GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
210 advisories
Filter by severity
** DISPUTED ** CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins...
Critical
Unreviewed
CVE-2018-15474
was published
May 13, 2022
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0...
High
Unreviewed
CVE-2023-35899
was published
Mar 21, 2024
** DISPUTED ** In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists,...
High
Unreviewed
CVE-2019-14352
was published
May 24, 2022
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7...
Critical
Unreviewed
CVE-2023-47534
was published
Mar 12, 2024
A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the ...
Moderate
Unreviewed
CVE-2023-45597
was published
Mar 5, 2024
Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A...
Moderate
Unreviewed
CVE-2021-36334
was published
Nov 24, 2021
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress...
High
Unreviewed
CVE-2019-17661
was published
May 24, 2022
An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a...
Moderate
Unreviewed
CVE-2023-47022
was published
Feb 6, 2024
CSV Injection in symfony/serializer
Moderate
CVE-2021-41270
was published
for
symfony/serializer
(Composer)
Nov 24, 2021
The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in...
High
Unreviewed
CVE-2022-3604
was published
Jan 16, 2024
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and...
High
Unreviewed
CVE-2022-3026
was published
Sep 7, 2022
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (...
High
Unreviewed
CVE-2023-31294
was published
Dec 29, 2023
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (...
High
Unreviewed
CVE-2023-31295
was published
Dec 29, 2023
Potential CSV export data leak
High
CVE-2023-50448
was published
for
activeadmin
(RubyGems)
Dec 15, 2023
Duplicate Advisory: ActiveAdmin vulnerable to CSV injection
High
GHSA-rqxc-9p8h-xqgq
was published
for
activeadmin
(RubyGems)
Dec 24, 2023
•
withdrawn
ActiveAdmin CSV Injection leading to sensitive information disclosure
Moderate
CVE-2023-51763
was published
for
activeadmin
(RubyGems)
Dec 28, 2023
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the...
High
Unreviewed
CVE-2023-48207
was published
Dec 7, 2023
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point...
Moderate
Unreviewed
CVE-2020-16214
was published
May 24, 2022
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote...
High
Unreviewed
CVE-2023-42004
was published
Nov 28, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane...
High
Unreviewed
CVE-2022-46821
was published
Nov 7, 2023
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject...
High
Unreviewed
CVE-2023-48029
was published
Nov 17, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in Shambix Simple CSV/XLS...
High
Unreviewed
CVE-2022-42882
was published
Nov 7, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in Kaushik Kalathiya...
High
Unreviewed
CVE-2022-41616
was published
Nov 7, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in WebToffee WordPress...
Critical
Unreviewed
CVE-2022-45370
was published
Nov 7, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in Icegram Icegram...
Critical
Unreviewed
CVE-2022-45810
was published
Nov 7, 2023
ProTip!
Advisories are also available from the
GraphQL API