GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
CSV Injection vulnerability with exported contact lists in Mautic
Moderate
CVE-2018-8092
was published
for
mautic/core
(Composer)
Jan 19, 2021
Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore
Moderate
CVE-2021-37702
was published
for
pimcore/pimcore
(Composer)
Aug 30, 2021
Dell EMC CloudLink 7.1 and all prior versions contain a CSV formula Injection Vulnerability. A...
Moderate
Unreviewed
CVE-2021-36334
was published
Nov 24, 2021
CSV Injection in symfony/serializer
Moderate
CVE-2021-41270
was published
for
symfony/serializer
(Composer)
Nov 24, 2021
Improper Neutralization of Formula Elements in a CSV File in html-2-csv
Moderate
CVE-2021-23654
was published
for
html-to-csv
(pip)
Nov 30, 2021
Open-AudIT before 2.2 has CSV Injection.
Moderate
Unreviewed
CVE-2018-9137
was published
May 13, 2022
SEP (Mac client) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to...
Moderate
Unreviewed
CVE-2018-12244
was published
May 24, 2022
A stored CSV Injection vulnerability was reported in Lenovo XClarity Administrator (LXCA)...
Moderate
Unreviewed
CVE-2019-6182
was published
May 24, 2022
Pivotal Application Manager, versions 666.0.x prior to 666.0.36, versions 667.0.x prior to 667.0...
Moderate
Unreviewed
CVE-2019-11275
was published
May 24, 2022
The TablePress plugin 1.9.2 for WordPress allows tablepress[data] CSV injection by Editor users.
Moderate
Unreviewed
CVE-2019-20180
was published
May 24, 2022
KeePass 2.4.1 allows CSV injection in the title field of a CSV export.
Moderate
Unreviewed
CVE-2019-20184
was published
May 24, 2022
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields...
Moderate
Unreviewed
CVE-2020-9372
was published
May 24, 2022
admin/include/operations.php (via admin/email-harvester.php) in Chadha PHPKB Standard Multi...
Moderate
Unreviewed
CVE-2020-10460
was published
May 24, 2022
Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, PerformanceBridge Focal Point...
Moderate
Unreviewed
CVE-2020-16214
was published
May 24, 2022
OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls...
Moderate
Unreviewed
CVE-2020-28861
was published
May 24, 2022
There has a CSV injection vulnerability in ManageOne 8.0.1. An attacker with common privilege may...
Moderate
Unreviewed
CVE-2020-9205
was published
May 24, 2022
A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be...
Moderate
Unreviewed
CVE-2021-27839
was published
May 24, 2022
Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of...
Moderate
Unreviewed
CVE-2021-1475
was published
May 24, 2022
There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An...
Moderate
Unreviewed
CVE-2021-37131
was published
May 24, 2022
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists...
Moderate
Unreviewed
CVE-2019-16120
was published
May 24, 2022
ghas-to-csv vulnerable to Improper Neutralization of Formula Elements in a CSV File
Moderate
CVE-2022-39217
was published
for
some-natalie/ghas-to-csv
(GitHub Actions)
Sep 16, 2022
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious...
Moderate
Unreviewed
CVE-2022-38845
was published
Sep 17, 2022
Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at...
Moderate
Unreviewed
CVE-2022-38061
was published
Sep 25, 2022
An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the ...
Moderate
Unreviewed
CVE-2022-37786
was published
Jan 1, 2023
The SAP Application Interface Framework (Message Dashboard) - versions AIF 703, AIFX 702, S4CORE...
Moderate
Unreviewed
CVE-2023-29109
was published
Apr 11, 2023
ProTip!
Advisories are also available from the
GraphQL API