Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2024-58264Highserde-json-wasm: serde-json-wasm stack overflow during recursive JSON parsingCVE-2024-25817Higheza: eza Potential Heap Overflow Vulnerability for AArch64GHSA-29C2-65RJ-H343Mediumckb: Nervos CKB Permit load cell data from memoryGHSA-H4C3-5275-VRMGMediumckb: Nervos CKB Pool does not remove the conflicting transactions from the statistics CVE-2018-25001Mediumlibpulse-binding: Use after free in libpulse-bindingGHSA-Q73F-W3H7-7WCCCriticalckb: Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic resultGHSA-3GJH-29FV-8HR6Highckb: Nervos CKB Snappy decompress length can be very large and causes out of memory error GHSA-WJXC-PJX9-4WVMHighckb: Nervos CKB Panic on malformed inputGHSA-HJQQ-29PW-96WJHighckb: Nervos CKB node panics when processing a block which parent timestamp is too newGHSA-R9RV-9MH8-PXF4Mediumckb: Nervos CKB BlockTimeTooNew should not be considered as invalid blockGHSA-PR39-8257-FXC2Lowckb: Nervos CKB DoS: Process exists when p2p discovery protocol receives unsupported peer IPGHSA-84X2-2QV6-QG56Criticalckb: Nervos CKB P2P DoS AttacksGHSA-Q669-2VFG-CXCGMediumckb: Nervos CKB Unaligned Pointer DereferenceCVE-2022-39394Lowwasmtime: wasmtime_trap_code C API function has out of bounds write vulnerabilityCVE-2021-29511Mediumevm: Memory over-allocation in evm crateCVE-2024-23649Highlemmy_server: Any authenticated user may obtain private message details from other users on the same instanceCVE-2024-58265Lowsnow: Unauthenticated Nonce Increment in snowCVE-2024-23644Mediumtrillium-http: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') in trillium-http and trillium-clientGHSA-C8V3-JHV9-4PPCMediumrust-i18n-support: Use-after-free when setting the localeGHSA-W59H-378F-2FRMMediumthreadalone: Unsound sending of non-Send types across threads in threadaloneCVE-2024-58266Lowshlex: Multiple issues involving quote API in shlexGHSA-58J9-J2FJ-V8F4Highsurrealdb: SurrealDB vulnerable to Uncontrolled CPU Consumption via WebSocket InterfaceGHSA-8R5V-VM4M-4G25Mediumh2: Resource exhaustion vulnerability in h2 may lead to Denial of Service (DoS)GHSA-6R8P-HPG7-825GMediumsurrealdb: Uncontrolled Recursion in SurrealQL ParsingGHSA-M24X-R6Q3-2VP9Highsurrealdb: Uncaught Exception processing HTTP Headers in SurrealDB

Stop the waste.
Protect your environment with Kodem.