Cargo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2020-35867Criticalrusqlite: Data races in rusqliteCVE-2020-35865Highos_str_bytes: os_str_bytes relies on undefined behavior of `char::from_u32_unchecked`CVE-2020-35868Criticalrusqlite: Data races in rusqliteCVE-2020-35870Criticalrusqlite: Use after free in rusqliteCVE-2020-35877Criticalozone: Out of bounds read in OzoneCVE-2020-35873Criticalrusqlite: Use after free in rusqliteCVE-2020-35878Criticalozone: Drop of uninitialized memory in OzoneCVE-2020-35862Criticalbitvec: Use after free and double free in bitvecCVE-2020-35864Highflatbuffers: Dangling reference in flatbuffersCVE-2020-35869Criticalrusqlite: Mishandling of format strings in rusqliteCVE-2020-35860Criticalcbox: NULL Pointer Dereference in cboxCVE-2020-35861Highbumpalo: Out of bounds read in bumpaloCVE-2020-35872Criticalrusqlite: Improper type usage in rusqliteCVE-2020-35871Highrusqlite: Data races in rusqliteCVE-2020-35876Criticalrio: Use after free in rioCVE-2020-35875Hightokio-rustls: Excessive memory usage in tokio-rustlsCVE-2020-35874Highinternment: Use after free in internmentCVE-2019-25004Criticalflatbuffers: Unsound casting in flatbuffersCVE-2019-25003Highlibsecp256k1: libsecp256k1 contains side-channel timing attackCVE-2019-25009Criticalhttp: Double free in httpCVE-2019-25007Highstreebog: Incorrect implementation in streebogCVE-2019-25010Criticalfailure: Rust Failure Crate Vulnerable to Type confusionCVE-2020-35859Criticallucet-runtime-internals: Out of bounds access in lucet-runtime-internalsCVE-2020-35857Hightrust-dns-server: Stack consumption in trust-dns-serverCVE-2020-35858Criticalprost: Out of bounds write in prost

Stop the waste.
Protect your environment with Kodem.