Exposure of Angular

JavaScript frameworks
75
exposure score
213,044
sites use
0
exploited
0
critical
Vexday analysis

O histórico de vulnerabilidades do Angular soma 30 CVEs catalogadas, com zero registros de exploração ativa no catálogo KEV da CISA, taxa abaixo da média geral do catálogo. Não há falhas de severidade crítica no conjunto, e o maior valor EPSS observado é de aproximadamente 0,053, indicando probabilidade de exploração relativamente baixa em todo o portfólio. O ponto de atenção mais relevante é a concentração de falhas do tipo CWE-79 (Cross-Site Scripting), padrão dominante na base, e o volume expressivo de 18 CVEs surgidas nos últimos 90 dias, o que sugere um ciclo recente de descobertas que demanda acompanhamento próximo. A CVE mais perigosa atualmente identificada é a CVE-2022-25869, com EPSS de 0,0528, reforçando que, apesar da ausência de exploração confirmada, equipes que mantêm versões desatualizadas do framework devem priorizar a aplicação dos patches disponíveis.

CVEs

33 results
CVE-2022-25869MEDIUMAll versions of the package angular; all versions of the package angularjs.core; all versions of the package angularjs are vulnerable to CroEPSS 6.8%CVE-2022-25844MEDIUMRegular Expression Denial of Service (ReDoS)EPSS 4.9%CVE-2024-21490HIGHThis affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split thEPSS 1.9%CVE-2023-26116MEDIUMVersions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility fuEPSS 1.7%CVE-2023-26117MEDIUMVersions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to tEPSS 1.7%CVE-2023-26118MEDIUMVersions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> elementEPSS 1.7%CVE-2021-4231LOWAngular Comment cross site scriptingEPSS 1.1%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.6%CVE-2026-27970HIGHAngular i18n vulnerable to Cross-Site Scripting (XSS)EPSS 0.5%CVE-2026-22610HIGHAngular has XSS Vulnerability via Unsanitized SVG Script AttributesEPSS 0.4%CVE-2025-66412HIGHAngular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML AttributesEPSS 0.4%CVE-2026-69149HIGHAngular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)EPSS 0.3%CVE-2026-69151HIGHAngular i18n: Cross-Site Scripting (XSS) via event-handler attributesEPSS 0.3%CVE-2026-54268HIGHAngular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)EPSS 0.3%CVE-2025-59052HIGHAngular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data LeakageEPSS 0.3%CVE-2026-41423HIGHAngular: SSRF via protocol-relative and backslash URLs in Angular Platform-ServerEPSS 0.3%CVE-2026-50178HIGHAngular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service ExtensionEPSS 0.3%CVE-2026-50170HIGHAngular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCacheEPSS 0.3%CVE-2026-50556HIGHAngular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSREPSS 0.2%CVE-2026-54264HIGHAngular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service WorkerEPSS 0.2%