Home/Product/angularjs
Product

angularjs

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-8373
<= 1.8.3
Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass com
4.8MEDIUM
CVE-2024-8372
>= 1.3.1 and <= 1.8.3
Improper sanitization of the value of the 'srcset' attribute in AngularJS allows attackers to bypass common image source restricti
4.8MEDIUM
CVE-2024-21490
>= 1.3.0
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive i
7.5HIGH
CVE-2023-26118
>= 1.4.9 and <= 1.8.3
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url
5.3MEDIUM
CVE-2023-26117
>= 1.0.0 and <= 1.8.3
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource servic
5.3MEDIUM
CVE-2023-26116
>= 1.2.21 and <= 1.8.3
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy()
5.3MEDIUM
CVE-2022-25869
all versions
All versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnera
4.2MEDIUM
CVE-2021-4231
< 11.0.5
A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling o
3.5LOW
CVE-2022-25844
>= 1.7.0
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule t
5.3MEDIUM
CVE-2020-7676
< 1.8.0
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanit
5.4MEDIUM
CVE-2019-14863
>= 1.0.0 and <= 1.4.14
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the
6.1MEDIUM
CVE-2019-10768
< 1.7.9
In AngularJS before 1.7.9 the function merge() could be tricked into adding or modifying properties of Object.prototype using
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin