Skip to content
Noroxi

angularjs records

13 published records for vendor angularjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
84.6%
Median publish → KEV
No record has entered KEV

All records

13 records
  • Regular Expression Denial of Service (ReDoS)

    HighCVSS 7.5No exploitEPSS 5%

    angularjs · angularjsMay 1, 2022

  • In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto

    HighCVSS 7.5No exploitEPSS 2%

    angularjs · angularjsNov 19, 2019

  • This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.

    HighCVSS 7.5Proof of conceptEPSS 2%

    angularjs · angular.jsFeb 10, 2024

  • All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cro

    MediumCVSS 6.1Proof of conceptEPSS 7%

    angularjs · angularjsJul 15, 2022

  • There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appli

    MediumCVSS 6.1No exploitEPSS 1%

    angularjs · angularjsJan 2, 2020

  • ag-grid is an advanced data grid that is library agnostic.

    MediumCVSS 6.1No exploitEPSS 1%

    ag-grid · ag-gridJun 4, 2018

  • CVE-2020-7676
    22Monitor

    angular.js prior to 1.8.0 allows cross site scripting.

    MediumCVSS 5.4No exploitEPSS 2%

    angularjs · angularjsJun 8, 2020

  • Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fu

    MediumCVSS 5.3No exploitEPSS 2%

    angularjs · angularjsMar 30, 2023

  • Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to t

    MediumCVSS 5.3No exploitEPSS 2%

    angularjs · angularjsMar 30, 2023

  • Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element

    MediumCVSS 5.3No exploitEPSS 2%

    angularjs · angularjsMar 30, 2023

  • CVE-2021-4231
    21Monitor

    Angular Comment cross site scripting

    MediumCVSS 5.4No exploitEPSS 1%

    angular · angularMay 26, 2022

  • CVE-2024-8373
    17Monitor

    AngularJS improper sanitization in '<source>' element

    MediumCVSS 4.3No exploitEPSS 1%

    angularjs · angularjsSep 9, 2024

  • CVE-2024-8372
    17Monitor

    AngularJS improper sanitization in 'srcset' attribute

    MediumCVSS 4.3No exploitEPSS 1%

    angularjs · angularjsSep 9, 2024