Записи angularjs
13 опубликованных записей вендора angularjs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 84,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-1333 Inefficient Regular Expression Complexity5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-1289 Improper Validation of Unsafe Equivalence in Input1
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-791 Incomplete Filtering of Special Elements1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2022-25844Эксплойта нет | Regular Expression Denial of Service (ReDoS)angularjs · angularjs · CWE-1333 | Высокая7,5 | — | 4,9 % | 1 мая 2022 г. |
31Наблюдать | CVE-2019-10768Эксплойта нет | In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__protoangularjs · angularjs · CWE-1321 | Высокая7,5 | — | 2,0 % | 19 нояб. 2019 г. |
31Наблюдать | CVE-2024-21490Proof of concept | This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.angularjs · angular.js · CWE-1333 | Высокая7,5 | — | 1,9 % | 10 февр. 2024 г. |
26Наблюдать | CVE-2022-25869Proof of concept | All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Croangularjs · angularjs · CWE-79 | Средняя6,1 | — | 7,3 % | 15 июл. 2022 г. |
24Наблюдать | CVE-2019-14863Эксплойта нет | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appliangularjs · angularjs · CWE-79 | Средняя6,1 | — | 1,2 % | 2 янв. 2020 г. |
24Наблюдать | CVE-2017-16009Эксплойта нет | ag-grid is an advanced data grid that is library agnostic.ag-grid · ag-grid · CWE-79 | Средняя6,1 | — | 1,0 % | 4 июн. 2018 г. |
22Наблюдать | CVE-2020-7676Эксплойта нет | angular.js prior to 1.8.0 allows cross site scripting.angularjs · angularjs · CWE-79 | Средняя5,4 | — | 1,9 % | 8 июн. 2020 г. |
22Наблюдать | CVE-2023-26116Эксплойта нет | Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fuangularjs · angularjs · CWE-1333 | Средняя5,3 | — | 1,7 % | 30 мар. 2023 г. |
22Наблюдать | CVE-2023-26117Эксплойта нет | Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to tangularjs · angularjs · CWE-1333 | Средняя5,3 | — | 1,7 % | 30 мар. 2023 г. |
22Наблюдать | CVE-2023-26118Эксплойта нет | Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> elementangularjs · angularjs · CWE-1333 | Средняя5,3 | — | 1,7 % | 30 мар. 2023 г. |
21Наблюдать | CVE-2021-4231Эксплойта нет | Angular Comment cross site scriptingangular · angular · CWE-79 | Средняя5,4 | — | 1,2 % | 26 мая 2022 г. |
17Наблюдать | CVE-2024-8373Эксплойта нет | AngularJS improper sanitization in '<source>' elementangularjs · angularjs · CWE-791 | Средняя4,3 | — | 0,6 % | 9 сент. 2024 г. |
17Наблюдать | CVE-2024-8372Эксплойта нет | AngularJS improper sanitization in 'srcset' attributeangularjs · angularjs · CWE-1289 | Средняя4,3 | — | 0,6 % | 9 сент. 2024 г. |
- CVE-2022-2584431Наблюдать
Regular Expression Denial of Service (ReDoS)
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %angularjs · angularjs1 мая 2022 г.
- CVE-2019-1076831Наблюдать
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %angularjs · angularjs19 нояб. 2019 г.
- CVE-2024-2149031Наблюдать
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %angularjs · angular.js10 февр. 2024 г.
- CVE-2022-2586926Наблюдать
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cro
СредняяCVSS 6,1Proof of conceptEPSS 7 %angularjs · angularjs15 июл. 2022 г.
- CVE-2019-1486324Наблюдать
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appli
СредняяCVSS 6,1Эксплойта нетEPSS 1 %angularjs · angularjs2 янв. 2020 г.
- CVE-2017-1600924Наблюдать
ag-grid is an advanced data grid that is library agnostic.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %ag-grid · ag-grid4 июн. 2018 г.
- CVE-2020-767622Наблюдать
angular.js prior to 1.8.0 allows cross site scripting.
СредняяCVSS 5,4Эксплойта нетEPSS 2 %angularjs · angularjs8 июн. 2020 г.
- CVE-2023-2611622Наблюдать
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fu
СредняяCVSS 5,3Эксплойта нетEPSS 2 %angularjs · angularjs30 мар. 2023 г.
- CVE-2023-2611722Наблюдать
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to t
СредняяCVSS 5,3Эксплойта нетEPSS 2 %angularjs · angularjs30 мар. 2023 г.
- CVE-2023-2611822Наблюдать
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element
СредняяCVSS 5,3Эксплойта нетEPSS 2 %angularjs · angularjs30 мар. 2023 г.
- CVE-2021-423121Наблюдать
Angular Comment cross site scripting
СредняяCVSS 5,4Эксплойта нетEPSS 1 %angular · angular26 мая 2022 г.
- CVE-2024-837317Наблюдать
AngularJS improper sanitization in '<source>' element
СредняяCVSS 4,3Эксплойта нетEPSS 1 %angularjs · angularjs9 сент. 2024 г.
- CVE-2024-837217Наблюдать
AngularJS improper sanitization in 'srcset' attribute
СредняяCVSS 4,3Эксплойта нетEPSS 1 %angularjs · angularjs9 сент. 2024 г.