Vulnerabilities (CVE)

Filtered by vendor Angularjs Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-25869 1 Angularjs 1 Angular 2022-07-21 N/A 6.1 MEDIUM
All versions of package angular are vulnerable to Cross-site Scripting (XSS) due to insecure page caching in the Internet Explorer browser, which allows interpolation of <textarea> elements.
CVE-2020-7676 1 Angularjs 1 Angular.js 2020-10-09 3.5 LOW 5.4 MEDIUM
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.
CVE-2019-14863 2 Angularjs, Redhat 3 Angular.js, Decision Manager, Process Automation 2020-01-09 4.3 MEDIUM 6.1 MEDIUM
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
CVE-2017-16009 2 Ag-grid, Angularjs 2 Ag-grid, Angularjs 2019-10-09 4.3 MEDIUM 6.1 MEDIUM
ag-grid is an advanced data grid that is library agnostic. ag-grid is vulnerable to Cross-site Scripting (XSS) via Angular Expressions, if AngularJS is used in combination with ag-grid.