by dav1d AV1 decoder integer overflowCVE-2023-53156Mediumtranspose: transpose: Buffer overflow due to integer overflowGHSA-XFHW-6MC4-MGXFHighcrayon: crayon: ObjectPool creates uninitialized memory when freeing objects

Stop the waste.
Protect your environment with Kodem.