GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
15 advisories
Filter by severity
CSV injection in Craft CMS
High
GHSA-xrpj-f9v6-2332
was published
for
craftcms/cms
(Composer)
Oct 4, 2021
•
withdrawn
CSV Injection Vulnerability
High
CVE-2021-41824
was published
for
craftcms/cms
(Composer)
Oct 18, 2021
Arbitrary code execution in Magnolia CMS
High
CVE-2021-46363
was published
for
info.magnolia:magnolia-core
(Maven)
Feb 12, 2022
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
High
CVE-2022-24770
was published
for
gradio
(pip)
Mar 18, 2022
Improper Neutralization of Formula Elements in a CSV File in Kimai 2
High
CVE-2021-43515
was published
for
kevinpapst/kimai2
(Composer)
Apr 9, 2022
Improper neutralization of formula elements in yii-helpers
High
CVE-2022-1544
was published
for
luyadev/yii-helpers
(Composer)
May 3, 2022
Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection
High
CVE-2023-2629
was published
for
pimcore/customer-management-framework-bundle
(Composer)
May 11, 2023
Admidio Improper Neutralization of Formula Elements in a CSV File vulnerability
High
CVE-2023-3302
was published
for
admidio/admidio
(Composer)
Jun 23, 2023
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File vulnerability
High
CVE-2023-4006
was published
for
thorsten/phpmyfaq
(Composer)
Jul 31, 2023
Potential CSV export data leak
High
CVE-2023-50448
was published
for
activeadmin
(RubyGems)
Dec 15, 2023
Duplicate Advisory: ActiveAdmin vulnerable to CSV injection
High
GHSA-rqxc-9p8h-xqgq
was published
for
activeadmin
(RubyGems)
Dec 24, 2023
•
withdrawn
Refuel Autolab Eval Injection vulnerability
High
CVE-2024-27321
was published
for
refuel-autolabel
(pip)
Sep 12, 2024
Refuel Autolab Eval Injection vulnerability
High
CVE-2024-27320
was published
for
refuel-autolabel
(pip)
Sep 12, 2024
ProTip!
Advisories are also available from the
GraphQL API