GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
140 advisories
Filter by severity
Sage X3 version 12.14.0.50-0 is vulnerable to CSV Injection.
High
Unreviewed
CVE-2023-31867
was published
Jun 22, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in WPOmnia KB Support...
High
Unreviewed
CVE-2023-25983
was published
Nov 15, 2023
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export...
High
Unreviewed
CVE-2024-25007
was published
Apr 4, 2024
IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote...
High
Unreviewed
CVE-2023-22877
was published
Aug 28, 2023
An issue in Atlos v.1.0 allows an authenticated attacker to execute arbitrary code via a crafted...
High
Unreviewed
CVE-2023-38843
was published
Aug 17, 2023
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
High
Unreviewed
CVE-2023-37219
was published
Jul 30, 2023
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website...
High
Unreviewed
CVE-2022-28864
was published
Jul 24, 2023
IBM Watson Knowledge Catalog on Cloud Pak for Data 4.0 is potentially vulnerable to CSV Injection...
High
Unreviewed
CVE-2023-28958
was published
Jul 10, 2023
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to CSV injection in...
High
Unreviewed
CVE-2023-0721
was published
Jun 9, 2023
Minical 1.0.0 and earlier contains a CSV injection vulnerability which allows an attacker to...
High
Unreviewed
CVE-2023-33410
was published
Jun 5, 2023
ChurchCRM 4.5.3 was discovered to contain a CSV injection vulnerability via the Last Name and...
High
Unreviewed
CVE-2023-25348
was published
Apr 25, 2023
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in...
High
Unreviewed
CVE-2019-12134
was published
May 24, 2022
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1...
High
Unreviewed
CVE-2021-33256
was published
May 24, 2022
IBM Cloud Pak for Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0...
High
Unreviewed
CVE-2023-35899
was published
Mar 21, 2024
** DISPUTED ** In Joget Workflow 6.0.20, CSV Injection, also known as Formula Injection, exists,...
High
Unreviewed
CVE-2019-14352
was published
May 24, 2022
A CSV injection in the codepress-admin-columns (aka Admin Columns) plugin 3.4.6 for WordPress...
High
Unreviewed
CVE-2019-17661
was published
May 24, 2022
The WP Users Exporter plugin for WordPress is vulnerable to CSV Injection in versions up to, and...
High
Unreviewed
CVE-2022-3026
was published
Sep 7, 2022
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (...
High
Unreviewed
CVE-2023-31295
was published
Dec 29, 2023
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (...
High
Unreviewed
CVE-2023-31294
was published
Dec 29, 2023
Potential CSV export data leak
High
CVE-2023-50448
was published
for
activeadmin
(RubyGems)
Dec 15, 2023
Duplicate Advisory: ActiveAdmin vulnerable to CSV injection
High
GHSA-rqxc-9p8h-xqgq
was published
for
activeadmin
(RubyGems)
Dec 24, 2023
•
withdrawn
Availability Booking Calendar 5.0 allows CSV injection via the unique ID field in the...
High
Unreviewed
CVE-2023-48207
was published
Dec 7, 2023
IBM Security Guardium 11.3, 11.4, and 11.5 is potentially vulnerable to CSV injection. A remote...
High
Unreviewed
CVE-2023-42004
was published
Nov 28, 2023
Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane...
High
Unreviewed
CVE-2022-46821
was published
Nov 7, 2023
Corebos 8.0 and below is vulnerable to CSV Injection. An attacker with low privileges can inject...
High
Unreviewed
CVE-2023-48029
was published
Nov 17, 2023
ProTip!
Advisories are also available from the
GraphQL API