angularjs records
13 published records for vendor angularjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 84.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-1289 Improper Validation of Unsafe Equivalence in Input1
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-791 Incomplete Filtering of Special Elements1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2022-25844No exploit | Regular Expression Denial of Service (ReDoS)angularjs · angularjs · CWE-1333 | High7.5 | — | 4.9% | May 1, 2022 |
31Monitor | CVE-2019-10768No exploit | In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__protoangularjs · angularjs · CWE-1321 | High7.5 | — | 2.0% | Nov 19, 2019 |
31Monitor | CVE-2024-21490Proof of concept | This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.angularjs · angular.js · CWE-1333 | High7.5 | — | 1.9% | Feb 10, 2024 |
26Monitor | CVE-2022-25869Proof of concept | All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Croangularjs · angularjs · CWE-79 | Medium6.1 | — | 7.3% | Jul 15, 2022 |
24Monitor | CVE-2019-14863No exploit | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appliangularjs · angularjs · CWE-79 | Medium6.1 | — | 1.2% | Jan 2, 2020 |
24Monitor | CVE-2017-16009No exploit | ag-grid is an advanced data grid that is library agnostic.ag-grid · ag-grid · CWE-79 | Medium6.1 | — | 1.0% | Jun 4, 2018 |
22Monitor | CVE-2020-7676No exploit | angular.js prior to 1.8.0 allows cross site scripting.angularjs · angularjs · CWE-79 | Medium5.4 | — | 1.9% | Jun 8, 2020 |
22Monitor | CVE-2023-26116No exploit | Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fuangularjs · angularjs · CWE-1333 | Medium5.3 | — | 1.7% | Mar 30, 2023 |
22Monitor | CVE-2023-26117No exploit | Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to tangularjs · angularjs · CWE-1333 | Medium5.3 | — | 1.7% | Mar 30, 2023 |
22Monitor | CVE-2023-26118No exploit | Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> elementangularjs · angularjs · CWE-1333 | Medium5.3 | — | 1.7% | Mar 30, 2023 |
21Monitor | CVE-2021-4231No exploit | Angular Comment cross site scriptingangular · angular · CWE-79 | Medium5.4 | — | 1.2% | May 26, 2022 |
17Monitor | CVE-2024-8373No exploit | AngularJS improper sanitization in '<source>' elementangularjs · angularjs · CWE-791 | Medium4.3 | — | 0.6% | Sep 9, 2024 |
17Monitor | CVE-2024-8372No exploit | AngularJS improper sanitization in 'srcset' attributeangularjs · angularjs · CWE-1289 | Medium4.3 | — | 0.6% | Sep 9, 2024 |
- CVE-2022-2584431Monitor
Regular Expression Denial of Service (ReDoS)
HighCVSS 7.5No exploitEPSS 5%angularjs · angularjsMay 1, 2022
- CVE-2019-1076831Monitor
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto
HighCVSS 7.5No exploitEPSS 2%angularjs · angularjsNov 19, 2019
- CVE-2024-2149031Monitor
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.
HighCVSS 7.5Proof of conceptEPSS 2%angularjs · angular.jsFeb 10, 2024
- CVE-2022-2586926Monitor
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cro
MediumCVSS 6.1Proof of conceptEPSS 7%angularjs · angularjsJul 15, 2022
- CVE-2019-1486324Monitor
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appli
MediumCVSS 6.1No exploitEPSS 1%angularjs · angularjsJan 2, 2020
- CVE-2017-1600924Monitor
ag-grid is an advanced data grid that is library agnostic.
MediumCVSS 6.1No exploitEPSS 1%ag-grid · ag-gridJun 4, 2018
- CVE-2020-767622Monitor
angular.js prior to 1.8.0 allows cross site scripting.
MediumCVSS 5.4No exploitEPSS 2%angularjs · angularjsJun 8, 2020
- CVE-2023-2611622Monitor
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fu
MediumCVSS 5.3No exploitEPSS 2%angularjs · angularjsMar 30, 2023
- CVE-2023-2611722Monitor
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to t
MediumCVSS 5.3No exploitEPSS 2%angularjs · angularjsMar 30, 2023
- CVE-2023-2611822Monitor
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element
MediumCVSS 5.3No exploitEPSS 2%angularjs · angularjsMar 30, 2023
- CVE-2021-423121Monitor
Angular Comment cross site scripting
MediumCVSS 5.4No exploitEPSS 1%angular · angularMay 26, 2022
- CVE-2024-837317Monitor
AngularJS improper sanitization in '<source>' element
MediumCVSS 4.3No exploitEPSS 1%angularjs · angularjsSep 9, 2024
- CVE-2024-837217Monitor
AngularJS improper sanitization in 'srcset' attribute
MediumCVSS 4.3No exploitEPSS 1%angularjs · angularjsSep 9, 2024