angularjs kayıtları
angularjs üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %84,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1333 Inefficient Regular Expression Complexity5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-1289 Improper Validation of Unsafe Equivalence in Input1
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-791 Incomplete Filtering of Special Elements1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2022-25844İstismar yok | Regular Expression Denial of Service (ReDoS)angularjs · angularjs · CWE-1333 | Yüksek7,5 | — | %4,9 | 1 May 2022 |
31İzleyin | CVE-2019-10768İstismar yok | In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__protoangularjs · angularjs · CWE-1321 | Yüksek7,5 | — | %2,0 | 19 Kas 2019 |
31İzleyin | CVE-2024-21490Kavram kanıtı | This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.angularjs · angular.js · CWE-1333 | Yüksek7,5 | — | %1,9 | 10 Şub 2024 |
26İzleyin | CVE-2022-25869Kavram kanıtı | All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Croangularjs · angularjs · CWE-79 | Orta6,1 | — | %7,3 | 15 Tem 2022 |
24İzleyin | CVE-2019-14863İstismar yok | There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appliangularjs · angularjs · CWE-79 | Orta6,1 | — | %1,2 | 2 Oca 2020 |
24İzleyin | CVE-2017-16009İstismar yok | ag-grid is an advanced data grid that is library agnostic.ag-grid · ag-grid · CWE-79 | Orta6,1 | — | %1,0 | 4 Haz 2018 |
22İzleyin | CVE-2020-7676İstismar yok | angular.js prior to 1.8.0 allows cross site scripting.angularjs · angularjs · CWE-79 | Orta5,4 | — | %1,9 | 8 Haz 2020 |
22İzleyin | CVE-2023-26116İstismar yok | Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fuangularjs · angularjs · CWE-1333 | Orta5,3 | — | %1,7 | 30 Mar 2023 |
22İzleyin | CVE-2023-26117İstismar yok | Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to tangularjs · angularjs · CWE-1333 | Orta5,3 | — | %1,7 | 30 Mar 2023 |
22İzleyin | CVE-2023-26118İstismar yok | Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> elementangularjs · angularjs · CWE-1333 | Orta5,3 | — | %1,7 | 30 Mar 2023 |
21İzleyin | CVE-2021-4231İstismar yok | Angular Comment cross site scriptingangular · angular · CWE-79 | Orta5,4 | — | %1,2 | 26 May 2022 |
17İzleyin | CVE-2024-8373İstismar yok | AngularJS improper sanitization in '<source>' elementangularjs · angularjs · CWE-791 | Orta4,3 | — | %0,6 | 9 Eyl 2024 |
17İzleyin | CVE-2024-8372İstismar yok | AngularJS improper sanitization in 'srcset' attributeangularjs · angularjs · CWE-1289 | Orta4,3 | — | %0,6 | 9 Eyl 2024 |
- CVE-2022-2584431İzleyin
Regular Expression Denial of Service (ReDoS)
YüksekCVSS 7,5İstismar yokEPSS %5angularjs · angularjs1 May 2022
- CVE-2019-1076831İzleyin
In AngularJS before 1.7.9 the function `merge()` could be tricked into adding or modifying properties of `Object.prototype` using a `__proto
YüksekCVSS 7,5İstismar yokEPSS %2angularjs · angularjs19 Kas 2019
- CVE-2024-2149031İzleyin
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0.
YüksekCVSS 7,5Kavram kanıtıEPSS %2angularjs · angular.js10 Şub 2024
- CVE-2022-2586926İzleyin
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to Cro
OrtaCVSS 6,1Kavram kanıtıEPSS %7angularjs · angularjs15 Tem 2022
- CVE-2019-1486324İzleyin
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web appli
OrtaCVSS 6,1İstismar yokEPSS %1angularjs · angularjs2 Oca 2020
- CVE-2017-1600924İzleyin
ag-grid is an advanced data grid that is library agnostic.
OrtaCVSS 6,1İstismar yokEPSS %1ag-grid · ag-grid4 Haz 2018
- CVE-2020-767622İzleyin
angular.js prior to 1.8.0 allows cross site scripting.
OrtaCVSS 5,4İstismar yokEPSS %2angularjs · angularjs8 Haz 2020
- CVE-2023-2611622İzleyin
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fu
OrtaCVSS 5,3İstismar yokEPSS %2angularjs · angularjs30 Mar 2023
- CVE-2023-2611722İzleyin
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to t
OrtaCVSS 5,3İstismar yokEPSS %2angularjs · angularjs30 Mar 2023
- CVE-2023-2611822İzleyin
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element
OrtaCVSS 5,3İstismar yokEPSS %2angularjs · angularjs30 Mar 2023
- CVE-2021-423121İzleyin
Angular Comment cross site scripting
OrtaCVSS 5,4İstismar yokEPSS %1angular · angular26 May 2022
- CVE-2024-837317İzleyin
AngularJS improper sanitization in '<source>' element
OrtaCVSS 4,3İstismar yokEPSS %1angularjs · angularjs9 Eyl 2024
- CVE-2024-837217İzleyin
AngularJS improper sanitization in 'srcset' attribute
OrtaCVSS 4,3İstismar yokEPSS %1angularjs · angularjs9 Eyl 2024